Here’s your reminder for today of the insider threat: OAKLAND – A federal grand jury has indicted Rambler Gallo, charging him with intentionally causing damage to a protected computer after he allegedly accessed the computer network for the Discovery Bay Water Treatment Facility, located in the Town of Discovery Bay, Calif., and intentionally uninstalled the…
Category: U.S.
What a way to start a new job…
The News Tribune reports: The new interim leader for the Tacoma-Pierce County Health Department started her role with news about a 5-year-old data breach the department says it learned about just last month. Kudos to her for her transparency: TPCHD’s Cindan Gizzi announced the news immediately after being appointed the department’s interim director during Wednesday’s…
If Kirkland & Ellis Can’t Avoid Cyberattacks, Who Can?
Justin Henry reports: By exploiting a vulnerability in a widely used file transfer application, hackers were able to access the internal information of several large organizations, including three Am Law 50 law firms, highlighting the vulnerability of widespread use of one third-party application. The incident has observers wondering: If some of the largest and most profitable…
DEVELOPING: HCA Healthcare patient data for sale on hacking forum?
A new user on a hacking forum has listed patient data from HCA Healthcare for sale. “As of 2021, HCA Healthcare is ranked #62 on the Fortune 500 rankings of the largest United States corporations by total revenue.” the seller writes, adding Data is grouped by division into 17 files totaling to 27,700,000 rows. More…
Deputy U.S. Marshal Pleads Guilty to Obtaining Cell Phone Location Information Unlawfully
This Department of Justice – Office of Inspector General press release from June 30 is a recent reminder of the insider threat: A deputy U.S. Marshal pleaded guilty today to misusing a law enforcement service to obtain cell phone location information for personal use. According to court documents, Adrian Pena, 49, of Del Rio, Texas,…
CISA issues warning for cardiac device system vulnerability
Jonathan Greig reports: The Cybersecurity and Infrastructure Security Agency (CISA) warned of a severe vulnerability in a cardiac device from medical device company Medtronic. The issue – tracked as CVE-2023-31222 – carries a “critical” CVSS score of 9.8 out of 10 and affects the company’s Paceart Optima software that runs on a healthcare organization’s Windows server. Medtronic said…