{"id":50,"date":"2019-12-29T20:37:00","date_gmt":"2019-12-29T20:37:00","guid":{"rendered":"https:\/\/thecyberstaff.com\/?p=50"},"modified":"2025-12-13T20:38:38","modified_gmt":"2025-12-13T20:38:38","slug":"2019-cyber-news-review","status":"publish","type":"post","link":"https:\/\/thecyberstaff.com\/?p=50","title":{"rendered":"2019 Cyber News Review"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The 2019 Cyber News Review started in April 2019 and provides a weekly review of Cyber Security news.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4\/18\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/chinese-hackers-strike-us-universities-in-bid-for-military-technology\/\">Chinese hackers strike US universities in bid\nfor military technology<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Accenture\u2019s iDefense team has confirmed cyberattacks against at least 27 universities worldwide. \u201cIt is believed that the threat actors behind the campaign have utilized phishing tactics in an attempt to compromise university networks, often by posing as partner universities and institutions.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.bbc.com\/news\/uk-england-dorset-47551331\">GCSE coursework lost in cyber attack on\nBridport school<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A teacher in England opened an email that appeared to come from another teacher at a school nearby. The email contained ransomware that spread to the school&#8217;s network, the article states that the coursework of at least 11 students has been lost. The ransomware infection locked all of the files on the teacher&#8217;s computer then used worm capabilities to spread into the school&#8217;s network infecting other machines. This displays the importance of layered security or defense-in-depth approach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/microsoft-loses-control-over-windows-tiles-subdomain\/\">Microsoft loses control over Windows Tiles\nsubdomain<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Windows 8 and Windows 10 have a feature called live tiles, this feature allows RSS based news and updates from websites to be delivered to the tiles in the start menu. The subdomain that Microsoft set up to allow websites to show live updates inside the start menu has been taken over by the security researcher Hanno B\u00f6ck. &#8220;We won&#8217;t keep the host registered permanently. There&#8217;s a decent amount of traffic reaching this host and running up costs,&#8221; the researcher said. &#8220;Once we cancel the subdomain a bad actor could register it and abuse it for malicious attacks,&#8221; he warned. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5\/3\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blog.knowbe4.com\/scott-county-schools-victim-of-3.7-million-ceo-fraud-scam\">Scott County Schools victim of $3.7 million\nCEO Fraud Phishing Scam<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Scott County Schools in Georgetown Kentucky got an email from a fraudster pretending to be a known vendor. The fraudster told the school they did not pay their invoice and tricked the school into paying the money to the fraudster&#8217;s bank account. The money is gone and the school is going to attempt to get the money back with their cyber fraud insurance, cyber fraud insurance is usually provided to protect unauthorized use of computer systems and may not cover this social engineering attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.welivesecurity.com\/2019\/05\/02\/d-link-camera-vulnerability-video-stream\/\">D-Link camera vulnerability allows attackers\nto tap into the video stream<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Vulnerabilities found in the D-Link DCS-2132L cloud surveillance camera allow attackers to remotely view video streams and manipulate the device&#8217;s firmware. The camera communicates through the cloud to D-Link servers then to users&#8217; smartphones. Network traffic of video streams has been found to be unencrypted and susceptible to a <a href=\"https:\/\/us.norton.com\/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html\">man in the middle attack<\/a>. This shows us how important end to end encryption is, especially when using services in the cloud.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/dell-laptops-and-computers-vulnerable-to-remote-hijacks\/\">Dell laptops and computers vulnerable to\nremote hijacks<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A vulnerability in the Dell SupportAssist application allows a remote attack, in this attack, a hacker can execute code with remote privileges. If the hacker can trick the victim to go to a malicious web page, JavaScript code can trick the Dell SupportAssist application into downloading and running files. Dell was quick to release a patch for this vulnerability but the software comes pre-installed on Dell computers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5\/10\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/05\/baltimore-ransomware-cyberattack.html\">Baltimore City Shuts Down Most of Its Servers\nAfter Ransomware Attack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Baltimore City has been\nhit with Ransomware for the second time in just over a year, the ransomware has\nworm capabilities and has been spreading to different systems on their network.\nCity Hall personnel were told to shut down all of their computers to prevent\nthem from getting the infection, multiple city services are temporarily shut\ndown due to the incident. \u201cA similar ransomware attack hit the Baltimore City&#8217;s\nphone system in March last year, shutting down automated dispatches for 911 and\n311 calls for more than 15 hours.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/microsoft-sharepoint-servers-are-under-attack\/\">Microsoft SharePoint servers are under attack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cHacker groups are\nattacking Microsoft SharePoint servers to exploit a recently patched vulnerability\nand gain access to corporate and government networks, according to recent\nsecurity advisories sent out by Canadian and Saudi Arabian cyber-security\nagencies.\u201d Code has been published to exploit this vulnerability but it does\nnot work out of the box, this means less skilled hackers will not be able to\nuse it easily. The advice to defend against this is to patch SharePoint servers\nand keep them behind a firewall. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.advanced-intel.com\/blog\/top-tier-russian-hacking-collective-claims-breaches-of-three-major-anti-virus-companies\">Top-Tier Russian Hacking Collective Claims\nBreaches of Three Major Anti-Virus Companies<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hackers claim to have breached three leading antivirus companies, there is no indication of what antivirus companies are affected. \u201cThe collective extracted sensitive source code from antivirus software, AI, and security plugins belonging to the three companies.\u201d With this information an attacker would be able to get past the antivirus layer, having extensive knowledge of how a product works is the best way to get past it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5\/17\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/05\/15\/update-now-critical-remote-wormable-windows-vulnerability\/\">UPDATE NOW! Critical, remote, \u2018wormable\u2019\nWindows vulnerability<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft has released a patch for a vulnerability in its Remote Desktop service, this vulnerability could allow an attacker to run malicious code on a system without authenticating. This vulnerability is so bad that Microsoft has sent security patches to Windows XP machines that are no longer supported\/getting regular updates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/paterson-public-schools-notified-of-breach-threatens-with-civil-case\/\">Paterson Public Schools Notified of Breach,\nThreatens with Civil Case<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Paterson Public Schools has been notified about a breach where a hacker claims to have access to systems and over 20,000 accounts. The hacker provided some proof with screenshots of outlook inboxes of two district employees. The school district issued a password reset for all accounts and enabled two-factor authentication in response to the attack. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.schneier.com\/blog\/archives\/2019\/05\/more_attacks_ag.html\">More Attacks against Computer Automatic Update\nSystems<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another supply chain\nattack, this time it is the ASUS live update software that has been infected.\nThe hackers got their malicious code into the ASUS tool so the infection would\nbe delivered to users when they use this tool to update. This is very evil\nbecause updating is one of the ways we stay secure! This attack was discovered\nby Kaspersky and it is called Operation Shadowhammer, the attack also targeted\nsix other companies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.wbaltv.com\/article\/baltimore-government-is-still-recovering-from-ransomware-attack\/27457696\">Six days later, Baltimore government is still\nrecovering from ransomware attack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Baltimore is still working to recover from the ransomware breach email, phones and computers are still unusable. \u201cMayor Jack Young said the city will not pay the ransom, even though it could be the less expensive option.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">5\/24\/2019<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/ohio-school-sends-students-home-because-of-trickbot-malware-infection\/\">Ohio school sends students home because of\nTrickbot malware infection<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">School was canceled on Monday in an Ohio school district due to a malware infection. The school&#8217;s treasury office was targeted and infected, this led to the malware spreading over the school&#8217;s network. The malware is called Trickbot, this malware used to be a banking Trojan but has evolved over the years into a malware swiss army knife. Trickbot has been observed as the first step in many ransomware infections. When a computer is infected with Trickbot, the malware talks back to the hacker&#8217;s command and control server, the hacker can see what the computer is vulnerable to and send more malware to target the vulnerabilities. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/statescoop.com\/2018-was-a-bad-year-for-ransomware-but-so-far-2019-is-no-better\/\">What Colorado learned from treating a\ncyberattack like a disaster<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe Colorado Department of Transportation joined the ranks of dozens of other U.S. government entities affected by the SamSam ransomware virus when it was infected with the malware in February 2018\u201d The state refused to pay the ransom and spent about $1.5 million to remediate the infection- Colorado declared a statewide emergency to bring in resources from the National Guard and other states to help with the remediation. The malware got into the network through a new server that was exposed to the internet with default security settings, the server was infected within 48 hours. Hackers scan the internet 24\/7 looking for servers fully exposed, that is why it is important to harden servers and keep them behind a firewall.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/krebsonsecurity.com\/2019\/05\/account-hijacking-forum-ogusers-hacked\/\">Account Hijacking Forum OGusers Hacked<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A hacker run website used for illegal hacking activities such as hijacking online accounts and sim swapping attacks has been compromised, the database of user accounts and the website source code has been posted on another site. \u201cAlso, federal and state law enforcement investigators going after SIM swappers are likely to have a field day with this database, and my guess is this leak will fuel even more arrests and charges for those involved.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5\/31\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/threatpost.com\/pos-malware-found-at-102-checkers-restaurant-locations\/145181\/\">POS Malware Found at 102 Checkers Restaurant\nLocations<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">POS stands for point of\nsale, the machines used to accept payment methods such as credit cards. POS\nmalware is a malicious program that gets installed on a POS system and collects\ncredit card information, this information is logged on the machine and sent to\na malicious actor. Checkers and Rally\u2019s announced Wednesday that they found POS\nmalware at 102 of their locations across 20 states. Customers that used credit\ncards at these locations could have their cardholder name, payment card number,\ncard verification code and expiration date exposed to malicious actors. This\ninformation is usually collected and sold on the dark web.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/05\/hacking-mysql-phpmyadmin.html\">Hackers Infect 50,000 MS-SQL and PHPMyAdmin\nServers with Rootkit Malware<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cCyber Security researchers at Guardicore Labs today published a detailed report on a widespread cryptojacking campaign attacking Windows MS-SQL and PHPMyAdmin servers worldwide.\u201d This campaign is being carried out by an APT style Chinese hacking group, they have already infected 50,000 servers. The attack uses the brute-forcing technique after finding publically accessible Windows MS-SQL and PHPMyAdmin servers using a simple port scanner. The group obtains administrator privileges before executing sequences of SQL commands to download a malicious payload from a remote server. This attack relies on weak username and password combinations for MS-SQL and PHPMyAdmin servers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6\/21\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/sim-swap-horror-story-ive-lost-decades-of-data-and-google-wont-lift-a-finger\/\">SIM swap horror story: I&#8217;ve lost decades of\ndata and Google won&#8217;t lift a finger<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A hacker called T-Mobile and ordered a sim card for a Zdnet employees phone, T-Mobile sent the hacker the sim card! This type of attack is called Sim Swapping, the hacker took over the victim&#8217;s main cell phone number and used it to compromise all of his accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/protect-your-online-identity-now-fight-hackers-with-these-5-security-precautions\/\">Protect your online identity now: Fight\nhackers with these 5 security safeguards<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article goes over 5 steps that can be used to help prevent Sim Swapping attacks. Sim Swapping is where a bad guy gets a sim card with your phone number and uses it to take over your number. This will usually deactivate your phone&#8217;s sim card making your phone unable to make calls or use the mobile network. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.pcmag.com\/news\/369122\/florida-city-to-pay-600-000-to-hackers-after-ransomware-att\">Florida City to Pay $600,000 to Hackers After\nRansomware Attack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Florida City just paid 65 bitcoin ($600,000) to get their data decrypted. This attack started with a police officer opening a malicious email. When you pay the bad guys to get the decryption keys they are starting to offer support to help convert your money into bitcoin and support for running the decryption program.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6\/28\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/aws-s3-server-leaks-data-from-fortune-100-companies-ford-netflix-td-bank\/\">AWS S3 server leaks data from Fortune 100\ncompanies: Ford, Netflix, TD Bank<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When data is stored in the cloud, it has to be protected with layered security, some organizations feel they are protected when a vendor stores their data for them, but this is not always the case. Attunity, an Israeli IT firm that provides data management, warehousing, and replication services for the world&#8217;s biggest companies, has exposed some of its customers&#8217; data after it left three Amazon S3 buckets exposed on the internet without a password. The data included some of Attunity&#8217;s own operations, but also data from some of its customers &#8212; Fortune 100 companies like Ford, Netflix, and TD Bank.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/06\/dhs-cyber-director-warns-of-surge-in-iranian-wiper-hack-attacks\/\">DHS cyber director warns of surge in Iranian\n\u201cwiper\u201d hack attacks<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Department of\nHomeland Security&#8217;s Cybersecurity and Infrastructure Security Agency is warning\nof increased cyber threats from Iran due to current tensions with the US.\nIranian actors are using \u201cwiper\u201d attacks where they cause destruction by\ndeleting data. There have been allegations of Iranian-backed wiper attacks in\nthe past\u2014the most infamous of which is Shamoon, a family of malware that first\nemerged in an attack against Saudi Aramco in August of 2012.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>7\/12\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/07\/12\/apple-watchs-walkie-talkie-app-goes-radio-silent-due-to-vulnerability\/?utm_source=Naked+Security+-+Sophos+List&amp;utm_campaign=39dfdde181-Naked+Security+-+July+test+-+groups+1+and+3&amp;utm_medium=email&amp;utm_term=0_31623bb782-39dfdde181-455503189\">Apple Watch\u2019s Walkie-Talkie app goes radio\nsilent due to vulnerability<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cApple\u2019s shut down its\nWatch Walkie-Talkie app after somebody reported a bug that could have allowed\nan eavesdropper to surreptitiously listen in on somebody else\u2019s iPhone, the company\ntold&nbsp;<a href=\"https:\/\/techcrunch.com\/2019\/07\/10\/apple-disables-walkie-talkie-app-due-to-vulnerability-that-could-allow-iphone-eavesdropping\/\">Tech Crunch<\/a>&nbsp;on Wednesday evening.\u201d &nbsp;Apple had a similar issue in\nJanuary where eavesdropping was possible through a FaceTime call before the\ncall was answered.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/07\/whatsapp-android-malware.html\">New Malware Replaced Legit Android Apps With\nFake Ones On 25 Million Devices<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This Android malware was\ndelivered through 3<sup>rd<\/sup> party app stores, you are usually safe using\nthe default Google play store. Some countries cannot connect to Google\u2019s\nservices so they have to rely on other app stores to deliver apps to their\nmobile devices. This malware has been named \u201cAgent Smith\u201d and it takes\nadvantage of Android vulnerabilities to install a malicious version of an app\non a mobile device, the app then functions the way it is supposed to with added\nmalicious capabilities. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/threatpost.com\/google-home-recordings-domestic-violence\/146424\/\">Google Home Silently Captures Recordings of\nDomestic Violence and More<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cGoogle is under fire after a report found that Google Home and Google Assistant records user audio, even when no wake-up word is used.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>7\/26\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/edscoop.com\/ellucian-banner-cyberattacks-62-universities\/\">Ellucian systems compromised at 62\nuniversities, Education Dept. says<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hackers have compromised Ellucians Banner platform and compromised information systems at 62 universities. The attack exploited a security flaw that allowed hackers to generate masses of fake student accounts and potentially access sensitive data. Ellucian released a patch in May that will close the security hole. This is an example of a supply chain attack. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/bradford-man-arrested-over-lancaster-university-hacking-spree\/\">Bradford man arrested over Lancaster\nUniversity hacking spree<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A British man has been\narrested on suspicion of breaking into Lancaster University systems and\nstealing records belonging to students. Lancaster University deemed the\nincident &#8220;a sophisticated and malicious phishing attack which has resulted\nin breaches of student and applicant data.&#8221; Fake invoices in phishing\nemails have also been sent to some students, which may indicate that the ransacking\nof university data was the first stepping stone into what could have become\nfinancial theft.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/07\/cyberattack-power-outage.html\">Ransomware Attack Caused Power Outages in the\nBiggest South African City<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Yesterday, some\nresidents of Johannesburg, the largest city in South Africa, were left without\nelectricity after the city&#8217;s power company got attacked by a ransomware virus.\nCity Power, the company responsible for powering South Africa&#8217;s financial\ncapital Johannesburg, confirmed Thursday on Twitter that it had been hit by a\nRansomware virus that had encrypted all of its databases, applications, and\nnetwork.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>8\/2\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/start.jcolemorrison.com\/the-technical-side-of-the-capital-one-aws-security-breach\/\">The Technical Side of the Capital One AWS\nSecurity Breach<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOn July 19th, 2019 Capital One got the red flag that every modern company hopes to avoid &#8211; their data had been breached. Over 106 million people affected. 140,000 Social Security numbers. 80,000 bank account numbers. 1,000,000 Social Insurance Numbers.\u201d The hacker compromised a server in AWS (Amazon web services cloud) through a firewall misconfiguration, the hacker got onto the server with an account that had permissions to access 700+ AWS buckets. The hacker then copied all data from the buckets in the cloud took a copy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/arstechnica.com\/tech-policy\/2019\/07\/louisiana-declares-state-emergency-in-response-to-ransomware-attack\/\">Louisiana declares state of emergency in\nresponse to ransomware attack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThis Wednesday, Louisiana Governor John Bel Edwards declared a state of emergency in response to ransomware attacks on three public school districts.\u201d The technology supervisor received an alert on his phone at 4 am on a Sunday about unusually high bandwidth usage, shortly after they found ransomware on their servers. The Principal said \u201canything and everything housed solely on the School District&#8217;s servers&#8221; was lost, including 17 years of his own personal documents\u201d. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.google.com\/maps\/d\/viewer?mid=1UE6Nko9iRG1tLci_AeqqsxzxGzs&amp;ll=36.15241077097511%2C-91.41670479754634&amp;z=4\">Google Ransomware Map<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This link leads to a\nGoogle map with ransomware attacks noted by location, you can even click on the\nlocations to pull up the article that explains the ransomware attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>8\/9\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thenextweb.com\/security\/2019\/08\/06\/malware-attacks-on-infrastructure-and-state-run-facilities-shot-up-200-in-2019\/\">Malware attacks on infrastructure and\nstate-run facilities shot up 200% in 2019<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Malware attacks are up in 2019; \u201cIBM said 50 percent of the malware attacks were in the manufacturing, oil and gas, and education sectors. Most of the destructive attacks observed by the team have taken place in Europe, the US, and the Middle East.\u201d This article states that cybercriminals are primarily leveraging phishing emails and password-guessing attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.govtech.com\/education\/Data-Breach-Exposes-Personal-Info-for-53000-Illinois-Students.html\">Data Breach Exposes Personal Info for 53,000\nIllinois Students<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe personal\ninformation of nearly 53,000 students and 3,100 educators in Naperville\nDistrict 203 and Indian Prairie District 204 was exposed following a data\nbreach at a company that handles the districts\u2019 K-8 academic assessments.\u201d The\nvendor that was responsible for the breach was Pearson, a compromise of their\nAIMSweb software was what lead to the breach. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.kcchronicle.com\/2019\/08\/07\/district-303-304-student-information-exposed-in-data-breach\/alqud6b\/\">District 303, 304 student information exposed\nin data breach<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cST. CHARLES \u2013 Students in Geneva Community Unit School District 304 and St. Charles Community Unit School District 303 had personal information exposed in a data breach.\u201d This breach was also caused by Pearson\u2019s AIMSweb, this article even states that the districts no longer use AIMSweb.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>8\/16\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/700000-choice-hotels-records-leaked-in-data-breach\/\">700,000 Choice Hotels records leaked in data\nbreach, ransom demanded<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Choice hotel brand had a database publicly available on the internet with no password, leaving a total of 5.6 million records exposed. The hackers copied the data and have demanded .4 Bitcoin (about $4,000) for the return of the data. The database belonged to a vendor that was not named. The data contained guest&#8217;s names, email addresses, and phone numbers, the data is not extremely sensitive but can be used in targeted phishing campaigns that lead to bigger attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/threatpost.com\/energy-phish-microsoft-security-google-drive\/147397\/\">Energy Sector Phish Swims Past Microsoft Email\nSecurity via Google Drive<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is an example of how hackers get past security controls, in this instance, they do not put their malicious link in an email because it will get blocked. Instead, they share a Google doc with you, the link to the Google doc is not malicious so it will not be blocked by email security. Inside the Google doc the hacker places the malicious link. Most users trust Google docs so they will fall for this trick. The attacks will continue to evolve showing us the importance of user security awareness and education.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/08\/dslr-camera-hacking.html\">Canon DSLR Cameras Can Be Hacked With\nRansomware Remotely<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ransomware is getting so popular it is moving to more devices, this article explains how a researcher installed ransomware on a Canon DSLR camera. This attack is possible over USB and Wi-Fi. There is a video in this article that shows the researcher installing the ransomware over Wi-Fi. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>8\/23\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.theverge.com\/2019\/8\/20\/20823139\/texas-towns-ransomware-attack-cities-fbi-threat-computers-offline\">22 Texas towns hit by coordinated ransomware\nattack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">22 Texas towns have been\ncompromised in a coordinated ransomware attack that appears to have been pulled\noff by one single threat actor. \u201cBorger, Texas and Keene, Texas have announced\nthat they were affected by the attack. The city of Borger says it is unable to access\nbirth and death certificates or take utility payments, and NPR reports that\nKeene is unable to process utility payments.\u201d The mayor of Keene told NPR that\nthe hacker has asked for $2.5 million to unlock the files, he said they will\nnot be paying the ransom. Some of the Texas towns have shut off all of their\ncomputer systems as a response to the attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.idahopress.com\/news\/local\/2cscoop\/nampa-school-district-victim-of-cyber-attack\/article_f9bd7e6b-d00c-5e2f-8ce5-9e10375cb1d7.html\">Nampa School District victim of cyber attack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Nampa school district in Idaho has been hit with a malware attack, the school&#8217;s network and systems have been down for several days. They have instructed their teachers and administrators to go back to using pen and paper or their own devices until the attack is remediated. The school will remain in session without the network and systems until they can restore them. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/08\/22\/quick-thinking-by-portland-public-schools-stops-29m-bec-scam\/?utm_source=Naked+Security+-+Sophos+List&amp;utm_campaign=9615e3e079-Naked+Security+-+Aug+2019+-+ad+A+%28G1%2C2%2C3%2C4%29&amp;utm_medium=email&amp;utm_term=0_31623bb782-9615e3e079-455503189\">Quick thinking by Portland Public Schools stops\n$2.9m BEC scam<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cEmployees at Portland Public Schools were breathing easier this week after thwarting a business email compromise (BEC) scam that could have cost them almost $3m.\u201d A fraudster contacted them pretending to be a construction contractor they were working with, the fraudster asked for payments to be made of $2.9 million into a fake account. The employee from the school approved the payments and sent the $2.9 million. The school caught on and worked with the bank to freeze the fraudulent funds before it was too late.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>8\/30\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/microsoft-using-multi-factor-authentication-blocks-99-9-of-account-hacks\/\">Microsoft: Using multi-factor authentication\nblocks 99.9% of account hacks<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft is reporting\nthat using MFA will block 99.9% of attacks, this information is very\ninteresting considering the rise in account compromises. The article talks\nabout the many ways hackers get passwords such as credential stuffing,\nphishing, keystroke logging, local discovery, extortion, password guessing and brute\nforcing. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.ibtimes.sg\/cyber-security-lake-county-govt-forced-shut-down-servers-after-ransomware-attack-32219\">Cyber Security: Lake County Govt forced to\nshut down servers after ransomware attack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">More Ransomware, this time it is Lake County Illinois that got hit. The attack has forced them to shut down their email and several other internal applications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.newsday.com\/long-island\/education\/hackers-ramsomware-school-districts-1.35422441\">Rockville Centre pays almost $100G to hackers\nafter ransomware attack, officials say<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe Rockville Centre school district paid almost $100,000 to restore its data after being hacked with a ransomware virus that encrypted files on the system\u2019s server until payment was made to unlock the information, officials said Friday.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/news.yahoo.com\/amphtml\/warning-to-android-users-as-pdf-app-used-by-100-million-contained-malware-195553244.html\">Warning to Android users as PDF app used by\n100 million \u2018contained malware\u2019<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A popular Android app\ncalled CamScanner has been identified as malicious, the app does everything it\nis advertised to do but also has malicious code that does bad things in the\nbackground. It is important to audit your apps and remove what you no longer\nneed. We cannot see the code behind the application so it is difficult to tell\nwhen an app is doing something malicious. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blog.malwarebytes.com\/trojans\/2019\/08\/trojans-ransomware-dominate-2018-2019-education-threat-landscape\/?mkt_tok=eyJpIjoiT0dSbFlqQmlZemhqTVdKbSIsInQiOiI3RmlkbjhpU2hCYVQwODF0aVhUSjBuMUV0WUtqY3Uxbzk0ZEV6U2FzdStteUdtakVPaTZVNGI0YUg2OFpXTTUwVkh1b1wvOU9NdWQ0c0RBcEx2cU9WMXVkcUlmRHF5NU1Pb1BSNWFcL2NDa0FIaUE0REllRThMZnJoYVBpV09HSGdlIn0%3D\">Trojans, ransomware dominate 2018\u20132019\neducation threat landscape<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article talks about hackers targeting the education field, the reasons include smaller budgets, old equipment and the use of personal devices. The article explains how the threats will get worse as time goes on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">9\/6\/2019<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/08\/rash-of-ransomware-continues-with-13-new-victims-most-of-them-schools\/\">Rash of ransomware continues with 13 new\nvictims\u2014most of them schools<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">More information on how\nschools are becoming a popular target for ransomware. \u201cAccording to Armor&#8217;s\ndata, schools have become the second-largest pool of ransomware\nvictims\u2014slightly behind local governments and closely followed by healthcare\norganizations.\u201d Below are recent ransomware infections.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.nwitimes.com\/news\/cyber-attack-forces-emergency-shutdown-of-lake-county-government-servers\/article_a4b36fa8-61fa-5817-a243-a49c2982c1c8.html\">Lake County,\n     Indiana<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.newsday.com\/long-island\/education\/hackers-ramsomware-school-districts-1.35422441\">Rockville\n     Center School District in Rockville Center, New York<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.columbiabasinherald.com\/local_news\/20190825\/mlsd_details_july_cyber_attack_on_districts_network\">Moses Lake\n     School District in Moses Lake, Washington&nbsp;<\/a>&nbsp;(the\n     attack apparently occured in July but was only reported as ransomware this\n     month<\/li>\n\n\n\n<li>Mineola\n     Public Schools in&nbsp;<a href=\"https:\/\/www.msspalert.com\/cybersecurity-breaches-and-attacks\/ransomware\/ryuk-hits-rockville-centre\/\">Mineola, New\n     York<\/a><\/li>\n\n\n\n<li>The Stevens\n     Institute of Technology in&nbsp;<a href=\"https:\/\/www.insidehighered.com\/news\/2019\/08\/27\/two-universities-targeted-hackers-just-new-school-year\">Hoboken, New\n     Jersey<\/a><\/li>\n\n\n\n<li>New Kent\n     County Public Schools in New Kent, Virginia<\/li>\n\n\n\n<li>Nampa Idaho\n     School District,&nbsp;<a href=\"https:\/\/cybersecurityfuture.wordpress.com\/2019\/08\/28\/idaho-schools-under-ransomware-attack-will-ransomware-make-america-great-again\/\">Nampa, Idaho<\/a><\/li>\n\n\n\n<li>Middletown\n     School District,&nbsp;<a href=\"https:\/\/www.courant.com\/community\/middletown\/hc-news-middletown-school-ransomware-20180629-story.html\">Middletown,\n     Connecticut<\/a><\/li>\n\n\n\n<li>Wolcott\n     Public Schools,&nbsp;<a href=\"https:\/\/www.wtnh.com\/news\/connecticut\/new-haven\/ransomware-attack-locks-out-school-district-for-3-months\/\">Wolcott,\n     Connecticut<\/a><\/li>\n\n\n\n<li>Wallingford\n     School District,&nbsp;<a href=\"https:\/\/www.nbcconnecticut.com\/news\/local\/Schools-Targeted-by-Hackers_Hartford-513207932.html\">Wallingford,\n     Connecticut<\/a><\/li>\n\n\n\n<li>New Haven\n     Public Schools,&nbsp;<a href=\"https:\/\/www.nbcconnecticut.com\/news\/local\/Schools-Targeted-by-Hackers_Hartford-513207932.html\">New Haven,\n     Connecticut<\/a><\/li>\n\n\n\n<li>The\n     Watertown Daily Times in&nbsp;<a href=\"https:\/\/cnycentral.com\/news\/local\/watertown-newspaper-hacked-cannot-print-sunday-editions\">Watertown,\n     New York<\/a><\/li>\n\n\n\n<li>Hospice of\n     San Joaquin,&nbsp;<a href=\"https:\/\/www.hipaajournal.com\/rhode-island-healthcare-provider-hacked-3000-records-potentially-compromised\/\">San Joaquin,\n     California<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.secureworldexpo.com\/industry-news\/ransomware-attack-cancels-school-2019?utm_campaign=Industry%20News&amp;utm_source=hs_email&amp;utm_medium=email&amp;utm_content=76512729&amp;_hsenc=p2ANqtz--OQDdsSJkk5V_t5FDRUd-VkTFVzld9EvRJTyf2mtAIjc9bx8Pwu1cyv42wpmrkUX8bfK7RuG_O7glzJnUqoIGL7sqhoPnqJwh7mjzzmhMoQpRDXHM&amp;_hsmi=76512977\">Ransomware Attack: District Suddenly Cancels\nSchool and Childcare for Thousands<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Flagstaff, Arizona, school district called off school due to a ransomware attack. This school was also affected by the AIMSweb 1.0 data breach last month as well. No information on how they got infected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/ransomware-gang-wanted-5-3-million-from-us-city-but-they-only-offered-400000\/\">Ransomware gang wanted $5.3 million from US\ncity, but they only offered $400,000<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A ransomware gang\ninfected New Bedford, Massachusetts with ransomware and demanded $5.3 million\nfor the decryption keys. New Bedford Mayor Jon Mitchell offered the hackers\n$400,000 and they did not accept the offer, New Bedford then started the\nprocess of restoring from backups and other systems that did not get infected.\nThe ransomware attack only affected 4% of their network, this infection\nhappened back in July and they kept it quiet until now. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.consumer.ftc.gov\/blog\/2018\/08\/selling-your-car-clear-your-personal-data-first\">Selling your car? Clear your personal data\nfirst.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now that cars have built-in WiFi, Bluetooth, Navigation and other technical features it is important to wipe your data before selling the car. Here are some types of data you want to remove from the electronic system before selling or donating your car:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Phone contacts and an address book&nbsp;may have been downloaded when you synced your phone with your vehicle.<\/li>\n\n\n\n<li>Mobile apps\u2019&nbsp;log-in information, or data that\u2019s gathered and stored on mobile apps, may be stored in the car.<\/li>\n\n\n\n<li>Digital content&nbsp;like music may be stored on a built-in hard drive.<\/li>\n\n\n\n<li>Location data&nbsp;like addresses or the routes you take to home, work, and favorite places may be stored in your navigation system.<\/li>\n\n\n\n<li>Garage door codes&nbsp;for your home or office may be on your system.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>9\/13\/2049<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/seems-phishy-back-school-lures-target-university-students-and-staff\">Seems Phishy: Back to School Lures Target\nUniversity Students and Staff<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Proofpoint has identified an uptick in college-themed targeted phishing emails when school starts back up for the year. A typical medium volume phishing campaign sends thousands or tens of thousands of emails a day! The email templates observed have been made to look like library and student portal logins. The fraudulent web pages are made up to look identical to the pages that the colleges use, the best way to identify the fake pages is by observing the URL to see if it is the correct school URL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.secureworks.com\/blog\/cobalt-dickens-goes-back-to-school-again\">COBALT DICKENS Goes Back to School\u2026Again<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">COBALT DICKENS is a name\nassigned to a threat group that targets colleges. 9 members of this group have\nrecently been caught: \u201d<em>In March 2018, the U.S. Department of Justice&nbsp;<\/em><a href=\"https:\/\/www.justice.gov\/opa\/pr\/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary\"><em>indicted<\/em><\/a><em>&nbsp;the Mabna Institute and\nnine Iranian associates for compromising hundreds of universities to steal\nintellectual property and benefit financially.\u201d <\/em>The group was caught sending\nphishing emails to college libraries with SSL certificates to make the web\npages look legitimate. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.denverpost.com\/2019\/09\/06\/regis-university-cybersecurity-attack-student\/\">Who\u2019ll benefit from the Regis University\ncyberattack? The Denver school\u2019s cybersecurity students.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regis University teaches students what to do in the event of a cyber-attack, they were victims of an attack themselves. They will use their attack as a case study in classrooms to teach students what they did to remediate the breach. With cyber-attacks becoming more common, experience in remediating them is very valuable. \u201c<em>Shari Plantz-Masters, dean of Regis\u2019s College of Computer and Information Sciences, said the university plans to hold an invitational conference when the situation is resolved to talk about what they learned and help prepare others<\/em>.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.secureworldexpo.com\/industry-news\/the-2-college-kids-who-nearly-hacked-their-way-to-president-trumps-tax-returns?utm_campaign=Industry%20News&amp;utm_source=hs_email&amp;utm_medium=email&amp;utm_content=76791158&amp;_hsenc=p2ANqtz-8Meg_ttipO2Df0wiRf3XwOGacvGkz1TXQJ1gnE_blubgKHyahN63KTsG1vScn7ngiyCEr009KHuR0UJdkxdNp0aVTwTjOVa7RcHkPuJsdgOx9NPk4&amp;_hsmi=76791225\">The Two College Kids Who Nearly Hacked into\nPresident Trump&#8217;s Tax Returns<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201c<em>Two\ntwenty-somethings in Pennsylvania pleaded guilty to charges after attempting to\nhack their way into the IRS to get President Trump&#8217;s tax returns<\/em>.\u201d The\nstudents made a false FASFA application in the name of someone in Trump\u2019s\nfamily, they then used the IRS tool to electronically pull records to try and\npull trumps tax returns. They ran into a problem where an account already\nexisted for Donald Trump. They then GUESSED the security questions and got into\nthe existing account. \u201c<em>Although the Department of Justice says the attempt\n&#8220;ultimately failed,&#8221; it is not clear why. We simply know the students\ngot close to getting their hands on the President&#8217;s taxes.\u201d<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>9\/20\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/09\/browser-chrome-extension-adblock.html\">Two Widely Used Ad Blocker Extensions for\nChrome Caught in Ad Fraud Scheme<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cTwo widely used\nAdblocker Google Chrome extensions, posing as the original \u2014 AdBlock and uBlock\nOrigin \u2014 extensions on Chrome Web Store, have been caught stuffing cookies in\nthe web browser of millions of users to generate affiliate income from referral\nschemes fraudulently.\u201d Web browser extensions have become a popular vector for\nmalicious attacks, both of these extensions had over 800,000 users each. Google\nhas removed both of the malicious extensions from the Chrome Web Store. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/two-arrested-in-10-million-tech-support-scheme-that-preyed-on-the-elderly\/\">Two arrested in $10 million tech support\nscheme that &#8216;preyed on the elderly&#8217;<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two suspects have been\narrested for running a massive tech support scam, this scam has made over $10\nmillion in profit by defrauding more than 7,500 victims, most of which were\nelderly. This scam would trick users into calling fake tech support that would\ncharge them for unneeded tech services. &nbsp;\u201cIn 2018, tech support schemes\ngenerated over 142,000 consumer complaints with the US Federal Trade\nCommission.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/09\/advanced-hackers-are-infecting-it-providers-in-hopes-of-hitting-their-customers\/\">Advanced hackers are infecting IT providers in\nhopes of hitting their customers<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hackers have proven that they will do anything to compromise our networks, even if that means compromising third-party IT vendors to create a path to their customers networks. \u201cA previously undocumented attack group with advanced hacking skills has compromised 11 IT service providers\u201d This is another example of a supply chain attack, the coordinated Ransomware attacks in Texas were believed to also come from IT service providers. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>9\/27\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/09\/doordash-data-breach.html\">DoorDash Breach Exposes 4.9 Million Users&#8217;\nPersonal Data<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Door Dash is a food\ndelivery service, they are like GrubHub and will deliver food from restaurants\nwithout delivery service. Today they announced a breach that affects almost 5\nmillion people, including its customers, delivery workers, and merchants as\nwell.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The type of data\naccessed by the unknown attacker(s) include both personal and financial data,\nas shown below:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Profile information of all 4.9 million affected users&nbsp;\u2014 This data includes their names, email addresses, delivery addresses, order history, phone numbers, and hashed passwords.<\/li>\n\n\n\n<li>Financial information of some consumers&nbsp;\u2014 The company said the hackers also managed to get their hands on the last four digits of payment cards for some of its consumers but assured that full payment card numbers or a CVV      were not accessed.<\/li>\n\n\n\n<li>Financial information of some Dashers and merchants&nbsp;\u2014 Not just consumers, but some Dashers and merchants also had the last four digits of their bank account number accessed by the hackers.<\/li>\n\n\n\n<li>Information of 100,000 Dashers&nbsp;\u2014 The attackers were also able to access driver&#8217;s license numbers for 100,000 Dashers.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/arstechnica.com\/tech-policy\/2019\/09\/russian-national-confesses-to-biggest-bank-hack-in-us-history\/\">Russian national confesses to biggest bank\nhack in US history<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This person hacked Chase\nbank in 2014 and stole hundreds of millions of dollars along with data from\nmore than 80 million JPmorgan clients. \u201cAndrei Tyurin, 35, whose last name is\nalso spelled Tiurin, also pleaded guilty to hacks against other US financial\ninstitutions, brokerage firms, and other companies. In all, he pleaded guilty\nin federal court to computer intrusion, wire fraud, bank fraud, and illegal\nonline gambling as part of a securities-fraud scheme carried out by\nco-conspirators.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/krebsonsecurity.com\/2019\/09\/mypayrollhr-ceo-arrested-admits-to-70m-fraud\/\">MyPayrollHR CEO Arrested, Admits to $70M Fraud<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Earlier this month more\nthan 1,000 companies saw one or two paychecks worth of funds deducted from\ntheir bank accounts. The CEO of their cloud payroll provider took the money\nfrom customers, on Monday he was arrested and confessed that the act was a\nfinal desperate gasp of a financial shell game that earned him $70 million over\nseveral years. \u201cMichael T. Mann, the 49-year-old CEO of Clifton Park, NY-based\nMyPayrollHR, was arrested this week and charged with bank fraud. In court\nfilings, FBI investigators said Mann admitted under questioning that in early\nSeptember \u2014 on the eve of a big payroll day \u2014 he diverted to his own bank\naccount some $35 million in funds sent by his clients to cover their employee\npayroll deposits and tax withholdings.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>10\/4\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/over-500-us-schools-were-hit-by-ransomware-in-2019\/\">Over 500 US schools were hit by ransomware in\n2019<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIn the first nine\nmonths of the year, ransomware infections have hit over 500 US schools,\naccording to a report published last week by cyber-security firm Armor. In\ntotal, the company said it found and tracked ransomware infections at 54\neducational organizations like school districts and colleges, accounting for\ndisruptions at over 500 schools.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/threatpost.com\/senate-passes-bill-aimed-at-combating-ransomware-attacks\/148779\/\">Senate Passes Bill Aimed At Combating\nRansomware Attacks<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">New legislation has been\napproved by the senate that will help local cities and schools respond to\nransomware attacks. \u201cThe proposed law, the \u201cDHS Cyber Hunt and Incident\nResponse Teams Act,\u201d authorizes the Department of Homeland Security (DHS) to\ninvest in and develop \u201cincident response teams\u201d to help organizations battle\nransomware attacks.&nbsp; Part of that means that the DHS would create teams to\nprotect state and local entities from cyber threats and restore infrastructure\nthat has been affected by ransomware attacks.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/microsoft-mfa-bypass-attacks-are-so-rare-we-dont-have-good-statistics-on-them\/\">Microsoft: MFA bypass attacks are so rare we\ndon&#8217;t have good statistics on them<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">MFA Works! There are no\ngood statistics on attacks that were successful past MFA because the attacks\nrarely work. MFA provides a second factor of authentication on top of the\npassword. The attackers have not evolved past MFA safeguards because it is not\nused everywhere, they will just attack the victims that do not use MFA because\nthey are easier targets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>10\/11\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/ransomware-gang-uses-itunes-zero-day\/\">Ransomware gang uses iTunes zero-day<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The applications<strong>\niCloud<\/strong> and <strong>iTunes<\/strong> for the <strong>Windows operating system <\/strong>have a\nZero-Day exploit that has been used to deliver ransomware to systems. A\nzero-day exploit is a vulnerability that the vendor does not yet know about.\nApple has released a patch for this vulnerability this week. If anyone is using\niCloud or iTunes on a Windows computer, update both applications as soon as\npossible!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/beware-of-fake-amazon-aws-suspension-emails-for-unpaid-bills\/\">Beware of Fake Amazon AWS Suspension Emails\nfor Unpaid Bills<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is a common\nphishing attack, you get an email from a vendor stating that you have not paid\nyour bill. This sparks our curiosity and makes us want to click the link to see\nwhat bill we have not paid. Do not click the link!!! Instead, log into the legitimate\nwebsite for this vendor that you always use or pick up the phone and give them\na call. See <a href=\"https:\/\/staysafeonline.org\/blog\/5-ways-spot-phishing-emails\/\">the top ways to spot a phishing email<\/a> for more information on\navoiding these scams.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cyware.com\/news\/university-of-texas-first-ever-to-offer-cybersecurity-certification-in-healthcare-ef5dd2ca\">University of Texas First Ever to Offer\nCybersecurity Certification in Healthcare<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe healthcare industry takes the lion\u2019s share of ransomware attacks and the reasons are: the value of healthcare data; little attention on tech upgrades; and the rising complexity of healthcare ops. Nonetheless, the cybersecurity industry talent crisis isn\u2019t new to us.\u201d In a field as complex as Cybersecurity, industry-focused education is a great idea. Working in healthcare requires not only a strong knowledge of systems and networks but also compliance to deal with HIPAA and other challenges the industry brings. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>10\/18\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/18\/phishy-text-message-tries-to-steal-your-cellphone-account\/\">Phishy text message tries to steal your\ncellphone account<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hackers use social\nengineering in many ways, in this scam, they are sending phishing messages by\nmobile text message. The scam works the same as a phishing email, they send you\nto a fake webpage and try to steal your username and password. \u201cMessages sent\nvia SMS unexceptionably use a brief and direct style that makes it much easier\nto get the spelling and grammar right.\u201d Be on the lookout for these malicious\ntext messages.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.secureworldexpo.com\/industry-news\/are-doctors-quitting-after-ransomware-attacks?utm_campaign=Industry%20News&amp;utm_source=hs_email&amp;utm_medium=email&amp;utm_content=78228969&amp;_hsenc=p2ANqtz-8Hz1hvtjCw1nPGY_OelYNZB9Z6QsFuilx3HPjR98_e8pI64taRH3HS4RgE1FaZckW2mA9POgtUyiP_LrRR2ofnY9OlaimNlTLrXaxMBhiRy_hPJTM&amp;_hsmi=78229188\">Doctors Quitting Due to Ransomware Attacks<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ransomware attacks are\ngetting so bad at hospitals doctors are starting to quit or retire early. With\nthe loss of medical records, they are having a difficult time doing their job.\nIn Michigan a clinic has completely closed due to a ransomware attack, they had\ntheir files and backup systems encrypted. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/16\/food-writer-jack-monroe-loses-at-least-5000-in-sim-swap-fraud\/\">Food writer Jack Monroe loses at least \u00a35,000\nin SIM-swap fraud<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cBritish food writer and activist Jack Monroe has had her bank account drained by hijackers, despite using two-factor authentication (2FA) to protect accounts.\u201d The 2FA was text message-based and what led to the bank account compromise. Using an app or hardware token for your second factor is much more secure than a text message. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>10\/25\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/vietnamese-student-behind-android-adware-strain-that-infected-millions\/\">Vietnamese student behind Android adware\nstrain that infected millions<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The researchers at ESET have tracked down a person behind a recent wave of Android adware. The person behind the mobile adware is a university student from Vietnam. 42 apps were found on the Android app store, all of the apps contained adware that ESET has named Ashas. Some of the apps started off as legitimate apps with no adware, the student then decided to add the adware. ESET contacted the Google play security team and they removed the apps right away. The apps may still be available on third-party app stores. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.swindonadvertiser.co.uk\/news\/17986919.no-personal-data-stolen-college-cyber-attack\/\">No personal data stolen in college cyber\nattack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An investigation into hackers attacking Swindon College\u2019s network revealed that no personal data had been stolen. The college worked with the National Crime Agency over the last month and determined no data was extracted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/threatpost.com\/click-fraud-malware-apple-app-store\/149496\/\">Apple Removes 17 Malicious iOS Apps From App\nStore<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Researchers have\nuncovered 17 apps on Apple\u2019s official App Store infected with malware. Apple\nhas since removed the apps from the App Store \u2013 but a \u201csignificant\u201d number of\niOS users could have installed them, researchers said. All of the malicious\napps were published by the developer: AppAspect Technologies Pvt. Ltd. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>11\/1\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/fossbytes.com\/android-malware-cant-removed-after-factory-reset\/\">Beware! This Android Malware Can\u2019t Be Removed\nEven After Factory Reset<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The team at Malwarebytes has identified a new malware strain that has affected around 45,000 Android devices. &nbsp;This malware is mostly obtained by third-party app stores, once the malware is installed it displays frequent pop-up notifications. The interesting thing about this malware is that it has been observed to survive a factory reset on the mobile phone. Sticking to your mobile phones stock app store is much more secure than downloading apps from third-party app stores.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2019\/11\/01\/new-google-chrome-security-alert-update-your-browsers-as-high-severity-zero-day-exploit-confirmed\/#7fdab9d270b3\">New Google Chrome Security Alert: Update Your\nBrowsers As \u2018High Severity\u2019 Zero-Day Exploit Confirmed<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you use Google Chrome, update it ASAP, Google\u2019s security team has reported a new Zero-Day exploit that affects the Chrome browser on Windows, Mac, and Linux. The vulnerability could allow an attacker to take control of a device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/10\/indian-nuke-plants-network-reportedly-hit-by-malware-tied-to-n-korea\/\">Indian nuke plant\u2019s network reportedly hit by\nmalware tied to N. Korea<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A domain controller at a Nuclear Power Plant in India has been compromised, attribution of the attack points to North Korea. The report shows that the reactor controls have not been affected and the attack may have been after technical information about the plant. The plant officials have stated that the control systems are air-gapped from the rest of the network and not affected. This plant is India\u2019s largest and has had reports of multiple safety issues. \u201cThere have been over 70 shutdowns since the reactors went active in 2013. And on October 19, the plant&#8217;s second reactor was shut down due to a fault in the reactor&#8217;s steam generation, according to KKNPP officials. The shutdown was not related to the malware attack, officials asserted.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2019\/10\/messagetap-who-is-reading-your-text-messages.html\">MESSAGETAP: Who\u2019s Reading Your Text Messages?<\/a> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">APT41 is a code name for a Chinese nation-state hacking group. Recent malware from APT41 called MESSAGETAP has been observed to steal SMS text messages from the servers they pass through when they are sent from phone to phone. The malware steals the contents of the text message, the IMSI sim card number, and the source and destination phone number. The text messages are able to be read because they are sent in cleartext. If you use an encrypted SMS service like iMessage, the contents of the message would not be immediately readable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>11\/8\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/11\/ring-doorbell-wifi-password.html\">Amazon&#8217;s Ring Video Doorbell Lets Attackers\nSteal Your Wi-Fi Password<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security researchers at\nBitdefender have discovered a vulnerability in the Ring Doorbell. This\nvulnerability gives an attackers access to your Wi-Fi password allowing them to\nget on your internal network. The vulnerability stems from the setup process of\nthe Ring Doorbell, you have to provide the doorbell your Wi-Fi password to set\nit up. The attackers send multiple messages to the doorbell over the air that\nmakes the doorbell think it has to be set up again. When the user sets up the\ndoorbell the attacker performs a man in the middle attack and steals the\npassword provided to the Ring doorbell. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/apple-mail-on-macos-leaves-parts-of-encrypted-emails-in-plaintext\/\">Apple Mail on macOS leaves parts of encrypted\nemails in plaintext<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Apple assistant Siri has been busted reading text from emails in a database called snippets.db. Apple stores encrypted emails in this database in plain text, this means they can be read and are not encrypted while stored in the file. Siri does this to provide the user with more features but by doing this significantly decreases security. This is happening on macOS the laptop and desktop operating system. See the article for instructions to turn this feature off. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/krebsonsecurity.com\/2019\/11\/study-ransomware-data-breaches-at-hospitals-tied-to-uptick-in-fatal-heart-attacks\/\">Study: Ransomware, Data Breaches at Hospitals\ntied to Uptick in Fatal Heart Attacks<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A new study has shown a\nrise in fatal heart attacks in hospitals that are remediating ransomware.\n\u201cBreach remediation efforts were associated with deterioration in timeliness of\ncare and patient outcomes,\u201d the authors found. \u201cRemediation activity may\nintroduce changes that delay, complicate or disrupt health IT and patient care\nprocesses.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>11\/15\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/us-govt-recommends-vendor-system-configs-to-block-malware-attacks\/\">US Govt Recommends Vendor System Configs To Block\nMalware Attacks<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe Department of Homeland Security&#8217;s Cybersecurity and Infrastructure Security Agency (CISA) today reminded users and system administrators to properly configure their systems to defend against malware that can exploit improper configurations.\u201d The recommendations are setting up systems to vendor recommended configurations, applying security patches, installing anti-malware solutions, and using firewalls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/officials-warn-about-the-dangers-of-using-public-usb-charging-stations\/\">Officials warn about the dangers of using\npublic USB charging stations<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cTravelers are advised\nto avoid using public USB power charging stations in airports, hotels, and\nother locations because they may contain dangerous malware, the Los Angeles\nDistrict Attorney said in a security alert published last week.\u201d Security\nresearchers have recently started installing malicious hardware in phone chargers,\nit is a best practice to use your charger and your charger only. The attack\nwhere a hacker uses a phone charging cable to deliver a malicious payload has\nbeen labeled \u201cJuice jacking\u201d. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/11\/hacking-with-sim-swapping.html\">Two Arrested for Stealing $550,000 in\nCryptocurrency Using Sim Swapping<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cStarting with the\ncountry&#8217;s first-ever conviction for &#8216;SIM Swapping&#8217; this February, U.S.\nDepartment of Justice has since then announced charges against several individuals\nfor involving in the scheme to siphon millions of dollars in cryptocurrency\nfrom victims.\u201d Cybercriminals from Massachusetts have been charged with\nstealing $550,000 in cryptocurrency from at least 10 victims using sim swapping\nattacks. Sim swapping is where an attacker tricks your mobile phone provider to\nget a sim card activated with your number, this can then be used to reset\npasswords for your accounts. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>11\/22\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thejournal.com\/articles\/2019\/11\/18\/schools-under-cyber-siege-need-a-path-to-resilience.aspx\">Schools Under Cyber Siege Need a Path to\nResilience<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">More education institutions are getting hit with ransomware making them the second-largest victims in all sectors. More technology is getting introduced into schools for instruction, without the resources to properly manage and secure the equipment. \u201cAs endpoint and environmental complexities increase, and risk alongside them, it\u2019s no surprise that 68 percent of education IT leaders in the U.S. list cybersecurity as their top priority. In tandem, several state governments, including Louisiana, Texas and North Dakota, have stepped up their efforts to safeguard schools against cyberattacks with various measures such as cyber policy mandates, cyber commission formation and state IT department oversight for schools.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/11\/louisiana-was-hit-by-ryuk-triggering-another-cyber-emergency\/\">Louisiana was hit by Ryuk, triggering another\ncyber-emergency<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOn November 18, a ransomware attack caused Louisiana&#8217;s Office of Technology Services to shut down parts of its network, including the systems of several major state agencies.\u201d Some of the services have been brought back online but some are still in the process of being restored. Since they had backups in place and a plan to restore services, they are not paying the ransom and will hopefully be back up and running in the days to come.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/us-student-was-allegedly-building-a-custom-gentoo-linux-distro-for-isis\/\">US student was allegedly building a custom\nGentoo Linux distro for ISIS<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A 20-year-old student from Chicago has been arrested and charged for providing material support to ISIS. \u201cAccording to court documents, the suspect allegedly created a Python script to automate saving ISIS multimedia from official social media channels, so other members could re-post it on their own accounts, and help spread the terrorist group&#8217;s propaganda.\u201d This student was also in the process of creating a secure Linux operating system that could be used by the terrorist group and their supporters. This operating system would be difficult for law enforcement to penetrate allowing for ISIS supporters to keep their operations anonymous. \u201cIf found guilty for providing material support to ISIS, Osadzinski faces up to 20 years in prison.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>12\/6\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/livingston-school-district-in-new-jersey-hit-with-ransomware\/\">Livingston School District in New Jersey Hit\nWith Ransomware<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cStudents at the Livingston public school district in New Jersey are undoubtedly happy for a two hour delayed opening tomorrow. Unfortunately, this delay is not being caused by snow, but rather by a ransomware attack that the district is still recovering from.\u201d The school&#8217;s servers were encrypted and down causing them to initiate an investigation with a third-party security company. They are unsure if any data has been stolen at this point. \u201cJust this past Thursday, the operators of the Maze Ransomware publicly released 10% of the data that was stolen from Allied Universal after they did not pay the ransom. They state that they will release the rest of the data if an increased ransom payment is not made.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/ransomware-attack-hits-major-us-data-center-provider\/\">Ransomware attack hits major US data center\nprovider<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the largest data\ncenters in the US has been hit with Ransomware, customers that use their cloud\nservices have been impacted and are reporting availability issues. &#8220;Six of\nour managed service customers, located primarily in our New York data center,\nhave experienced availability issues due to a ransomware program encrypting\ncertain devices in their network,&#8221; CyrusOne told ZDNet. This is the same\nstrain of Ransomware that hit 20 local governments in Texas back in June.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/threatpost.com\/att-verizon-subscribers-exposed-mobile-bills\/150867\/\">AT&amp;T, Verizon Subscribers Exposed as\nMobile Bills Turn Up on the Open Web<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A contractor working with Sprint made a mistake and exposed hundreds of thousands of phone bills for AT&amp;T, Verizon, and T-Mobile customers. The information was on an Amazon Web Services bucket that was not properly secured. \u201cAccording to a media investigation, the contractor misconfigured a cloud storage bucket on Amazon Web Services (AWS), in which more than 261,300 documents were stored \u2013 mainly cell phone bills from Sprint customers who switched from other carriers.\u201d Some of the records included bank statements, usernames, passwords, and online pins. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>12\/3\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/edscoop.com\/sycamore-community-school-district-ransomware\/\">Yet another school district hit by ransomware,\nthis time in Illinois<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">60 miles west of Chicago, Sycamore Community School District 427 has been hit with Ransomware. \u201cSycamore Community\u2019s incident is the latest in a string of ransomware attacks against K-12 schools and higher education institutions in which hackers lock-up systems and data and demand bitcoin payment for returned access. According to data collected by Scoop News Group, at least 48 school districts and colleges have been infected by ransomware so far this year.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2019\/12\/snatch-ransomware-safe-mode.html\">Snatch Ransomware Reboots Windows in Safe Mode\nto Bypass Antivirus<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A new variant of Ransomware called Snatch has the ability to restart the computer into Safe Mode. This will allow it to bypass some antivirus products and other host-based security tools. \u201cWhat makes Snatch different and dangerous from others is that in addition to ransomware, it&#8217;s also a data stealer. Snatch includes a sophisticated data-stealing module, allowing attackers to steal vast amounts of information from the target organizations.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.secureworldexpo.com\/industry-news\/pensacola-shooting-malware-attack-linked?utm_campaign=Industry%20News&amp;utm_source=hs_email&amp;utm_medium=email&amp;utm_content=80723149&amp;_hsenc=p2ANqtz-8wJN5YTWi6aqOEQ0X8FUnoUeaHGh-Jdub_q2-4gnMOmvpgByZT6NjLtVdGDrRhgLn2iZCFYthqMtJ_ZcREo6MEYursFqHnIJBcGkICCeY68U-PPAQ&amp;_hsmi=80722787\">Linked? Pensacola Naval Shootings and a\nRansomware Attack Hours Later<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FBI is looking for a link in the Pensacola Naval Shootings and a Ransomware Attack Hours Later on the City of Pensacola. Security researcher and data scientist Kenneth Geers mentions that increased news coverage for specific events sometimes leads to increases in cyber-attacks. &#8220;Malware is super dynamic, it is changing all the time, but it is a reflection of human affairs.&nbsp; Everyone is connected for everything, to everything online. That&#8217;s where the good guys are and the bad guys are\u2014everybody.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>12\/20\/2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/latesthackingnews.com\/2019\/12\/15\/visa-alerts-north-america-regarding-pos-malware-attacks-on-gas-pumps\/\">VISA\nAlerts North America Regarding POS Malware Attacks On Gas Pumps<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cVISA has recently issued a cybersecurity alert for the\nresidents of North America. VISA has noticed a wave of POS malware attacks at\nvarious fuel dispensing systems in the region. They suspect an increase in\nthese attacks precisely targeting fuel dispenser merchants.\u201d Visa recommends\nthe following to protect POS systems:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Protect remote access with safe passwords and restricting\nunnecessary access <\/li>\n\n\n\n<li>Monitor network traffic <\/li>\n\n\n\n<li>Enable EMV technology <\/li>\n\n\n\n<li>Apply network segmentation to prevent malware spreading<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><em>It is important\nto monitor your card statements to watch out for fraudulent charges, setting up\na text or email alert for each transaction is a good way to continuously audit.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/krebsonsecurity.com\/2019\/12\/ransomware-gangs-now-outing-victim-businesses-that-dont-pay-up\/#more-49994\">Ransomware\nGangs Now Outing Victim Businesses That Don\u2019t Pay Up<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hackers are increasing their tactics to get victims to pay\nup with Ransomware attacks. \u201cSeveral prominent purveyors of ransomware have\nsignaled they plan to start publishing data stolen from victims who refuse to\npay up.\u201d This is interesting because most Ransomware attacks this year reported\nthat no data was exfiltrated. It looks like the bad guys will begin by\nexfiltrating sensitive data to use as leverage to get victims to pay.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/12\/17\/ransomware-seized-new-orleans-declares-state-of-emergency\/\">Ransomware-seized\nNew Orleans declares state of emergency<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The city of New Orleans has been\nhit with Ransomware, they have declared a state of emergency to get federal\nhelp. Sophos reported on this attack and shared the following to protect\nagainst Ransomware:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pick strong passwords. And don\u2019t re-use passwords, ever.<\/li>\n\n\n\n<li>Make regular backups. They could be your last line of defense against a      six-figure ransom demand. Be sure to keep them offsite where attackers can\u2019t find them.<\/li>\n\n\n\n<li>Patch early, patch often. Ransomware like&nbsp;<a href=\"https:\/\/nakedsecurity.sophos.com\/2017\/05\/17\/wannacry-the-ransomware-worm-that-didnt-arrive-on-a-phishing-hook\/\">WannaCry<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/nakedsecurity.sophos.com\/2017\/06\/28\/new-petya-ransomware-all-you-wanted-to-know-but-were-afraid-to-ask\/\">NotPetya<\/a>&nbsp;relied on unpatched vulnerabilities to spread around the globe.<\/li>\n\n\n\n<li>Lockdown      RDP. Criminal gangs&nbsp;<a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/07\/17\/rdp-exposed-the-wolves-already-at-your-door\/\">exploit weak RDP credentials<\/a>&nbsp;to launch targeted ransomware attacks. Turn off RDP if you don\u2019t need it, and use rate-limiting, 2FA or a VPN if you do.<\/li>\n\n\n\n<li>Use anti-ransomware protection. Sophos&nbsp;<a href=\"https:\/\/www.sophos.com\/en-us\/products\/intercept-x.aspx?cmp=26103\">Intercept      X<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/www.sophos.com\/en-us\/products\/next-gen-firewall.aspx?cmp=26057\">XG      Firewall<\/a>&nbsp;are designed to work hand in hand to combat ransomware and its effects. Individuals can protect themselves with&nbsp;<a href=\"https:\/\/home.sophos.com\/?cmp=27313\">Sophos      Home<\/a>.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The 2019 Cyber News Review started in April 2019 and provides a weekly review of Cyber Security news. 4\/18\/2019 Chinese hackers strike US universities in bid for military technology Accenture\u2019s iDefense team has confirmed cyberattacks against at least 27 universities worldwide. \u201cIt is believed that the threat actors behind the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":34,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-50","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=\/wp\/v2\/posts\/50","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=50"}],"version-history":[{"count":1,"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=\/wp\/v2\/posts\/50\/revisions"}],"predecessor-version":[{"id":51,"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=\/wp\/v2\/posts\/50\/revisions\/51"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=\/wp\/v2\/media\/34"}],"wp:attachment":[{"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=50"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=50"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thecyberstaff.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=50"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}