Jordan Robertson and Riley Griffin report: On March 15, 2020, just days after the US declared a national emergency because of the Covid-19 pandemic, the computer network for the US Department of Health and Human Services briefly vanished from the internet. In public remarks the following day, HHS Secretary Alex Azar attributed the 10-minute outage to a cyberattack but…
Category: Government Sector
Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency Servers
The Hacker News reports: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a high-severity Adobe ColdFusion vulnerability by unidentified threat actors to gain initial access to government servers. “The vulnerability in ColdFusion (CVE-2023-26360) presents as an improper access control issue and exploitation of this CVE can result in arbitrary code execution,” CISA said,…
Britain dismisses report claiming Sellafield nuclear site hacking, says no malware exists on our system
FirstPost reports: Hours after The Guardian report claimed that UK’s most hazardous nuclear site Sellafield has been hacked into by cyber groups closely linked to Russia and China, Britain on Monday said that it has no records or evidence to suggest that networks were compromised. “Our monitoring systems are robust and we have a high degree of…
Sellafield nuclear site hacked by groups linked to Russia and China (1)
Anna Isaac and Alex Lawson report: The UK’s most hazardous nuclear site, Sellafield, has been hacked into by cyber groups closely linked to Russia and China, the Guardian can reveal. The astonishing disclosure and its potential effects have been consistently covered up by senior staff at the vast nuclear waste and decommissioning site, the investigation…
Norwegian Labor and Welfare Administration fined for data protection failures
The Norwegian Supervisory Authority (Datatilsynet) has taken enforcement action, imposing a fine of EUR 1.7 million (USD $1.85 million) on Arbeids- og velferdsetaten, the Norwegian Labor and Welfare Administration (NAV). As part of its investigation, the DPA found that the controller had failed to implement appropriate technical and organizational measures to protect personal data. For example, the…
NZ: Health Worker Arrested for Misusing Vaccination Data: A Case of Breach of Trust
Somasetty Suresh reports: A health worker has been apprehended by the authorities for an alleged misuse and disclosure of vaccination data. The individual, whose identity has not been revealed, has been charged with accessing a computer system for dishonest purposes. The incident came to light recently, prompting swift action from the concerned authorities. The accused…