Ransomware Attacks Continue to Target US Cities

So far in 2019, there have been 22 reported public-sector ransomware attacks on US cities, signaling a rise in frequency since 2018. The attacks are targeted at local US government facilities such as cities, police stations, and schools. Some of these attacks have cost millions of dollars in ransom to get functioning again. Recorded Future, a cybersecurity firm that has …

Image credit: Inner Harbor sky in Baltimore after a storm passed by Mark Peters

Raised Stakes in Baltimore Ransomware Attack

The city of Baltimore was recently hit with a crippling ransomware attack, bringing most of the city’s servers down and affecting everything from bill payments to government communications. Baltimore has refused to pay, so the hackers seem to have upped the ante. A newly-created Twitter account claims to show screenshots of sensitive information purloined from the Baltimore cyberattack. In most …

Intel Zombieland Fix Threatens Processor Performance

“Zombieload” vulnerabilities of the microarchitectural data sampling (MDS) variety have been discovered by researchers Michael Schwarz, Moritz Lipp, and Daniel Gruss at Graz University of Technology in Austria, as well as Jo Van Bulk at Belgium’s KU Leuven. These latest flaws in Intel processors can be utilized by attackers to steal private data from PCs and servers, cloud environments, and …

Hawkeye Uses NSA Cyberattack Tools

The mystery surrounding the misappropriation of some of the National Security Agency’s most effective cyberweapons deepened recently when a Chinese hacking group known as Buckeye, APT3, and Gothic Panda utilized NSA exploits and attack tools EternalRomance and EternalSynergy. It remains unclear how they obtained the NSA tools though both were released by the Shadow Brokers. In the report released by …

Homeland Security Warning for VPN Security Flaws

Companies use enterprise VPNs, or virtual private networks, to allow employees to work remotely. An alert from the Department of Homeland Security just announced, however, that a vulnerability has been discovered in some major enterprise VPN providers. The vulnerability stems from authentication tokens that store a user’s login credentials on their computer so they don’t have to constantly keep logging …

PayPal’s New Ransomware Detection

By now everyone should know that ransomware is a huge threat. PayPal aims to do something about that. What we can figure out from the patent filed by the online transaction company is that PayPal seems to have found a way to detect ransomware before all your files are locked away, and in that time they can either prevent the …

Conflicting Information on Recent Microsoft Email Data Breach

Reports from Techcrunch a few days ago stated that an email breach occurred between January 1st and March 28th at Microsoft. The breach exposed email addresses and subject lines of an unknown number of accounts, but no actual email content. Microsoft states that a customer support representative’s account credentials were compromised which allowed access to accounts. Microsoft disabled the credential …

vxCrypter: Ransomware and Duplicate File Cleanup

vxCrypter Ransomware not only encrypts your computer, it also deletes duplicate files.  According to Lawrence Abrams, creator and owner of BleepingComputer, the vxCrypter Ransomware could be “the first ransomware infection that not only encrypts a victim’s data, but also tidy’s up their computer by deleting duplicate files.” vxCrypter is based on an older ransomeware called vxLock that never saw fruition. …

Unprotected Amazon Cloud Puts Half Billion Facebook Users at Risk

Third party Facebook app developers have caused yet another database leak.  Unprotected Amazon cloud servers put more than half a billion Facebook user information at risk. UpGuard, a cybersecurity firm, discovered that two datasets were publicly accessible—Coltura Colectiva, a Mexican media company, and “At the pool”, a Facebook-integrated ap. Researchers at the cybersecurity firm UpGuard today revealed that they discovered …

Wake County leaders trying to get out in front of wave of ransomware attacks

RALEIGH, N.C. (WNCN) – As hackers’ attacks impact local governments and other entities across the country, Wake County leaders took a closer look Monday at efforts to detect threats and mitigate their effects. Bill Greeves, the county’s chief information and innovation officer, told county commissioners about training employees receive in identifying risks and how his department has prepared to respond …

Your Best Defense: Training, Prevention and Cyber Insurance

Insurance companies are among the growing chorus of those who say it’s not a matter of if your law firm will get hacked, it’s a matter of when. And that has given rise to more carriers offering cybersecurity insurance. “If I could convince people of one thing, it’s that security by anonymity is false. It’s not your typical hacker in …

Repetitive Exposure to Phishing Improves Employee Click Rate

Like most things in life, practice makes perfect.  Well, perhaps, better at least.  KnowBe4 has reported that a “long-term phishing study involving 6 healthcare institutions shows employees are vulnerable to phishing attacks and that they can become more vigilant through exposure.” Researchers initiated 95 separate campaigns studying employee interaction with over 2 million simulated phishing emails.  There was a 16.7% …

Meditab Fax Server Leak

California-based Meditab, a leading software maker for healthcare electronic medical records, was leaking thousands of doctor’s notes, medical records, and prescriptions. The cause? A security lapse that left a fax server without a password. Without a password, the over six million records in its database could be read in real time. And to add insult to injury, none of that …

North Carolina First in Flight Again: First UPS Drone Delivery

North Carolina proudly claims the slogan “First in flight” thanks to the first manned flight carried out by the Wright brothers in Kitty Hawk, North Carolina. Now North Carolina can claim another first in flight. UPS’s first drone delivery was carried out in the state capital, Raleigh. The use of drones is expected to not only speed up delivery times, …

Time To Change Your Facebook Password (Again)

Hard on the heels of CEO Mark Zuckerberg’s lengthy Facebook post that the social network was doubling down on privacy and ensuring users’ data remains safe, Facebook faces yet more negative publicity. KrebsOnSecurity recently announced that an internal investigation has found between 200-600 million Facebook user passwords stored in insecure plaintext format. Meaning any of Facebook’s 20,000 employees had access. …

Citrix Systems Attacked Again

Citrix Systems announced an apparent network penetration by hackers. The Fort Lauderdale, Florida technology business was appraised by a suspected problem last Wednesday by the FBI. They have launched a full investigation. Stan Black, Citrix’s CSIO, said in his blog post on Friday that while the hackers appear to have accessed and stolen business documents, there is no indication that …