Mark Young and Tomos Griffiths of Covington and Burling write: In the early hours of Friday, 13 May, the European Parliament and the Council of the EU reached provisional political agreement on a new framework EU cybersecurity law, known as “NIS2”. This new law, which will replace the existing NIS Directive (which was agreed around the same…
Author: Dissent
Exploratory study into ransomware attacks in Dutch government services and companies
Cybercrimeinfo.nl writes: Statistics Netherlands (CBS), in collaboration with the National Cyber Security Center (NCSC), has conducted an exploratory study into ransomware attacks in Dutch government services and companies. The researchers looked at, among other things, the timeline and costs of attacks with ransomware. Due to the sensitivity of the collected data, the report has not been published…
Alert (AA22-137A): Weak Security Controls and Practices Routinely Exploited for Initial Access
Alert (AA22-137A) Weak Security Controls and Practices Routinely Exploited for Initial Access CISA Alert Published May 17, 2022: Summary Cyber actors routinely exploit poor security configurations (either misconfigured or left unsecured), weak controls, and other poor cyber hygiene practices to gain initial access or as part of other tactics to compromise a victim’s system. This…
Data leak containing info of 22.5 million Malaysians not from NRD, says Hamzah
Mazwin Nik Anis reports: The alleged data leak containing information of 22.5 million Malaysians is not from the National Registration Department (NRD), says Datuk Seri Hamzah Zainudin. The Home Minister said there was a mechanism in place which could prove that the leaked information did not come from the department. Read more at TheStar.
Mandiant Quietly Investigating Suspected Russian Intrusions
Katrina Manson reports: Right now, cyber investigators at Mandiant say they’re actively responding to more than a dozen live intrusions by Russian foreign intelligence services aimed at diplomats, military computers, defense contractors and other targets. […] One reason the Russian attacks aren’t making headlines is that, according to Mandiant’s findings, the actual number of them is roughly…
Christus Health ransomware incident involved theft of sensitive patient and employee data
First, the good news (such as it is): a ransomware attack on Christus Health by Avos Locker has not impacted patient care. Now, the bad news: the threat actors acquired — and have already leaked — a lot of sensitive information on patients and employees. On May 11, Avos Locker added Christus Health to their…