Truckers’ Medical Records Leaked

Truckers’ Medical Records Leaked

Medical records belonging to truck drivers and rail workers may have been exposed following an alleged cyber-attack on an occupational healthcare provider in Virginia. 

Data apparently belonging to employees of the United Parcel Service (UPS) and Norfolk Southern Railroad was published online to a leak site by the gang behind Conti ransomware. The cyber-criminals claimed to have obtained the data during a December cyber-attack on Taylor Made Diagnostics (TMD).

The HIPAA Journal reported that the leaked data includes full names, Social Security numbers, details of medical examinations, drug and alcohol testing reports, and scans of driver’s licenses.

With locations in Chesapeake and Newport News, TMD is an operator of occupational health clinics used by transportation companies and government agencies. The company provides services including drug testing, CPR training, fit-for-duty evaluations, vaccinations, and respirator fit testing.

According to their website, TMD clients include the US military, the US Secret Service, the navy special warfare development group, BAE systems, Old Dominion University, the Social Security Administration, and the Virginia Department of Military Affairs.  

While TMD has not verified the alleged attack, FreightWaves reported that among the more than 3,000 TMD files leaked on January 8 were multiple health records for employees at both UPS and Norfolk Southern dated as recently as December 2020. 

In addition, the trucking news source spotted records belonging to employees of US government agencies, defense contractors, and multiple smaller trucking companies.

Norfolk Southern Railroad, which employs nearly 25,000 people in 22 states, said that it was investigating the veracity of the cyber-criminals’ claims.

“The security of our employees’ data is a priority for Norfolk Southern and a requirement for our vendors,” Norfolk Southern spokesperson Jeff DeGraff wrote in an email to FreightWaves.

“Norfolk Southern is looking into the issue but has no further comment at this time.”

UPS, which employs 362,000 people in the US and an additional 82,000 internationally, said it was also looking into the possible data breach. 

According to the US Department of Health and Human Services, in December alone, 37 US healthcare providers reported hacking or unspecified information technology incidents that compromised nearly 1.5 million patients.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

France Arrests 14 Over Online Child Sexual Abuse

France Arrests 14 Over Online Child Sexual Abuse

Fourteen people have been arrested in France as part of a nationwide sweep to combat the sexual exploitation of children online. 

The arrests were made by the French Gendarmerie (Gendarmerie nationale) with the support of Europol as part of an operation that was code-named Horus. All suspects were taken into custody between November 16 and November 20, 2020.

In a statement released yesterday, Europol said: “The alleged suspects used social media networks to approach minors aged between 12 and 13 and lured them into sharing intimate images and videos.” 

It is not believed that there were any links between the 14 arrested suspects, three of whom have already been convicted and sentenced. 

Operation Horus, which is still ongoing, has so far contributed to the identification of eight potential victims who are minors and resulted in the seizure of 1,058 illicit images.

Over 50 cyber-investigators were brought in to work on the operation to track the online activities of a large volume of users. The investigators’ efforts were coordinated by the French Gendarmerie’s cybercrime center, C3N.

Support provided by Europol included operational analysis and real-time database cross-checks to enable the identification of potential suspects and victims.

Europol said that the investigation was made more complex by the suspected users’ often swapping their online pseudonyms. 

Statistics published by Europol in June showed that the exchanging of child sexual abuse material (CSAM) had increased sharply during the COVID-19 pandemic. 

“With both children and sexual offenders confined at home, law enforcement authorities have seen in the past few months the amount of child sexual exploitation material shared online increasing globally,” said Europol.

“Sex offenders have increased their criminal activities in social media, via peer-to-peer networks and on the darkweb. Attempts to access websites featuring child sexual abuse material, calls to helplines and activities in dark net and surface web chats sharing child abuse material have all increased during the confinement period.”

Europol reported that the amount of webcam footage depicting CSAM had increased considerably in forums accessed by offenders. 

“This includes videos depicting forced or coerced children, videos produced by children for peers or for social media attention or others which were captured without their knowledge.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Exploit Allows Root Access to SAP

Exploit Allows Root Access to SAP

A team of enterprise resource planning security experts in Massachusetts have identified a functional exploit affecting SAP that is publicly available.

The exploit was discovered by Onapsis Research Labs on code-hosting platform GitHub, where it had been published by Russian researcher Dmitry Chastuhin on January 14. Researchers said the exploit can be used against SAP SolMan, the administrative system used in every SAP environment that is similar to Active Directory in Windows.

The fully functional exploit abuses United States’ National Vulnerability Database listing CVE-2020-6207, a vulnerability in which SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check, does not perform any authentication for a service. This vulnerability results in the complete compromise of all SMDAgents connected to the Solution Manager.

A successful attack exploiting this vulnerability could impact an organization’s cybersecurity and regulatory compliance by placing its mission-critical data, SAP applications, and business process at risk.

“While exploits are released regularly online, this hasn’t been the case for SAP vulnerabilities, for which publicly available exploits have been limited,” wrote Onapsis researchers. 

“The release of a public exploit significantly increases the chance of an attack attempt since it also expands potential attackers not only to SAP-experts or professionals, but also to script-kiddies or less-experienced attackers that can now leverage public tools instead of creating their own.”

Because it was created to centralize the management of all SAP and non-SAP systems, SolMan has trusted connections with multiple systems. An attacker that could gain access to SolMan could potentially compromise any business system connected to it. 

“Unfortunately, since it doesn’t hold any business information, SAP SolMan is often overlooked in terms of security; in some companies, it does not follow the same patching policy as other systems,” noted researchers. 

An attacker with SAP SolMan control could shut down systems, access sensitive data, delete data, cause IT control deficiencies, and assign superuser privileges to any new or existing user. 

“It is not possible to list everything that can potentially be done in the systems if exploited, since having admin privileged control in the systems or running OS commands basically make it limitless for an attacker,” wrote researchers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Barmak Meftah Joins Board of Directors at Nozomi Networks

Barmak Meftah Joins Board of Directors at Nozomi Networks

IoT and OT security firm Nozomi Networks has announced that enterprise security leader Barmak Meftah has joined its board of directors.

Meftah brings more than 25 years of experience in building market-leading enterprise SaaS and cybersecurity companies to Nozomi Networks and most recently served as president of AT&T Cybersecurity where he established its cybersecurity division and grew revenue by double digits.

In addition to his independent board position with Nozomi Networks, Meftah also serves on various other boards of directors, is an advisor and coach to multiple CEOs and is an independent investor as well as a limited partner to a number of VC funds.

Commenting on the announcement, Nozomi Networks CEO Edgard Capdevielle, said: “Barmak’s impressive track record of success in Silicon Valley has gained him international respect as a pillar in enterprise security. His keen business instincts and depth of knowledge in security software and SaaS will be invaluable as we add cloud-based solutions to our product portfolio and accelerate market expansion and growth. We are ecstatic to welcome him to the board.”

Meftah added: “Nozomi Networks is leading the charge to ensure a secure future for critical infrastructure and industrial networks. IT/OT convergence and a growing reliance on AI-powered processes and IoT devices has created a flaming hot market for advanced security solutions that can help CISOs effectively span mixed networks, physical systems and IoT devices.

“I look forward to helping Nozomi Networks take its business to the next level.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Global Cybersecurity Spending to Soar 10% in 2021

Global Cybersecurity Spending to Soar 10% in 2021

The worldwide cybersecurity market is set to grow by up to 10% this year to top $60bn, as the global economy slowly recovers from the pandemic, according to Canalys.

The analyst firm clarified that double-digit growth from $54.7bn in 2020 would be its best-case scenario. However, even in the worst case, cybersecurity spending would reach 6.6%, it predicted.

That would factor in a deeper-than-anticipated economic impact from lockdowns, although the security market has proven to be remarkably resilient thus far to the pandemic-induced global economic crisis, Canalys said.

That said, SMB spending was hit hard last year, along with certain sectors like hospitality, retail and transport.

However, while spending is set to soar, so are data breaches and ransomware attacks. Human error continues to be a major factor, via misconfigurations of cloud infrastructure and susceptibility to phishing attacks, the analyst argued.

Mass remote working and learning in 2021 and the ongoing pressure placed on healthcare services will continue to expose these organizations to threats, it said.

Chief analyst, Matthew Ball, claimed the recent SolarWinds attacks highlight the continued unpredictability of the threat landscape. Amidst this volatile backdrop, organizations will need to adopt multi-layered approaches combining staff awareness training, data protection and threat detection and response, he said.

“Cybersecurity professional services engagements in response to this latest issue will be one of many factors contributing to sustained investment this year, especially in newer solutions to mitigate emerging threats,” Ball noted. “Growth in add-on subscriptions providing new features, products to secure the cloud and delivered from the cloud, and upgrades to existing solutions will be key drivers for expansion.”

The Canalys report covered shipments of endpoint security, network security, web and email security, data security, vulnerability and security analytics, and identity access management (IAM).

Web and email security (12.5%) will grow the most in 2021 with vulnerability and security analytics (11%) not far behind. Data security (6.6%) and network security (8%) are set to bring up the rear in terms of growth.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Security Biggest Barrier to Cloud Adoption for Over Half of UK Firms

Security Biggest Barrier to Cloud Adoption for Over Half of UK Firms

Over half (58%) of UK businesses have cited security concerns as the biggest barrier to public cloud adoption, according to a new study from Centrify.

The survey of 200 business decision makers in large and medium-sized enterprises in the UK also found that over a third (35%) who have adopted cloud are less than 80% confident it is completely secure.

Additionally, more than a quarter (28%) of those surveyed revealed that their organization had been targeted by a cloud hacking attempt since the start of the COVID-19 pandemic.

In regard to their companies’ security weaknesses, close to half (45%) of decision makers pinpointed the growth in machine identities and service accounts, such as those used by servers and applications, as their biggest exposure point.

Worryingly, 31% of business decision makers admitted their development teams are more interested in getting around security than building it into the DevOps pipeline, raising concerns over the ability of many companies to combat cyber-attacks in the future.

Kamel Heus, VP EMEA for Centrify, commented: “Adapting to the COVID-19 pandemic has been a bumpy ride for many businesses and, in most cases, companies have had to adopt the public cloud in at least some capacity due to the level of scalability, availability and efficiency it provides for distributed workforces.

“Whilst the common misperception is that cloud security is quite different to that of on-premises infrastructure, it is by no means less secure if common security protocols are followed, and security controls are applied.

“One core challenge posed by digital transformation is accurately verifying human and machine identities before granting access to systems, applications and other high value targets. Therefore, adopting cloud-ready privileged access management software is essential in protecting access to workloads in the public cloud, by granting access only when a requestor’s identity has been properly authenticated.”

While cloud adoption has grown since the shift to remote working as a result of the COVID-19 pandemic, in many cases, security has not adapted. Last year, a survey by Trend Micro revealed that nearly half of UK IT leaders have not updated their security to account for their move to cloud environments.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Threat Actor Dumps 1.9 Million Pixlr Records Online

Threat Actor Dumps 1.9 Million Pixlr Records Online

A notorious threat actor appears to have published 1.9 million user records for the popular online photo editing site Pixlr, putting customers at risk of follow-on attacks.

“ShinyHunters” dumped the files over the weekend for free on an underground forum, claiming the site was breached at the same time as 123RF, which is owned by the same company, Inmagine.

Among the data up for grabs are email addresses, usernames, hashed passwords and users’ countries.

So far there’s been no word from the firm itself, despite the fact that these users could be at risk of phishing attacks, credential stuffing attempts and other fraud if not informed promptly.

ShinyHunters is a prolific actor on the cybercrime underground, having been involved in breaches at Wishbone (40 million records), Heavenly (1.4 million), Dave (7.5 million) and many more.

If this incident is legitimate, as seems the case, Pixlr customers would be advised to be on the look-out for scams and to change their log-ins on the site, and any others they share the same passwords for.

ShinyHunters claimed to have stolen the data from Pixlr’s Amazon Web Services (AWS) S3 bucket late last year.

It’s unclear how, but CloudSphere VP of product, Pravin Rasiah, warned that misconfigured cloud storage is one of the leading causes of data breaches.

“The chances of leaving an S3 bucket exposed are all too high, as inexperienced users can simply choose the ‘all users’ access option, making the bucket publicly accessible. Leaving these S3 buckets open and exposed invites hackers to exploit the personal data entrusted to companies by their customers,” he argued.

“To prevent incidents like this from occurring, awareness within the cloud environment is imperative.” 

Cloud Security Posture Management (CSPM) tools are widely regarded as best practice in this space, as they continuously monitor such environments for configuration errors.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Interpol: Dating App Victims Lured into Investment Scams

Interpol: Dating App Victims Lured into Investment Scams

Interpol has issued a global warning that dating app users are being groomed for investment fraud scams.

The policing body’s Purple Notice claimed that lonely hearts are picked off online, when the fraudsters establish an “artificial romance” with their victims. Once they have built up a level of trust through regular communication, they share investment tips and encourage the victim to join up to a scheme.

“Victims download a trading app and open an account, buy various financial products and work their way up a so-called investment chain, all under the watchful eye of their new ‘friend.’ They are made to believe they can reach Gold or VIP status,” the notice explained.

“As is often the case with such fraud schemes, everything is made to look legitimate. Screenshots are provided, domain names are eerily similar to real websites and customer service agents pretend to help victims choose the right products.”

However, eventually the victims are abruptly locked out of their accounts, having invested significant sums in the financial products.

They’re then left with a double whammy of financial loss and emotional pain.

Investment and romance scams are nothing new: in fact, they’ve thrived under lockdown. The UK’s National Cyber Security Centre (NCSC) revealed in August last year that it had been forced to take down over 300,000 related URLs.

In the UK alone, the period June-August 2020 saw a 26% year-on-year increase in romance scams, with losses for the previous 12 months hitting £66m.

Over 19,400 romance scams were recorded by the FBI in 2019, making it the second highest earner for cyber-criminals after business email compromise (BEC). Scammers took $475m from victims.

Interpol urged dating site users to be vigilant, think twice before transferring money or getting involved with online investment schemes and to do their research to check the reputation of any new apps or services.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk