COO Charged in Georgia Hospital Cyber-attack

COO Charged in Georgia Hospital Cyber-attack

The chief operating officer of an IoT security company has been indicted by a federal grand jury over a cyber-attack carried out on a hospital in Georgia. 

Vikas Singla, of Marietta, Georgia, was arraigned on Thursday for his alleged role in the 2018 attack on Gwinnett Medical Center that exposed patients’ personal data. 

The center, which is now known as Northside Hospital, was a not-for-profit health care network that provided health care services at two hospitals located in Georgia; one was in Duluth and the other in Lawrenceville. 

Singla was the COO and co-founder of Atlanta-based startup Securolytics, which served the health care industry with a cloud-based threat detection and analytics platform that was purpose-built for IoT.

According to the indictment, 45-year-old Singla took part in an attack that disrupted Gwinnett’s phone service and network printer service. He is further accused of obtaining information from a digitizing device. 

Prosecutors said that the attack allegedly perpetrated by the Marietta resident was motivated in part by financial gain. 

“This cyber-attack on a hospital not only could have had disastrous consequences, but patients’ personal information was also compromised,” said Special Agent in Charge Chris Hacker of the FBI’s Atlanta Field Office. 

“The FBI and our law enforcement partners are determined to hold accountable those who allegedly put people’s health and safety at risk while driven by greed.”

It is alleged that on or about September 27, 2018, Singla, “aided and abetted by others unknown to the grand jury,” attacked one or more computers used by Gwinnett Medical Center that operated the Ascom phone system of the Duluth hospital. 

Singla is further accused of attacking one or more computers used by the Duluth and Lawrenceville hospitals that operated 17 different Lexmark printers. 

He is further accused of accessing without authorization a Hologic R2 Digitizer used by the Center in the Lawrenceville hospital.

Singla is charged with 17 counts of intentional damage to a protected computer and one count of obtaining information by computer from a protected computer.

The Department of Justice said that the attack on Gwinnett Medical Center is still being investigated by the FBI. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Launches National AI Task Force

US Launches National AI Task Force

The Biden administration has launched a new national artificial intelligence task force to make more government data available to AI researchers.

News of the National Artificial Intelligence (AI) Research Resource Task Force was announced on Thursday by the White House Office of Science and Technology Policy (OSTP) and the National Science Foundation (NSF).

A key role of the task force will be to serve as a federal advisory committee, assisting the creation and implementation of a blueprint for the National AI Research Resource (NAIRR).

The NAIRR is a shared research infrastructure that provides access to computers, high-quality data, educational tools, and user support to AI researchers and science students.

Co-chairing the task force will be Lynne Parker, White House Office of Science and Technology Policy, and Erwin Gianchandani, National Science Foundation.

“The task force will provide recommendations for establishing and sustaining the NAIRR, including technical capabilities, governance, administration, and assessment, as well as requirements for security, privacy, civil rights, and civil liberties,” said the White House in a statement released yesterday.

In May 2022, the task force will submit an interim report to Congress detailing a comprehensive strategy and implementation plan. A final report will be submitted in November 2022.

Kudelski Security CEO Andrew Howard told Infosecurity Magazine that releasing data could have both a positive and a negative effect.

“Overall, making data available for research is a good thing. It’s an example of our government working for us as well as increasing transparency. This release of data could lead to new innovations both in an academic and private business context that make our lives better and solve societal challenges,” said Howard. 

He warned: “There is also a downside. Depending on the sensitivity and scope of the data released, it could lead to the targeting of individuals and groups, both by companies and adversaries alike.”

Howard stressed that any data release should be accompanied by the implementation of appropriate privacy protections.

“This isn’t always easy to do since there are attacks which can allow someone to combine the released data with other pieces of publicly available data to deanonymize individuals in a dataset,” lamented Howard.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

McDonald’s Suffers Data Breach

McDonald’s Suffers Data Breach

A data breach at fast food restaurant McDonald’s has impacted customers and employees in South Korea and Taiwan and company operations in the United States.

The breach, which was first reported Friday by the Wall Street Journal, was the result of a cyber-attack. Hackers who broke into the computer system of McDonald’s Corp. accessed only a small number of files before their intrusion was detected.

During their period of unauthorized access, the cyber-criminals stole personal information belonging to delivery customers in Taiwan and South Korea. Information accessed and pilfered included customer emails, phone numbers and addresses.

Employee information stolen by the hackers included the names and contact information of McDonald’s workers in Taiwan. The burger servers said no customer payment details were accessed or stolen in the attack. 

McDonald’s did not disclose exactly how many files were exposed or the number of people who were affected by the data breach, sharing only that the quantity of files was small. 

The data breach was detected by external consultants hired by McDonald’s to investigate an incidence of unauthorized activity on an internal security system. Although access was blocked a week after detection, investigators found that company data in three countries had been breached.

In the United States, the hackers were able to access some business contact details for employees and franchisees. They also compromised restaurant data that included seating capacities and the size of play areas measured in square feet.

McDonald’s said no data belonging to US customers was affected and that the exposed employee information did not include any personal or sensitive data. 

Regulators in Asia were notified of the breach on Friday by the McDonald’s division in South Korea and Taiwan. The company said it will notify impacted customers and employees.

“Hackers will be quick to exploit the business contact details exposed in this breach, either simply selling the data or using the information to send convincing phishing, smishing or vishing attacks to victims of the breach,” commented Tessian CTO & co-founder Ed Bishop.

“The warning for all McDonald’s employees and franchisees, then, is to watch out for phishing emails and verify any requests for payments or information with the supposed source via another means of communication before complying with the request.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Gaming Giant EA Suffers Major Data Breach

Gaming Giant EA Suffers Major Data Breach

Hackers have stolen a wealth of data from gaming giant Electronic Arts (EA), including game source code and tools for several popular games, it has been reported.

Cyber-criminals made the claim in blog posts published on underground hacking forums, where they advertised a total of 780GB of data for sale. These posts were viewed and detailed by Motherboard, who EA informed that it had indeed suffered a data breach.

Among the data stolen was the source code for the popular football game FIFA 21 and code for its matchmaking server, and source code and tools for the Frostbite engine, which powers several EA games, including Battlefield. Additionally, the attackers took proprietary EA frameworks and software development kits.

Fortunately, it appears that hackers stole no personal data of customers in the breach, and EA told Motherboard that it does not expect the attack to impact “our games or our business.” This means that players should not be at an increased risk of cyber-attacks, phishing or identity theft.

Tom Van de Wiele, the principal security consultant at F-Secure, explained that the biggest impact of the data theft could that it offers valuable information for EA’s competitors to exploit. He said that “The EA source code and tools have a surprisingly high value to any company that operates in the shadows and want to get a leg up in competing with the bigger game development companies. Being able to steal an algorithm, approach, or game assets themselves and integrate them fast means not having to develop them on your own and means money and effort is saved that can be directed somewhere else. Especially when those games are released to a limited target group or platform where it is almost impossible to prove any wrongdoing or theft of intellectual property.”

Sam Curry, chief security officer at Cybereason, commented: “Oftentimes, there isn’t a lot of good news or optimism resulting from another global giant being breached. However, in the case of EA, they deal in petabytes of information so the reported amount of stolen data is relatively small in the gaming world. I’m not trying to diminish or minimize this compromise as the source code used to develop EA’s popular games has value to competitors and threat actors looking to sell the info on the darkweb.”

Curry also urged EA to share as many details as possible about how the breach occurred. “From initial reports, customer info, financial info or other proprietary information hasn’t been stolen. Behind the scenes, the threat actors either didn’t ultimately get where they wanted to in the network, or the good guys discovered the compromise early enough to limit the damage,” he said.

“EA should continue to be transparent, share as many details as possible and use this compromise as an opportunity to educate other companies in need of improving their own security hygiene. We should all look forward to hearing more from EA relating to this compromise and they have the opportunity to play the role of hero in this situation, as the role of villain or victim isn’t an option.”

