Security News > 2022 > October

Cyber-snoops broke into US military contractor, stole data, hid for months
2022-10-05 19:27

Spies for months hid inside a US military contractor's enterprise network and stole sensitive data, according to a joint alert from the US government's Cybersecurity and Infrastructure Security Agency, the FBI, and NSA. The intruders somehow broke into the defense org's Microsoft Exchange Server - the Feds still aren't sure how - and rummaged through mailboxes for hours and used a compromised admin account to query Exchange via its EWS API. The snoops also ran Windows commands to learn more about the IT setup and gathered up files into archives using WinRAR. Interestingly, the cyberattackers also used the open source network toolkit Impacket to remote-control machines on the network and move laterally. It seems someone eventually realized something was up because from November 2021 to January 2022, CISA and a "Trusted third-party" security company were called in to check over the contractor's enterprise network in an incident response.

October Is Cybersecurity Awareness Month
2022-10-05 19:07

For the past nineteen years, October has been Cybersecurity Awareness Month here in the US, and that event that has always been part advice and part ridicule. I tend to fall on the apathy end of the spectrum; I don't think I've ever mentioned it before.

NetWalker ransomware affiliate sentenced to 20 years by Florida court
2022-10-05 18:55

Naked Security has written and talked about Sebastien Vachon-Desjardins before, in both article and podcast form. Vachon-Desjardins had been a federal government worker in the Canadian Capital Region.

Software supply chains at risk: The account takeover threat
2022-10-05 18:38

Software supply chains at risk: The account takeover threat. A software supply chain attack consists of targeting software repositories or download locations, in order to spread malware instead of or in addition to legitimate software.

Chase UK's app-only bank hit with 24-hour ongoing outage
2022-10-05 17:59

The major outage began around Monday evening but has continued well into today with Chase reporting some customers facing degraded performance while others seeing improvement. Chase UK's customers with a mobile-based current account have been experiencing an ongoing outage and degraded performance with the bank's app, making it difficult for them to access their accounts and funds.

Avast releases free decryptor for MafiaWare666 ransomware variants
2022-10-05 17:46

Avast has released a decryptor for variants of the MafiaWare666 ransomware known as 'Jcrypt', 'RIP Lmao', and 'BrutusptCrypt,' allowing victims to recover their files for free. Utilizing Avast's tool, victims of the supported ransomware variants can decrypt and access their files again without paying a ransom to the attackers, which ranges between $50 and $300. However, ransom demands reached tens of thousands in some cases.

Avast releases free decryptor for Hades ransomware variants
2022-10-05 17:46

Avast has released a decryptor for variants of the Hades ransomware known as 'MafiaWare666', 'Jcrypt', 'RIP Lmao', and 'BrutusptCrypt,' allowing victims to recover their files for free. Utilizing Avast's tool, victims of the supported ransomware variants can decrypt and access their files again without paying a ransom to the attackers, which ranges between $50 and $300. However, ransom demands reached tens of thousands in some cases.

City of Tucson discloses data breach affecting over 125,000 people
2022-10-05 17:21

The City of Tucson, Arizona, has disclosed a data breach affecting the personal information of more than 125,000 individuals.As revealed in a notice of data breach sent to affected people, an attacker breached the city's network and exfiltrated an undisclosed number of files containing sensitive information.

Hundreds of Microsoft SQL servers backdoored with new malware
2022-10-05 16:01

Security researchers have found a new piece of malware targeting Microsoft SQL servers. Named Maggie, the backdoor has already infected hundreds of machines all over the world.

CommonSpirit US nonprofit health system discloses security incident
2022-10-05 15:37

One of the largest nonprofit health systems in the United States, says it took down some of its IT systems because of a security incident that has impacted multiple facilities. The US health system operates 140 hospitals and more than 1,000 care sites in 21 states, and its team of roughly 150,000 employees and 20,000 physicians provides health services to more than 21 million patients.