Ransomware Attack on Medical Billing Company

Ransomware Attack on Medical Billing Company

An Iowa medical billing and reimbursements services company is boosting its cybersecurity after suffering a ransomware attack.

An unknown threat actor hit Timberline Billing Service LLC with malware between February 12 and March 4, 2020. After gaining access to the company’s network, the attacker encrypted files and removed information.

Timberline said it was unable to determine precisely what data was exfiltrated, but a review of the files that could have been accessed concluded that current and former students in schools served by the company may have been impacted.

Timberline, which is based in Des Moines, provides services to around 190 schools in Iowa. The security incident was reported to the Department of Health and Human Services’ Office for Civil Rights as a data breach affecting up to 116,131 individuals.

Data accessed by the attacker may have included students’ names, dates of birth, Medicaid identification number, and related billing information. 

Social Security numbers may also have been accessed in what Timberline described as “very limited instances.”

Iowa City Community School District leaders said the ransomware attack “did not involve any access to District’s internal systems or student records.”

Timberline started contacting students in Iowa on October 20 to notify them of “a privacy incident that may have involved some of their information.”

While the company says it hasn’t yet unearthed any instances of student data being misused, Timberline is offering all students impacted by the incident free credit monitoring and identity protection services. 

A toll-free call center has been established by Timberline to support impacted students and their parents. 

Company officials said action was being taken to improve Timberline’s security systems to prevent a similar attack from happening in the future. Among the steps being implemented were firewall and server upgrades, migrating school and student data to a cloud location, resetting all user passwords, and requiring frequent password rotations.

Other Iowa organizations impacted by malware this year include UnityPoint Health and Iowa State Foundation, both of which suffered a data breach when their third-party vendor Blackbaud was attacked with ransomware in May.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Vatican Brings in Bots to Protect World’s Oldest Bible

Vatican Brings in Bots to Protect World’s Oldest Bible

The Vatican is using artificial intelligence to protect its vast digitized library of ancient artifacts, which includes the world’s oldest surviving copy of the Bible.

An average of 100 attempts a month have been made to hack into the virtual version of the Vatican Apostolic Library since digitization of the precious historical collection began in 2012. 

The library’s CIO, Manlio Miceli, told the Observer that cyber-attacks against the digital library are increasing. 

“We cannot ignore that our digital infrastructure is of interest to hackers,” said Miceli.

Describing what could happen if the library’s cyber-defenses were overcome in the current climate of untrustworthy information and fake news, Miceli said that the integrity of the contents of ancient documents could be under threat.  

 “A successful attack could see the collection stolen, manipulated or deleted altogether,” said Miceli.

“We have to protect our online collection so that readers can trust the records are accurate, unaltered history.”

Miceli said that defending the library against “trust attacks” was critical in the fight against misinformation.

He said: “While physical damage is often clear and immediate, an attack of this kind wouldn’t have the same physical visibility, and so has the potential to cause enduring and potentially irreparable harm, not only to the archive but to the world’s historical memory.”

The library was founded in 1451 by Pope Nicholas V and is one of the world’s most crucial research institutions. Among its 80,000 treasures are ancient Inca manuscripts, drawings and writings by Michelangelo and Galileo, and delicate illustrated fragments of Virgil’s Aeneid that are over 1,600 years old. 

So far, just 25% of the library’s 41 million pages have been digitized in a process Miceli said intends to “preserve the content of historical treasures without causing damage to the fragile originals” and increase educational equality.

The Vatican has partnered with British cyber-defense company Darktrace to protect the library from threats.

Miceli said: “You cannot throw people at this problem—you need to augment human beings with technology that understands the shades of grey within very complex systems and fights back at machine speed.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

EC Finds Amazon Breached Antitrust Rules

EC Finds Amazon Breached Antitrust Rules

Amazon is facing a £15bn fine after the European Commission found the American multinational breached EU antitrust rules.

