<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 01/26/2021

SHARE

Breaches

South Carolina County Suffers Weekend Cyberattack

A coastal South Carolina county says hackers broke into its computer network over the weekend. A statement from Georgetown County's local government Monday said the county's computer network "suffered a major infrastructure breach over the weekend." Most of the county's electronic systems, including emails, were impacted. The county's 911 system and jail operations were not affected, according to the statement. The county said it does not know when its electronic systems will be up and running again. READ MORE...

Hacking

Ransomware gang taunts IObit with repeated forum hacks

A ransomware gang continues to taunt Windows software developer IObit by hacking its forums to display a ransom demand. On January 16th, the IObit forums were hacked as part of an attack to distribute the DeroHE ransomware. During this attack, the threat actors emailed all of the IObit forum users with a free software promotion linking to a ransomware installer hosted on IObit's forums. When recipients downloaded the fake IObit software installer, they were infected with the DeroHE ransomware. READ MORE...


Packaging Giant WestRock Says Ransomware Attack Impacted OT Systems

American packaging giant WestRock (NYSE: WRK) on Monday revealed that it was recently targeted in a ransomware attack that impacted both information technology (IT) and operational technology (OT) systems. The company has shared few details about the incident, which it discovered on January 23, when it "promptly" initiated response and containment protocols. Law enforcement has been notified and customers are being kept in the loop about the incident, WestRock said in a press release. READ MORE...

Malware

Fake Twitter personas, bogus blog delivered North Korea-linked malware to researchers

Hackers linked to North Korea targeted cybersecurity researchers through a seemingly legitimate research blog and friendly social media accounts, Google said Monday. The goal of those social engineering techniques was simple: Earn trust, and then trick researchers into interacting online with files that implanted file-stealing malware on their computers. There were also a few cases where unwitting researchers' machines were infected simply by direct interaction with the security blog, Google said. READ MORE...

Information Security

ProtonVPN causes Windows BSOD crashes due to antivirus conflicts

ProtonVPN is working on fixing a bug causing Windows blue screen crashes affecting customers using the latest versions of the company's Windows client software. The BSOD crashes don't affect all users and are caused due to conflicts with unnamed antivirus software solutions. "We have received reports that in particular circumstances the latest versions of ProtonVPN Windows clients (the stable version 1.18.2, and the early access version 1.18.3) might lead to Blue Screen crashes in Windows." READ MORE...

Exploits/Vulnerabilities

Google fixes severe Golang Windows RCE vulnerability

This month Google engineers have fixed a severe remote code execution (RCE) vulnerability in the Go language (Golang). The RCE vulnerability, CVE-2021-3115, mainly impacts Windows users of Go running the go get command, due to the default behavior of Windows PATH lookups. Recently, Japan-based security researcher RyotaK discovered a command injection vulnerability in the Golang project. The vulnerability, tracked as CVE-2021-3115, stems from how the compile process works. READ MORE...


Critical Vulns Discovered in Vendor Implementations of Key OT Protocol

Researchers from Claroty this week disclosed multiple critical vulnerabilities in vendor implementations of the Open Platform Communications (OPC) network protocol that is widely used in operational technology (OT) networks. The flaws affect products from three vendors whose technologies are also being used as third-party components in multiple other white-label products running the OPC protocol. Claroty privately reported its vulnerability discoveries to the three vendors in 2020. READ MORE...

On This Date

  • ...in 1925, film actor, director, and charitable entrepreneur Paul Newman ("Cool Hand Luke", "The Sting") is born in Shaker Heights, OH.
  • ...in 1961, NHL leading scorer Wayne Gretzky -- "The Great One" -- is born in Brantford, Ontario.
  • ...in 1978, the Great Blizzard of '78 arrives with 100 mph winds, burying Ohio and much of the Midwest in up to 36" of snow.
  • ...in 1992, Russian President Boris Yeltsin announces that Russia will stop targeting US cities with nuclear weapons.