Bill Toulas reports: A threat actor announced on a cybercrime forum that they sold the source code and a cracked version of the Zeppelin ransomware builder for just $500. The post was spotted by threat intelligence company KELA and while the legitimacy of the offer has not been validated, the screenshots from the seller indicate that the package…
Category: Of Note
Merck Settles Coverage Dispute With Insurers Over War Exclusion in NotPetya Attack
Insurance Journal reports: Merck & Co. Inc. has reportedly reached a deal with insurers over a closely-watched coverage dispute related to a massive cyberattack in 2017. The New Jersey Supreme Court in July 2023 agreed to hear the case after a state appeals court ruled months prior against eight insurers, finding that a hostile/warlike action exclusion in…
23andMe Says Breach Victims Are to Blame, Legal Action is Futile
As incident response and public relations go, blaming victims for your breach is generally not an impressive strategy. Michael Edgar reports that 23andMe seems to be doing exactly that: Months after the San Francisco based company experienced a data breach impacting about 6.9 million users, 23andMe is now facing criticism for blaming victims of the breach and…
UnitedHealth alleges trade secret theft by ex-execs
Nona Tepper reports: Two former UnitedHealth Group executives allegedly took trade secrets with them on the way out the door and used the information to found a pair of diabetes management startups, the conglomerate claims in a federal lawsuit. UnitedHealth Group filed suit against Ken Ehlert, Mark Pollmann and other leaders of Lore Health and…
The State of Ransomware in the U.S.: Report and Statistics 2023
Data analyses and commentary by Emsisoft begins: “From 2016 to 2021, we estimate that ransomware attacks killed between 42 and 67 Medicare patients.” — McGlave, Neprash, and Nikpay; University of Minnesota School of Public Health1 In 2023, the U.S. was once again battered by a barrage of financially-motivated ransomware attacks that denied Americans access to…
Operation Triangulation: The last (hardware) mystery
Boris Lairn reports: Today, on December 27, 2023, we (Boris Larin, Leonid Bezvershenko, and Georgy Kucherin) delivered a presentation, titled, “Operation Triangulation: What You Get When Attack iPhones of Researchers”, at the 37th Chaos Communication Congress (37C3), held at Congress Center Hamburg. The presentation summarized the results of our long-term research into Operation Triangulation, conducted with our…