The EC sent a Statement of Objections to Amazon following a preliminary investigation into the company’s ecommerce business practices. According to the EC, Amazon used non-public data to distort competition in online retail markets. 

In a statement released yesterday, the EC said: “The Commission takes issue with Amazon systematically relying on non-public business data of independent sellers who sell on its marketplace, to the benefit of Amazon’s own retail business, which directly competes with those third-party sellers.” 

The Commission’s preliminary view is that Amazon’s use of seller data allows the company to skirt the normal risks of retail competition and “leverage its dominance in the market for the provision of marketplace services in France and Germany—the biggest markets for Amazon in the EU.” 

Amazon has denied the charges, which, if proved, could see the company being fined 10% of its global turnover. 

A second formal investigation has been launched by the EC to examine claims that Amazon gives preferential treatment to its own retail offers and to marketplace sellers that use Amazon’s logistics and delivery services.

“We must ensure that dual role platforms with market power, such as Amazon, do not distort competition,” said EC executive vice president Margrethe Vestager, in charge of competition policy. 

“Data on the activity of third-party sellers should not be used to the benefit of Amazon when it acts as a competitor to these sellers.”

Vestager added that an increase in the number of people shopping online meant the need for a level playing field for consumers and sellers was crucial.

“With e-commerce booming, and Amazon being the leading e-commerce platform, a fair and undistorted access to consumers online is important for all sellers,” she said. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#EdgeLive: Security Pros Can Harness Paul Rudd’s Superpower of Adaptability

#EdgeLive: Security Pros Can Harness Paul Rudd’s Superpower of Adaptability

The importance of continuous adaption was outlined by Hollywood actor Paul Rudd during a fireside chat at the Akamai Edge Live virtual conference. These insights have relevance to the cybersecurity industry as it pivots to the huge environmental changes brought about by the COVID-19 pandemic.

Rudd has taken on a vast range of acting roles during his career, ranging from theater to comedy to more recently, becoming a superhero in the Marvel movies.

It was perhaps his decision to join the Marvel universe as Ant Man in 2015 that was the biggest challenge, forcing him to step well and truly outside of his comfort zone. “I’d never been to a Comic Con in my life,” he explained. “I had to go to one in San Diego when they announced Ant Man and I did the panel with the Avengers. To go to a Comic Con with the Avengers is like going to a music convention with the Beatles; I’d never seen fandom like that.”

Entering a completely new environment in which fans (or customers) have different expectations and needs, has big parallels with the security industry this year given the dramatic shift to remote working as a result of COVID-19. For example, organizations are increasingly finding that the traditional perimeter approach to security is no longer viable, with staff and corporate devices no longer operating across a single network.

This scenario was of course brought about by circumstances that no one could have predicted, and in many ways, that’s how Rudd’s career has panned out. It was always his intention to act, having attended an acting school, yet there was no script for the journey he has ended up taking. “Nothing ever happens like you think it’s going to happen,” he outlined.

From initially focusing on theater work, he explained how playing in the comedy film Wet Hot American Summer began a snowballing effect which led to roles in iconic comedies such as the film Anchorman and hit TV series Friends.

As with most industries, the media and entertainment sector has had to pivot enormously in the face of social distancing restrictions this year. While disruptive, Rudd believes many of these, such as the much greater use of video calls and the ability to work from home (for Rudd, doing voiceovers from his closet), are here to stay and will enhance people’s lives over the long term. He commented: “I was able to do things I never thought I’d be able to do and I hope some of those things stay. You adapt and soldier on.”

It is this willingness to adapt that needs to be embraced by cybersecurity professionals. It seems certain that remote working will be much more prevalent going forward, and there are huge benefits to individuals and businesses alike in doing so. Securing this new environment is therefore an opportunity as much as it is a challenge.

Akamai VP Ross Feinberg concluded: “Adapting to change can be painful at times, but as Paul said, we need to be able to turn on a dime, and that’s true in business as well as in our personal lives. With that willingness to adapt, maybe we’ll all discover some superpowers we never knew we had.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CREST and CMMC Center of Excellence Partner to Validate DoD Contractor Security

CREST and CMMC Center of Excellence Partner to Validate DoD Contractor Security

CREST International has partnered with the Cybersecurity Maturity Model Certification Center of Excellence (CMMC COE), to advance the cyber and supply chain security and resilience of the US Department of Defense (DoD) global Defense Industrial Base (DIB) network of contractors, suppliers and vendors.

The Memorandum of Understanding will establish an evaluation process to validate the capabilities, experience and integrity of CMMC COE provider partners. CREST, which provides internationally recognized accreditations for organizations offering technical security services, will help expand the adoption and use of CMMC-based cybersecurity practices for both the DIB contractor and information and communications technology communities.

This will create the capacity to validate CMMC providers in the areas of training and education, readiness assessment, development and implementation of a tailored plan of action and milestones to advance preparedness and continuous monitoring to ensure maintenance of certification compliance.

The partnership will operate in locations across Europe, Asia, Australia and the US, with the purpose of ultimately developing more security and resilience throughout the global DIB.

John Weiler, chairman of the board at the CMMC COE, commented: “This is a momentous occasion for us. Our global expansion will further help advance the goals and objectives for improving the supply chain security and resilience of the US DoD beyond North America.”

Tom Brennan, chairman of CREST USA, added: “This new partnership between CREST and CMMC COE will play an important role in strengthening the resilience and protection of vital critical national infrastructure through structured testing to validate security defenses and controls, carried out by highly-qualified and certified professionals.

“It is vital that the buying communities in both the public and private sectors have the confidence and trust that their employees, contractors or suppliers have the highest levels of knowledge, skill and competence.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Barracuda Acquires Zero-Trust Network Access Innovator Fyde

Barracuda Acquires Zero-Trust Network Access Innovator Fyde

Security solutions provider Barracuda has announced the acquisition of zero-trust network access (ZTNA) innovator Fyde.

The deal will see remote working-focused zero-trust access capabilities added to Barracuda’s security offering with the Fyde solution available immediately as Barracuda CloudGen Access to businesses of all sizes. It will be available in the coming weeks for managed service providers.

“Remote work is here to stay, cloud migrations are accelerating and traditional corporate perimeters have disappeared,” said BJ Jenkins, president and CEO at Barracuda. “Fyde offers a powerful ZTNA solution that works on any infrastructure, any device and with any application on a corporate network. With this acquisition, Barracuda is providing distributed businesses a new way to modernize remote access, enforce global security and access policies and achieve seamless connectivity without compromising productivity.”

With the acquisition, Barracuda expands its capabilities to offer:

  • Secure single sign-on to SaaS applications
  • Secure access to applications from BYOD devices
  • Simultaneous access to applications located on-premises and on multiple clouds
  • Mobile device security monitoring and protection against malicious websites
  • Simplified privileged access and more

Financial terms of the deal have not been disclosed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#EdgeLive: Stopping API Attacks with Bot Mitigation

#EdgeLive: Stopping API Attacks with Bot Mitigation

Attacks on APIs can be mitigated with efficient bot management.

Speaking on a panel session moderated by Mark Schimmelbusch at the Akamai Edge Live virtual conference, Akamai engagement managers Jason Wood and Viktoriya Reyzelman said that the tools to enable attacks on APIs have evolved over the past few years, and are commonly low level and harder to detect.

Schimmelbusch explained that attackers often target the API as the goal to target entire organizations in these instances, not targeting single applications or a single channel. Reyzelman said Akamai saw two million credential abuse attempts in 30 days, and it was able to block 71,000. “You need to have bot management solutions in place to be actively monitoring and protecting,” she said.

Looking at gaming, Wood said Akamai had seen upwards of 100 billion credential stuffing attacks, and nine billion were against gaming. “Games rely on APIs, and most are core to functionality,” he said. “In one case we looked at a customer’s API traffic, and 50% of the customer traffic came from bots. You need to know why you’re attacked, and have a multi-layered toolset to make the right decisions.”

The three speakers said the issue is not going away, while Schimmelbusch added that the motivation and potential for monetary gain is there. “I feel the threat of credential abuse of fraud is there also.” Reyzelman said 70% of retailers’ traffic is from bots, so it is critical to monitor proactively, as “bots are not something to forget about.”

Wood said he has had gaming customers reach out as they thought there were under a DDoS attack, but it was smaller. “That is a tell tale sign, that it is low and slow,” he said, adding that if you look at APIs and see a botnet leverage login credentials, the symptoms are out there and “until you look at it you don’t know what is going on.”

Outlining at a three-step mitigation strategy, Schimmelbusch recommended the following:

  • Short-term (next week): assess your critical transactional endpoints and identify potential security risks, especially those that use APIs
  • Medium-term (next three months): understand who is accessing your endpoints from where and how, and define appropriate security measures
  • Long-term (next six months): select security solutions that protect proactively, tailored to your organization’s needs, and drive an implementation project to protect your endpoints from credential abuse and fraud

Speaking in the opening keynote of the event on Tuesday, Akamai CEO Tom Leighton said attacks by malicious bots had increased by 134%, and organizations need to consider DDoS prevention. “You need to worry about site takeover, account and site scraping, and you need to worry about form jacking and protecting your users’ private information,” he said.

“Magecart attacks are rampant now, everyone is using third party scripts with code that links to third parties and then fourth parties, and all you need is one of those fourth parties to have malware on their site, and when users go to your site it is going to wind up on their browser and cause them to give up their private and personal information. That is a bad outcome for everyone.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Patch Tuesday: Dangerous Zero-Day Hides Among Another 100+ CVEs

Patch Tuesday: Dangerous Zero-Day Hides Among Another 100+ CVEs

After a brief respite last month, Microsoft hit system administrators with another large patch load this month, issuing fixes for 112 CVEs including one being actively exploited in the wild.

The updates for November cover a wide range of products including Windows, Office and Office 365, IE, Edge, Edge Chromium, Exchange Server, Microsoft Dynamics, Azure Sphere, Windows Defender, Microsoft Teams, Azure SDK, DevOps, ChakraCore and Visual Studio.

However, experts are urging customers to prioritize CVE-2020-17087, an Elevation of Privilege bug in the Windows Kernel Cryptography Driver. It affects all versions of the OS, from the Extended Security Update (ESU) in Windows 7 and Server 2008 up to the latest Windows 10 20H2 versions. 

“While the vulnerability is only rated as Important by Microsoft, it is a zero-day vulnerability and has been publicly disclosed. This means attackers have already been detected using it in the wild and information on how to exploit it has been distributed publicly, allowing additional threat actors easy access to reproduce this exploit,” explained Ivanti senior product manager, Todd Schell.

“CVE-2020-17087 was discovered by Google researchers as being exploited in tandem with a Google Chrome flaw (CVE-2020-15999), for which an update was made available on October 20. The two vulnerabilities should be resolved as soon as possible.”

Meanwhile, Qualys vulnerability signatures product manager, Animesh Jain, warned of six flaws in SharePoint that should be fairly high up on the to-do list.

“Three of these vulnerabilities (CVE-2020-17016, CVE-2020-17015, CVE-2020-17060) involve spoofing vulnerabilities, and two (CVE-2020-16979CVE-2020-17017) involve information disclosure vulnerabilities,” she explained. “The remaining one (CVE-2020-17061) is a remote code execution vulnerability; because of this, it is highly recommended to prioritize these patches across all SharePoint deployments.”

Many sysadmins will notice that Microsoft has pared back the information it includes with each vulnerability. Although this was ostensibly done to fall in line with industry standard CVSS, some have argued that this makes it harder for non-security specialists to understand how relevant a bug/CVE is to their organization.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cybersecurity Skills Shortage Falls for First Time

Cybersecurity Skills Shortage Falls for First Time

The huge global shortfall in cybersecurity professionals has dropped for the first time since records began, thanks to more joining the industry and pandemic-related uncertainties on the demand side, according to (ISC)2.

The non-profit certifications organization interviewed 3790 industry respondents around the world to better understand the current challenges facing the sector.

Its 2020 Cybersecurity Workforce Study revealed that 700,000 extra professionals, or 25% more than last year’s workforce estimate, have joined the industry — expanding its ranks to around 3.5 million.

The shortfall in skills has therefore dropped from 4.07 million last year to 3.12 million.

Not all of this is good news: the closing gap can partly be explained by job losses as COVID-19 hits security budgets. Nearly a quarter (23%) of respondents said that they or a peer had been let go as a result of the pandemic. More than half (54%) said they’re concerned about personnel spending and 51% are worried about technology spending going forward.

As well as lay-offs, 40% of respondents said that they or a peer had their salary reduced, 36% had their hours reduced and 9% had been moved from a full-time to a contract-based role.

In fact, in a new PwC report, over a fifth (22%) of UK business and technology leaders said they are planning to downsize their security teams, versus a global figure of 16%.

The irony is that security has never been more important in a world of mass remote working and digital transformation. Over half (56%) of respondents to the study said their organizations are at risk due to cybersecurity staff shortages.

Cloud security is the most in-demand skillset, with 40% of respondents stating they plan to develop it over the next two years.

Interestingly, only half (49%) of those working in the industry actually have degrees in computer and information sciences, highlighting the importance of employers looking outside the sector to find fresh blood.

A major recruitment drive is still needed to alleviate skills shortages: employment needs to grow by around 41% in the US and 89% worldwide to fill the talent gap, the report claimed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fifth of UK Firms Planning to Downsize Security Teams

Fifth of UK Firms Planning to Downsize Security Teams

Over a fifth (22%) of UK businesses are planning to downsize their cybersecurity teams, despite COVID-19 pressures giving the function a greater role at the heart of organizations, according to PwC.

The consulting giant polled 3249 business and technology executives globally, including 265 from the UK, in order to compile its Cyber Security Strategy 2021 Report.

It revealed that, although 96% of UK respondents have shifted their strategy due to the pandemic, and half claimed that they will now bake security into every business decision, they’re still lagging globally on several fronts.

In terms of headcount, just 16% of global respondents said they are planning to cut the size of their security team, for example, while 51% said they were expecting to hire more staff, versus 42% in the UK.

Elsewhere, just 38% of UK respondents claimed they were very confident their security budget is being allocated to the right risks, versus 44% globally. However, on the positive side, 56% said they were planning to increase these budgets next year, despite only 36% being confident they are getting a good return on their investments.

PwC cybersecurity chair, Richard Horne, said it was surprising that so many organizations lack confidence in their cybersecurity spend.

“It shows businesses need to improve their understanding of cyber-threats and the vulnerabilities they exploit, while changing the way they think about cyber-risk so it becomes an intrinsic part of every business decision,” he argued.

Another area the UK appears to be lagging behind the rest of the world relates to the role of the CISO. Over two-fifths (43%) of global respondents agreed that there will be more frequent interactions between the CISO and CEO or board, but this fell to 34% in the UK.

All of this matters because COVID-19 is accelerating digital transformation and therefore expanding the potential corporate attack surface for many organizations.

A third (34%) of UK leaders said they plan to accelerate digitalization in light of the pandemic, and a majority cited attacks on cloud services (58%), “disruptionware” attacks on critical business services (52%) and ransomware (50%) as the most likely threats over the coming year, according to the report.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk