<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 03/12/2021

SHARE

Breaches

Breach Exposes Data of 200K Health System Staff, Patients

A medical practice management firm that provides support to Tacoma-based MultiCare Health System has alerted over 200,000 patients, providers and staff that their personal information may have been exposed. Woodcreek Provider Services announced Tuesday that after a ransomware attack of its tech vendor, the information was retrieved upon paying an undisclosed ransom, The News Tribune reported. READ MORE...

Hacking

GitHub removes researcher's Exchange Server exploit, sparking industry debate

Microsoft-owned GitHub has removed a security researcher's proof-of-concept exploit for vulnerabilities in Microsoft software that are at the center of widespread malicious cyber activity. The decision immediately touched off debate in the cybersecurity industry over when researchers should refrain from releasing software exploits and how software repositories like GitHub should govern their users. READ MORE...


Molson Coors Beer Operations Halted by Hack

Molson Coors, one of the nation's largest beer makers, halted production this week after hackers disrupted company operations. In a regulatory filing, company officials said the cyberattack has taken its systems offline, and delayed production and shipments. Details about the nature of the attack were not disclosed. "Molson Coors experienced a systems outage that was caused by a cybersecurity incident," the company said in a statement. READ MORE...

Trends

Two new ways backup can protect enterprise SaaS data

Software-as-a-Service (SaaS) apps are a treasure trove of information. They're where business takes place and decisions get made, so it's not surprising that they're attractive targets for bad actors. But while there's lots of bustle around protecting data that resides in on-premises apps, when it comes to protecting data in SaaS apps, it's pretty much… crickets. Why? Mainly, it's because many enterprises assume SaaS vendors protect their customers' data in those apps. READ MORE...

Malware

FIN8 Resurfaces with Revamped Backdoor Malware

The financial cyber-gang is running limited attacks ahead of broader offensives on point-of-sale systems. The FIN8 cyberattack group has resurfaced after a period of relative quiet, researchers have found. The gang is using new versions of the BadHatch backdoor to compromise companies in the chemical insurance, retail and technology industries. The attacks have been seen hitting organizations around the world, mainly in Canada, Italy, Panama, Puerto Rico, South Africa and the United States. READ MORE...

Exploits/Vulnerabilities

Ransomware now attacks Microsoft Exchange servers with ProxyLogon exploits

Threat actors are now installing a new ransomware called 'DEARCRY' after hacking into Microsoft Exchange servers using the recently disclosed ProxyLogon vulnerabilities. Since Microsoft revealed earlier this month that threat actors were compromising Microsoft Exchange servers using new zero-day ProxyLogon vulnerabilities, a significant concern has been when threat actors would use it to deploy ransomware. Unfortunately, tonight our fears became a reality. READ MORE...


Serious Vulnerabilities Found in Schneider Electric Power Meters

Industrial cybersecurity firm Claroty this week disclosed technical details for two potentially serious vulnerabilities affecting PowerLogic smart meters made by Schneider Electric. PowerLogic is a line of revenue and power quality meters that are used not only by utilities, but also industrial companies, healthcare organizations, and data centers for monitoring electrical networks. READ MORE...

Science & Culture

OVH data center fire likely caused by faulty UPS power supply

Today, OVH founder and chairman Octave Klaba has provided a plausible explanation for the fire that had burned down OVH data centers in Strasbourg, France. OVH is the largest hosting provider in Europe and the third-largest in the world. The cloud computing company provides VPS, dedicated servers, and other web services. The online properties impacted by the fire included free chess server Lichess.org, videogame maker Rust, cryptocurrency exchange Deribit's blog and docs sites. READ MORE...

On This Date

  • ...in 1912, the Girl Scouts of the USA are formed as the "Girl Guides."
  • ...in 1922, Beat Generation writer Jack Kerouac ("On the Road", "The Dharma Bums") is born in Lowell, MA.
  • ...in 1930, Mahatma Gandhi begins his 200-mile Salt March to protest the British monopoly on salt in India.
  • ...in 1933, Franklin Delano Roosevelt gives his first Presidential address, which was also the first of his radio "fireside chats."