Security News

Indian Railways suffers unspecified security 'breaches in various IT applications'
2021-02-24 03:13

Indian Railways has revealed it has suffered "a number of incidents... regarding breaches in various IT applications" and appears to have blamed some of them on sloppy infosec practices among staff working from home due to the COVID-19 pandemic. The organisation's document [PDF] announcing the cyber-transgressions says "a majority of these are application related," but doesn't explain what applications were affected nor the extent of the intrusions.

Global Accellion data breaches linked to Clop ransomware gang
2021-02-22 14:06

The attacks occurred in mid-December 2020 and involved the Clop ransomware gang and the FIN11 threat group. After we reported on the Singtel breach earlier this month, the Clop gang contacted us and stated that they stole 73 GB of data as part of their attack.

Worldwide Accellion data breaches linked to Clop ransomware gang
2021-02-22 14:06

The attacks occurred in mid-December 2020 and involved the Clop ransomware gang and the FIN11 threat group. After we reported on the Singtel breach earlier this month, the Clop gang contacted us and stated that they stole 73 GB of data as part of their attack.

US cities disclose data breaches after vendor's ransomware attack
2021-02-19 04:02

A ransomware attack against the widely used payment processor ATFS has sparked data breach notifications from numerous cities and agencies within California and Washington. Due to the large amount of potential data allegedly stolen by the Cuba Ransomware operation, cities utilizing AFTS as their payment processor or address verification service have begun disclosing potential data breaches.

Healthcare breaches increased over 50% in 2020
2021-02-18 05:30

In 2020, there were 599 healthcare breaches that collectively affected over 26 million individuals. Bitglass' report takes an in-depth look at the breaches that healthcare organizations faced, comparing them to previous years and revealing key trends and cybersecurity challenges facing the industry.

Rising healthcare breaches driven by hacking and unsecured servers
2021-02-17 15:51

Analyzing data from the U.S. Department of Health and Human Services, threat protection company Bitglass found that the count of healthcare breaches reported in 2020 increased to 599, a jump of more than 50% compared to the previous year. Most of the breaches were caused by hacking and IT incidents, which exposed data from 24.1 million individuals, making them vulnerable to identity theft and phishing attacks.

Singtel, QIMR Berghofer report Accellion-related data breaches
2021-02-11 17:55

Singtel and the QIMR Berghofer Medical Research Institute are the latest companies to disclose data breaches caused by a vulnerability in the Accellion FTA secure file transfer software. As Accellion FTA service is used by numerous government agencies, educational institutions, and companies, we have begun to see a wide-scale impact as companies report related data breaches.

Sonrai Dig offers automated prevention of data breaches in public cloud deployments
2021-02-11 02:30

Sonrai Security announced significant new functionality designed to automate prevention of data breaches in public cloud deployments for its Sonrai Dig platform. Supporting leading public cloud databases in combination with advanced behavioral modeling and automated blocking, the newly enhanced service helps ensure critical corporate data is secure wherever it resides in cloud environments.

US Coast Guard orders maritime facilities to report SolarWinds breaches
2021-02-10 20:47

Image: USCG. The U.S. Coast Guard has ordered MTSA-regulated facilities and vessels using SolarWinds software for critical functions to report security breaches in case of suspicions of being affected by the SolarWinds supply-chain attack. "Reporting malicious cyber activity enhances maritime domain awareness and allows us all to be better postured to prevent and respond to cyber incidents that could disrupt commerce or jeopardize national security."

Supply-Chain Hack Breaches 35 Companies, Including PayPal, Microsoft, Apple
2021-02-10 13:49

These installers-such as Python Package Index for Python or npm and the npm registry for Node-are usually tied to public code repositories where anyone can freely upload code packages for others to use, Birsan noted. Birsan decided to answer this question last summer while attempting to hack PayPal with another ethical hacker, Justin Gardner, who shared with him "An interesting bit of Node.js source code found on GitHub," Birsan said.