Clinical Review Vendor Reports Data Breach

Clinical Review Vendor Reports Data Breach

A cyber-attack on the Medical Review Institute of America (MRIoA) may have exposed the personal data of 134,571 individuals.

MRIoA, which is based in Salt Lake City, Utah, said it was “the victim of a sophisticated cyber incident” discovered on November 9, 2021, that resulted in a threat actor’s gaining unauthorized access to its network and exfiltrating data.

MRIoA, which provides clinical reviews and virtual medical opinions, said attackers broke into its computer system by exploiting an alleged vulnerability in a product made by SonicWall. 

Information affected by the incident may have included first and last name, gender, home address, phone number, email address, date of birth and Social Security number; clinical information, such as medical history/diagnosis/treatment, dates of service, lab test results, prescription information, provider name, and medical account number; and financial information, including health insurance policy and group plan number, group plan provider, and claim information.

In a breach report filed with the Maine attorney general, MRIoA stated that it had “retrieved and subsequently confirmed the deletion” of the information exfiltrated in the attack.

A list of 31 MRIoA clients whose were affected by the cyber-attack was included in the breach report. 

Featured on the list are Horizon Blue Cross Blue Shield of New Jersey, five different branches of Blue Cross and Blue Shield, and the University of Arkansas Medical Benefit Plan.

MRIoA said it is taking steps to beef up its cybersecurity posture. Improvements include constant monitoring of its systems with advanced threat hunting and detection software, and the addition of extra authentication protections to protect system access.

In the wake of the attack, MRIoA said it had new servers “built from the ground up to ensure all threat remnants were removed.”

In a comment issued on Wednesday to ISMG, SonicWall stated: “It is SonicWall’s understanding that the product issue referred to is related to a known vulnerability that was reported and patched by SonicWall.”

The firewall maker confirmed that an intruder had accessed MRIoA’s environment through a SonicWall vulnerability on November 2, 2021.

“That has since been resolved and MRIoA’s environment has been secured,” stated a SonicWall spokesperson.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Teen Makes Tesla Hacking Claim

Teen Makes Tesla Hacking Claim

A teenage cybersecurity entrepreneur in Germany claims to have “full remote control” over more than 25 Tesla cars in 13 countries, including Switzerland.

The self-described IT security specialist and hacker made the claim via his Twitter account @David_colombo_ on Monday. 

Colombo, who is the 19-year-old founder of Colombo Technology, said he can remotely run commands on the compromised vehicles without the owners’ knowledge. Actions that he can allegedly perform include disabling Sentry mode, opening the cars’ doors and windows, flashing their lights, and even starting keyless driving.

The teen also claims to be able to query the exact location of the vehicle, check if the driver is present, and cause music to play on the Tesla’s sound system.

“I think it’s pretty dangerous if someone is able to remotely blast music on full volume or open the windows/doors while you are on the highway,” wrote Colombo on Twitter.

“Even flashing the lights non-stop can potentially have some (dangerous) impact on other drivers,” he added.

Colombo contacted Tesla to make them aware of the alleged issue, though he said it was not caused by a cybersecurity flaw in the cars.

“This is not a vulnerability in Tesla‘s infrastructure,” wrote Colombo. “It’s the owners [sic] faults.”

While Colombo’s alleged access would make it possible for him to play a video to the owners of the compromised vehicles via YouTube and alert them to the issue, the teen was unwilling to take this step.

“I thought about honking and playing a video on the screen but that sounds a bit too intrusive to me,” he wrote. 

Colombo wrote on Tuesday that Tesla’s security team had confirmed to him that they are investigating his claims and will keep him updated on their discovery. 

The teen is currently putting together a write-up regarding the incident, which he will send to MITRE.

Colombo said he “will release it as soon as the vulnerability got [sic] reported to the affected owners and they were able to take appropriate measures.”

The teen said he hadn’t shared any evidence of his claim on Twitter because “that’s not how responsible disclosure works.”

Kevin Dunne, president at Pathlock, commented: “Automakers can benefit from adopting Zero Trust policies, to ensure that they are not providing unnecessary privileges to any single device. 

“Working from the basic assumption that all devices on the network will be compromised, if they haven’t been already, will inevitably lead to better overall security practices and lower risk.”

A teenage cybersecurity entrepreneur in Germany claims to have “full remote control” over more than 25 Tesla cars in 13 countries including Switzerland.

The self-described IT security specialist and hacker made the claim via his Twitter account @David_colombo_ on Monday. 

Colombo, who is the 19-year-old founder of Colombo Technology, said he can remotely run commands on the compromised vehicles without the owners’ knowledge. Actions that he can allegedly perform include disabling Sentry Mode, opening the cars’ doors and windows, flashing its lights, and even starting Keyless Driving.

The teen also claims to be able to query the exact location of the vehicle, check if the driver is present, and cause music to play on the Tesla’s sound system.

“I think it‘s pretty dangerous if someone is able to remotely blast music on full volume or open the windows/doors while you are on the highway,” wrote Colombo on Twitter, 

“Even flashing the lights non-stop can potentially have some (dangerous) impact on other drivers,” he added.

Colombo contacted Tesla to make them aware of the alleged issue, though he said it was not caused by a cybersecurity flaw in the cars.

“This is not a vulnerability in Tesla‘s infrastructure,” wrote Colombo, “It‘s the owners [sic] faults.”

While Colombo’s alleged access would make it possible for him to play a video to the owners of the compromised vehicles via YouTube and alert them to the issue, the teen was unwilling to take this step.

“I thought about honking and playing a video on the screen but that sounds a bit too intrusive to me,” he wrote. 

Colombo wrote on Tuesday that Tesla’s Security Team had confirmed to him that they are investigating his claims and will keep him updated on their discovery. 

The teen is currently putting together a write-up regarding the incident, which he will send to MITRE.

Colombo said he “will release it as soon as the vulnerability got [sic] reported to the affected owners and they were able to take appropriate measures”.

The teen said he hadn’t shared any evidence of his claim on Twitter because “that’s not how responsible disclosure works”. 

A teenage cybersecurity entrepreneur in Germany claims to have “full remote control” over more than 25 Tesla cars in 13 countries including Switzerland.

The self-described IT security specialist and hacker made the claim via his Twitter account @David_colombo_ on Monday. 

Colombo, who is the 19-year-old founder of Colombo Technology, said he can remotely run commands on the compromised vehicles without the owners’ knowledge. Actions that he can allegedly perform include disabling Sentry Mode, opening the cars’ doors and windows, flashing its lights, and even starting Keyless Driving.

The teen also claims to be able to query the exact location of the vehicle, check if the driver is present, and cause music to play on the Tesla’s sound system.

“I think it‘s pretty dangerous if someone is able to remotely blast music on full volume or open the windows/doors while you are on the highway,” wrote Colombo on Twitter, 

“Even flashing the lights non-stop can potentially have some (dangerous) impact on other drivers,” he added.

Colombo contacted Tesla to make them aware of the alleged issue, though he said it was not caused by a cybersecurity flaw in the cars.

“This is not a vulnerability in Tesla‘s infrastructure,” wrote Colombo, “It‘s the owners [sic] faults.”

While Colombo’s alleged access would make it possible for him to play a video to the owners of the compromised vehicles via YouTube and alert them to the issue, the teen was unwilling to take this step.

“I thought about honking and playing a video on the screen but that sounds a bit too intrusive to me,” he wrote. 

Colombo wrote on Tuesday that Tesla’s Security Team had confirmed to him that they are investigating his claims and will keep him updated on their discovery. 

The teen is currently putting together a write-up regarding the incident, which he will send to MITRE.

Colombo said he “will release it as soon as the vulnerability got [sic] reported to the affected owners and they were able to take appropriate measures”.

The teen said he hadn’t shared any evidence of his claim on Twitter because “that’s not how responsible disclosure works”. 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Phishers Take Over FIFA 22 Accounts

Phishers Take Over FIFA 22 Accounts

Cyber-criminals are using social engineering attacks to take over accounts belonging to players of the Electronic Arts video game FIFA 22

In a statement released Tuesday, Electronic Arts said that multiple player accounts had been compromised, and that it was working with the rightful owners of the accounts to restore access.

While the gaming giant’s investigation into the attacks remains ongoing, Electronics Arts estimates that fewer than 50 accounts have been taken over through a combination of phishing techniques and mistakes made by its customer experience team. 

“Utilizing threats and other ‘social engineering’ methods, individuals acting maliciously were able to exploit human error within our customer experience team and bypass two-factor authentication to gain access to player accounts,” said the Electronic Arts Sports FIFA team. 

The team added: “Our investigation is ongoing as we thoroughly examine every claim of a suspicious email change request and report of a compromised account.”

Since discovering the cyber-criminal activity, Electronic Arts has put all its advisors and individuals who assist with the service of EA accounts through individualized re-training and additional team training, with a specific emphasis on account security practices and the phishing techniques used by the attackers. 

The company said it is also implementing additional steps to the account ownership verification process, such as mandatory managerial approval for all email change requests. 

In addition, Electronic Arts said it will be updating the software used by its customer experience so it can better identify suspicious activity, flag at-risk accounts, and slash the risk of human error in the account update process.

“Having strong, unique passwords and enabling MFA are essential to reducing the risk of an account being compromised. However, even with these technical controls, it is still possible that an account can be compromised through social engineering,” commented Javvad Malik, security awareness advocate at KnowBe4.

“It’s why educating users of these threats is vitally important. Whether that be through an organization rolling out a security awareness and training program or be it through useful on-screen hints and tips on consumers’ login pages reminding them to not share personal details or login codes with others, and to be wary of emails claiming to be from the organization.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

European Union to Launch Supply Chain Attack Simulation

European Union to Launch Supply Chain Attack Simulation

The European Union (EU) is planning a major supply chain cyber-attack simulation, it has been reported.

According to Bloomberg, the exercise will take place in the coming days and continue for six weeks. The drill is designed to test member states’ preparedness for an attack affecting the continent’s distribution networks.

Citing internal documents and sources “familiar with the matter,” Bloomberg said that the simulated attack will mainly target supply chains across Europe. The coordinated attack will be based on past supply chain hacks or those considered to be likely in the future to be as realistic as possible.

Those participating in the ‘stress test’ will coordinate diplomatic and public responses to the attacks and deal with the spillover of socioeconomic impacts in other member states.

It is believed the drill was proposed by France, which took over the presidency of the council of the European Union on January 1 2022. Following the exercise, the EU aims to develop a framework for a joint response to a major incident, which it currently lacks.

Recent incidents such as SolarWinds and Kaseya have demonstrated the widespread damage that supply chain cyber-attacks can cause, which appears to be a growing target for threat actors.

Commenting, Todd Carroll, CISO at CybelAngel, said: “Supply chain attacks are an ongoing trend and will only grow in severity. This is largely attributed to the fact that, as a state or organization’s supply chain and digital ecosystems expand, their attack surface grows exponentially along with it. In a few months from now, attacks like SolarWinds may look comparatively small.

“Ransomware can’t be called a hypothetical, systemic risk anymore. It’s now a systemic issue that will only grow. This is yet another clear illustration that cybersecurity impacts physical security and the daily lives of all of us at scale.  

“Unfortunately, we expect more supply chain attacks to occur. As companies increasingly entrust a large part of their services to single points of failure – think AWS or Google – this is becoming a problem, and as such, companies become targets of choice.

“This stress test is a welcomed action plan and highlights the increasing need for early threat detection capabilities and ransomware preparedness. Member states and businesses urgently need to get ahead of threats before attackers beat them to it.”

In December last year, Israel led a similar 10-country attack simulation targeting the global financial system.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

UK Launches Initiative to Develop Global AI Standards

UK Launches Initiative to Develop Global AI Standards

The UK government has announced a new initiative to develop global standards for artificial intelligence (AI).

The Alan Turing Institute, supported by the British Standards Institution (BSI) and the National Physical Laboratory (NPL), will pilot the AI Standards Hub, which is designed to improve AI governance as the use of these technologies increases in society. The hub will be backed by the Department for Digital, Culture, Media and Sport (DCMS) and the Office for AI (OAI).

In its pilot phase, the hub will focus on four areas:

  • Growing UK engagement to develop global AI standards
  • Bringing the AI community together
  • Creating tools and guidance for education, training and professional development
  • Exploring international collaboration with similar initiatives

It is hoped the scheme will help facilitate innovation in AI and unlock the enormous economic potential of these technologies. This can allow organizations to improve their productivity and develop more flexible ways of working, leading to significant societal benefits. For example, in cybersecurity, AI is already playing a vital role in detecting threats and relieving pressures on security teams.  

The UK government has published new research showing that UK businesses spent around £63bn on AI technology and AI related-labor in 2020. It also estimated that investment in AI will reach more than £200bn by 2040.

However, there remains significant security, ethical and legal concerns around the use of AI, including data collection and storage and algorithmic bias. This necessitates the development of standards to ensure these technologies are developed and used correctly.

Commenting on the announcement, DCMS Minister for Tech and the Digital Economy, Chris Philp, said: “It’s imperative the UK remains at the forefront of this transformative technology which is already improving our lives and has huge potential to create new jobs and wealth.

“Today, I’m confirming that the renowned Alan Turing Institute will lead the trial of a new UK program with support from the BSI and NPL to help shape and improve the global standards for AI.”

Scott Steedman, director-general, standards, at BSI, added: “International standards are a vital tool to help unlock the economic potential of AI, including establishing a common language for all to use. BSI, as the national standards body, is ideally placed to convene the AI community in the UK to identify and develop good practices for the development, governance and use of AI technologies that will be internationally recognized.”

The new initiative forms part of the UK’s National AI Strategy, which aims to harness the “power of AI to increase resilience, productivity, growth and innovation across the private and public sectors.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Two Years for Man Who Used RATs to Spy on Women and Children

Two Years for Man Who Used RATs to Spy on Women and Children

A Nottingham man has been jailed for over two years after using remote access trojans (RATs) and other cybercrime tools to spy on women and children.

Robert Davies, 32, is said to have built a sizeable collection of indecent images of his victims, which included at least one teenage girl whom he spied on via a hacked webcam.

Officers from the National Crime Agency (NCA) arrested Davies three times between November 2019 and August 2021 before he was finally brought before a court in September last year.

Davies pleaded guilty to 24 Computer Misuse Act offences, voyeurism, three counts of possessing indecent images of children (IIOC), making IIOC and possessing extreme pornographic images and was handed down a 26-month sentence yesterday at Nottingham Crown Court.

The cyber-voyeur is said to have used RATs to gain remote access to his victims’ machines and devices, where he searched for and exfiltrated compromising images or accessed the webcam function.

He used fake profiles on messaging apps to make initial contact with his targets and persuade them to download malicious links leading to the RAT. Davies also used crypters to help disguise the malware from anti-virus tools, the NCA said.

The agency said he was also a customer of weleakinfo, a site that sells stolen log-ins.

Although Davies is said to have had 27 images and videos of children on his computer, the NCA claimed officers visited over 30 victims during their investigation.

Andrew Shorrock, operations manager from the NCA’s National Cyber Crime Unit, claimed Davies had amassed a cybercrime toolkit.

“Not only was he using these tools to break into people’s devices, he was using them to spy on his unsuspecting victims and to steal naked images of them for his own sexual gratification,” he added.

“Increasing the barrier of entry into cybercrime by reducing the availability of, and accessibility to, off-the-shelf tools is a key focus for the NCA. We work with a range of partners to target both criminals and their infrastructure, to ultimately disrupt and deter this type of offending.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Microsoft Starts 2022 with 97 CVEs in January Patch Tuesday

Microsoft Starts 2022 with 97 CVEs in January Patch Tuesday

Microsoft began the year by publishing fixes for nearly a century of vulnerabilities, nine of which were rated critical and six of which were publicly disclosed.

The Windows OS updates issued this month will fix all of the known bugs, according to Ivanti VP of product management, Chris Goettl.

“While there are no known exploited vulnerabilities this month, the six publicly disclosed vulnerabilities may warrant more immediate attention as they could have exposed proof-of-concept code or other details that can give adversaries additional details to develop an exploit,” he warned.

These include: CVE-2022-21839, a denial of service vulnerability in the Windows event tracing discretionary access control list; an elevation of privilege flaw in Windows user profile service (CVE-2022-21919); and a Windows certificates spoofing vulnerability (CVE-2022-21836).

The remaining three publicly disclosed flaws are remote code execution bugs in Windows Security Center API (CVE-2022-21874), libarchive (CVE-2021-36976) and open source curl (CVE-2021-22947).

According to Automox, this month’s Patch Tuesday has the highest number of critical CVEs since July 2021.

There’s plenty more to keep sysadmins busy. Mozilla resolved 18 CVEs, including nine rated critical in three updates, impacting Mozilla Thunderbird, Firefox and Firefox ESR. Adobe issued five updates resolving 41 vulnerabilities, 22 of which are rated as critical.

There’s also more to come, with Oracle’s quarterly Critical Patch Update set to land next week.

All of this comes as organizations continue to hunt for vulnerable Log4j instances in their IT ecosystem, many of which may be hidden by complex Java dependencies.

“Organizations that were able to respond quickly found that truly understanding their exposure required rolling up their sleeves. They quickly assessed their internal development teams for use of Log4j and their vendor risk management process to determine what vendors they were consuming solutions from and assessing each to determine if they were exposed,” explained Goettl.

“As an additional step, security teams also utilized a variety of custom scanners purpose-built to scan for the Log4j binaries. This is crucial given Log4j was buried many cases in a few layers of JAR files which was throwing many vulnerability scanners off.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Europol Ordered to Delete Vast Trove of Personal Information

Europol Ordered to Delete Vast Trove of Personal Information

Europol has been told to delete a vast data trove of information on individuals with no link to criminality after previously failing to comply with regulations governing the policing body.

The European Data Protection Supervisor (EDPS) notified Europol of the order on January 3, following an inquiry in 2019. It now has 12 months to filter and extract relevant personal data permitted for analysis under the so-called Europol Regulation.

Any data older than six months on individuals not linked to criminality (known as data subject categorization) must be deleted, the EDPS said.

Europol’s apparent foot-dragging and failure to comply with the principles of data minimization and storage limitation enshrined in the Europol Regulation led to a rare admonishment by the EDPS in September 2020.

“Europol has dealt with several of the data protection risks identified in the EDPS’s initial inquiry. However, there has been no significant progress to address the core concern that Europol continually stores personal data about individuals when it has not established that the processing complies with the limits laid down in the Europol Regulation,” explained EDPS Wojciech Wiewiórowski.

“Such collection and processing of data may amount to a huge volume of information, the precise content of which is often unknown to Europol until the moment it is analyzed and extracted – a process often lasting years.”

In fact, the data trove could be more than four petabytes, according to a report in The Guardian , which claimed the information had been extracted over the past six years from crime reports, hacked phones and screening of asylum seekers never involved in any crime.

Europol hit back yesterday, claiming its binding regulation never specified a maximum time period for determining Data Subject Categorisation. The police agency stated that it was not the EDPS that initiated the inquiry and said it would “assess” the data privacy tsar’s decision.

“The EDPS decision will impact Europol’s ability to analyze complex and large datasets at the request of EU law enforcement. This concerns data owned by EU member states and operational partners and provided to Europol in connection with investigations supported within its mandate. It includes terrorism, cybercrime, international drugs trafficking and child abuse, amongst others,” a statement read.

“Europol’s work frequently entails a period longer than six months, as do the police investigations it supports. This is illustrated by some of Europol’s most prominent cases in recent years.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains