Catalin Cimpanu reports: E-commerce software vendor X-Cart suffered a ransomware attack at the end of October that brought down customer stores hosted on the company’s hosting platform. The incident is believed to have taken place after attackers exploited a vulnerability in a third-party software to gain access to X-Cart’s store hosting systems. Read more on ZDNet. h/t,…
FTC Requires Zoom to Enhance its Security Practices as Part of Settlement
Let’s start with the FTC’s press release in Zoom Video Communications, Inc., In the Matter of Matter Number: 192 3167 The Federal Trade Commission today announced a settlement with Zoom Video Communications, Inc. that will require the company to implement a robust information security program to settle allegations that the video conferencing provider engaged in a series…
Eight months after ransomware attack, Advanced Urgent Care of Florida Keys notifies patients
On March 14, DataBreaches.net reported that Advanced Urgent Care of the Florida Keys had been attacked, and patient data dumped. The data dump had been listed on a Russian-language forum known for data dumps, and the threat actor, then known as “m1x,” called the medical group “Malicious Defaulters” because they wouldn’t pay to prevent data…
Patients need to be notified sooner of ransomware dumps
In the past year, we have seen a significant increase in the use of dedicated leak sites where ransomware threat actors post the names of victims and dump some of their data to pressure them to pay demanded ransom. In the U.S., HIPAA gives covered entities no more than 60 days from discovery of a…
Alibaba-Backed Bigbasket Suffers Major Data Loss in Cyberattack
Saritha Rai has more on the BigBasket breach reported this past week: Cyberattackers have stolen the personal details of million users of top Indian internet grocer Bigbasket, the latest e-commerce data breach to emerge as home-bound consumers flock online. Bigbasket co-founder and chief executive officer Hari Menon confirmed the attack, which was first reported by…
CERT-in warns Indian companies about Egregor that sweeps IT system of organisations and steals data
CIOL Bureau reports: The country’s cybersecurity agency CERT-in has alerted users against the malicious spread of ransomware virus ‘Egregor’ that threatens to release sensitive corporate data of the victim organisation if not paid. The CERT-In or the Indian Computer Emergency Response Team said in the latest advisory that “while the initial infection vector and propagation…