Hackers have increasingly targeted the gaming industry in recent years due to its surging popularity. Researchers revealed they discovered 500,000 breached employee credentials and a million compromised internal accounts on the dark web from gaming firms earlier this year. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#G7UK: UK and US Strike New Agreements on Cybersecurity

#G7UK: UK and US Strike New Agreements on Cybersecurity

The UK and US governments have agreed to work together more closely to tackle cybercrime as well as enhance the security of supply chains and emerging technologies. The announcement has come amid US President Joe Biden’s visit to the UK for the G7 summit, which has started today.

The partnership will be built within the framework of the revitalized Atlantic Charter, first introduced in 1941, and will cover a range of areas in science and technology, including cybersecurity.  

The two nations stated that they intend to cooperate to enhance the resilience and security of critical supply chains, battery technologies and emerging technologies such as AI and quantum. This forms part of their desire to ensure the full potential of future technologies like quantum and 6G are realized in the future.

Additionally, the two governments aim to improve the accessibility and flow of data to support economic growth, public safety, and scientific and technological progress.

More generally, the agreement emphasized the need to ensure liberal and democratic values are embedded into the design and standards governing technology globally. This is an issue that the director of GCHQ, Jeremy Fleming, highlighted in a speech back in April this year.

UK digital secretary, Oliver Dowden, commented: “In the 80 years since the Atlantic Charter was signed, technology has changed the world beyond recognition. But the goals that underpin it still bind the US and UK together today: support for democracy, open societies and free markets.

“Today’s announcement marks a new era of cooperation with our closest ally, in which we commit to using technology to create prosperity and guarantee the safety and security of our citizens for years to come.”

Following the announcement, in an interview published in The Daily Telegraph last night, the UK foreign secretary, Dominic Raab, also revealed that the UK and US will work more closely together to “take the fight to cyber-criminals,” especially those targeting vital services like schools and hospitals.

Commenting, Charlie Smith, consulting solutions engineer at Barracuda Networks, said: “This announcement marks a turning point for the war on cyber-criminals, with the UK and US joining forces to root out and bring those responsible to justice. The sharp rise in ransomware attacks against schools, hospitals, local councils, and other critical national infrastructure cannot be underestimated and a concerted effort needs to be made to protect and secure these vital organizations from increasingly brazen attacks.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Unknown Attacker Chains Chrome and Windows Zero-Days

Unknown Attacker Chains Chrome and Windows Zero-Days

Security researchers warn of a series of highly targeted attacks designed to compromise victim networks via Google Chrome and Microsoft Windows zero-day exploits.

The attackers are thought to have first exploited the now-patched CVE-2021-21224 remote code execution bug in Chrome.

“This vulnerability was related to a Type Mismatch bug in the V8 — a JavaScript engine used by Chrome and Chromium web-browsers,” explained Kaspersky. “It allows the attackers to exploit the Chrome renderer process: the processes that are responsible for what happens inside users’ tabs.”

The second stage was an elevation of privilege exploit linked to two separate vulnerabilities in the Microsoft Windows OS kernel. The first, CVE-2021-31955, can lead to the disclosure of sensitive kernel information, while the second, CVE-2021-31956, is a heap-based buffer overflow bug.

Kaspersky claimed that attackers CVE-2021-31956 alongside the Windows Notification Facility (WNF) to create arbitrary memory read/write primitives and execute malware modules with system privileges.

Once they’ve gained a foothold in victim networks by exploiting these three flaws, the stager modules execute a more sophisticated malware dropper from a remote server, which in turn installs to executables masquerading as legitimate Windows files.

One of these is a remote shell module designed to download and upload files, create processes, lie dormant for periods of time, and delete itself from the infected system, Kaspersky said.

Microsoft patched both vulnerabilities in this week’s Patch Tuesday security update round while Google has already fixed the Chrome flaw.

The research team has yet to link the attacks to any known threat actor, so is dubbing the group behind it “PuzzleMaker.”

“Overall, of late, we’ve been seeing several waves of high-profile threat activity being driven by zero-day exploits. It’s a reminder that zero days continue to be the most effective method for infecting targets,” argued Boris Larin, senior security researcher at Kaspersky’s Global Research and Analysis Team (GReAT).

“Now that these vulnerabilities have been made publicly known, it’s possible that we’ll see an increase of their usage in attacks by this and other threat actors. That means it’s very important for users to download the latest patch from Microsoft as soon as possible.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

China’s New “Anti-Sanctions” Law Means Headache for Foreign Firms

China’s New “Anti-Sanctions” Law Means Headache for Foreign Firms

Western tech firms and other multinationals with a big presence in China could soon find themselves in a difficult position after Beijing passed new retaliatory sanctions laws.

The move is widely seen as a reaction to a string of sanctions put in place by the US and allies in recent months over human rights abuses in Xinjiang and the muzzling of democracy protests in Hong Kong.

The new law passed on Thursday will reportedly enable the government to put individuals or entities on an “anti-sanctions list” if they comply with sanctions from the US and other countries that displease Communist Party leaders.

These individuals and businesses may be denied entry to China, expelled from the country, have assets seized or frozen or be banned from doing business there.

It’s the latest sign of China using its economic might to push back against what it sees as unfair foreign interference in sovereign matters.

However, it could place foreign companies in an impossible situation and force many to choose sides between the world’s two superpowers.

The law was reportedly rushed through China’s rubber-stamp legislature, the National People’s Congress (NPC), without a third reading.

Also yesterday, China issued a second draft of a new Data Security Law which will restrict outward flows of “important” data from critical infrastructure (CNI) and non-CNI firms operating in the country — subjecting them to a security review process.

Purportedly, new rules could also prevent foreign companies from disclosing information on their Chinese subsidiaries to a foreign law enforcement agency or court.

Legal analysts have warned that much will hinge on how the authorities interpret the vague term “important.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Quantum Breakthrough in Britain Creates 600km Secure Link

Quantum Breakthrough in Britain Creates 600km Secure Link

Long-distance quantum-secured data transfer took a step closer this week after Toshiba announced that scientists in the UK have managed to produce a stable prototype that works over 600 kilometers.

Quantum computing is often described as a potential security challenge in that, once states can engineer working machines, they could theoretically crack any public-key cryptography system.

However, the technology could also be used to mitigate this risk by producing “unhackable” information streams using quantum key distribution (QKD).

This is a technology Toshiba Europe scientists are working on in Cambridge. Photons are encoded and transmitted for key generation. Still, if the stream is interrupted by an eavesdropper, the unique properties of quantum physics mean that the sender will be alerted, and it is instantly scrambled.

Up until now, the main challenge in achieving QKD has been the fragility of qubits, or quantum particles, which means that they could be scrambled unintentionally if the fiber cables they’re transmitted through experience temperature or other changes.

Toshiba used a new “dual band” stabilization technique to tackle this.

“This sends two optical reference signals, at different wavelengths, for minimizing the phase fluctuations on long fibers. The first wavelength is used to cancel the rapidly varying fluctuations, while the second wavelength, at the same wavelength as the optical qubits, is used for fine adjustment of the phase,” it said.

“After deploying these new techniques, Toshiba found it is possible to hold the optical phase of a quantum signal constant to within a fraction of a wavelength, with a precision of 10s of nanometers, even after propagation through hundreds of kilometers of fiber. Without cancelling these fluctuations in real-time, the fiber would expand and contract with temperature changes, scrambling the quantum information.”

Using this dual band technique has enabled the research team to implement the so-called Twin Field QKD at distances around three times longer than existing commercial QKD systems.

Secure information exchange of this sort could one day be used to support an entire “quantum internet” of interconnected quantum computers. Given the huge variety of potential applications, the US, EU and China are throwing vast sums of money at such projects.

“QKD has been used to secure metropolitan area networks in recent years. This latest advance extends the maximum span of a quantum link so that it is possible to connect cities across countries and continents without using trusted intermediate nodes,” said Andrew Shields, head of the Quantum Technology Division at Toshiba Europe.

“Implemented along with Satellite QKD, it will allow us to build a global network for quantum secured communications.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk