Savannah Sicurella reports: Peloton users have something new to worry about. In a new report, security company McAfee says hackers can gain remote access to a Peloton bike’s camera and microphone and can monitor users. The attackers can also add apps disguised as Netflix and Spotify to encourage users to input login credentials for later malicious…
Category: Commentaries and Analyses
Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise
Tyler McLellan, Robert Dean, Justin Moore, Nick Harbour, Mike Hunhoff, Jared Wilson, Jordan Nuce of FireEye report: Mandiant observed DARKSIDE affiliate UNC2465 accessing at least one victim through a Trojanized software installer downloaded from a legitimate website. While this victim organization detected the intrusion, engaged Mandiant for incident response, and avoided ransomware, others may be…
SCOOP: UnitingCare paid hundreds of thousands of dollars to REvil for decryption key and deletion of files
On April 25, UnitingCare Queensland (UCQ) was the victim of a ransomware attack that impacted multiple Queensland hospitals and aged care centres. The next day, they posted a notice on their web site informing people as to what was happening and its impact. And on May 5, they posted a second update where they revealed…
NYS Comptroller DiNapoli Releases School District Audit of East Syracuse-Minoa Central School District – Information Technology (Onondaga County and Madison County)
Summary: Audit Objective Determine whether East Syracuse Minoa Central School District (District) officials established adequate information technology (IT) controls to ensure employees’ personal, private and sensitive information (PPSI) on the financial server was adequately protected from unauthorized access, use and loss. Key Findings District officials did not adequately apply established IT controls to ensure PPSI…
Healthcare entities in Saudi Arabia, Illinois, and Mississippi fall prey to Xing Team
Note: updates to the breaches included in this report appear below the original post. Some threat actors have gained a lot of notoriety while others are lesser known. In this article, DataBreaches.net reports on a relatively unknown group that has been hitting the healthcare sector, “Xing Team.” Like other groups, Xing maintains a dedicated leak…
Arizona Asthma and Allergy Institute Provides Notice of Maze Attack in 2020
An incident initially reported to HHS on May 3 has been updated to 70,372 patients from the initial report of 50,000. The following is the entity’s notice on their web site, and after you read it, I’ll meet you on the other side to explain it more, because they only discovered the breach when DataBreaches.net…