Sergiu Gatlan reports: Admins, hosting providers, and the French Computer Emergency Response Team (CERT-FR) warn that attackers actively target VMware ESXi servers unpatched against a two-year-old remote code execution vulnerability to deploy ransomware. Tracked as CVE-2021-21974, the security flaw is caused by a heap overflow issue in the OpenSLP service that can be exploited by unauthenticated…
Category: Of Note
Julius ‘zeekill’ Kivimäki, former Lizard Squad hacker, arrested in France
Recidivism is a thing. Alexander Martin reports: Julius Kivimäki, the Finnish member of Lizard Squad — who as a teenager in 2015 was convicted on over 50,000 counts of computer crimes — has been arrested again in France. Finnish police confirmed the arrest on Friday in a press release stating the suspect is being held by…
HHS OCR Settles HIPAA Investigation with Banner Health Following 2016 Hacking Incident
The following is a press release from HHS. It is an update to a 2016 hacking incident previously covered on this site. The incident also resulted in a class action lawsuit that was settled for $6 million in 2019. February 02, 2023 Today, the U.S. Department of Health and Human Services’ Office for Civil Rights…
British Columbia: Mandatory breach reporting and privacy management program requirements now in effect for public bodies
February 1, 2023 Public bodies are now required to develop privacy management programs and report privacy breaches that could be expected to result in serious harm. The new requirements, which were among amendments to the Freedom of Information and Protection of Privacy Act (FIPPA) enacted in November 2021, came into force today. They apply to…
North Korean hackers stole research data in two-month-long breach
Bill Toulas reports: A new cyber espionage campaign dubbed ‘No Pineapple!’ has been attributed to the North Korean Lazarus hacking group, allowing the threat actors to stealthily steal 100GB of data from the victim without causing any destruction. The campaign lasted between August and November 2022, targeting organizations in medical research, healthcare, chemical engineering, energy,…
Former Employee Ubiquiti Networks Pleads Guilty To Stealing Confidential Data And Extorting Company For Ransom
There’s an update to a previously reported case involving a former employee of Ubiquiti Networks, although as is their policy, the DOJ does not name the victim firm: Damian Williams, the United States Attorney for the Southern District of New York, announced that NICKOLAS SHARP pled guilty today in Manhattan federal court to multiple federal…