IT Security Newsletter - 8/28/2024
950,000 Impacted by Young Consulting Data Breach
Software solutions provider Young Consulting is notifying over 950,000 individuals that their personal information was compromised in a data breach earlier this year. The incident was discovered on April 13, when the company "became aware of technical difficulties" within its environment. The company discovered that the attackers had access to its network between April 10 and April 13. READ MORE...
BlackByte affiliates use new encryptor and new TTPs
BlackByte, the ransomware-as-a-service gang believed to be one of Conti's splinter groups, has (once again) created a new iteration of its encryptor. "Talos observed some differences in the recent BlackByte attacks. Most notably, encrypted files across all victims were rewritten with the file extension 'blackbytent_h', which has not yet appeared in public reporting," researchers with Cisco's threat intelligence team have shared. READ MORE...
Old devices, new dangers: The risks of unsupported IoT tech
Outdated devices are often easy targets for attackers, especially if they have vulnerabilities that can be exploited and no patches are available due to their end-of-life status. Hacks of outdated or vulnerable devices are an issue, but why would anyone attempt to hack discontinued devices or those running out-of-support software? To gain control? To spy on people? The answer is quite multifaceted. READ MORE...
Hundreds of LLM Servers Expose Corporate, Health & Other Online Data
Hundreds of open source large language model (LLM) builder servers and dozens of vector databases are leaking highly sensitive information to the open Web. As companies rush to integrate AI into their business workflows, they occasionally pay insufficient attention to how to secure these tools, and the information they trust them with. In a new report, Legit security researcher Naphtali Deutsch demonstrated as much by scanning the Web for two kinds of potentially vulnerable AI services. READ MORE...
From Copilot to Copirate: How data thieves could hijack Microsoft's chatbot
Microsoft has fixed flaws in Copilot that allowed attackers to steal users' emails and other personal data by chaining together a series of LLM-specific attacks, beginning with prompt injection. Author and red teamer Johann Rehberger initially disclosed parts of the exploit to Redmond back in January, with the full attack chain following a month later. READ MORE...
Hitachi Energy Vulnerabilities Plague SCADA Power Systems
Hitachi Energy is urging customers of its MicroSCADA X SYS600 product for monitoring and controlling utility power systems to immediately upgrade to a newly released version to mitigate multiple critical and high-severity vulnerabilities. In a security advisory this week, the company described the vulnerabilities as enabling attacks that could have serious confidentiality, integrity, and availability impacts on affected products. READ MORE...
- ...in 1867, The United States takes possession of the uninhabited Midway Island.
- ...in 1907, UPS is founded by Seattle teenagers James E. Casey and Claude Ryan as a bicycle messenger service.
- ...in 1917, comics artist and writer Jack Kirby, the co-creator of Captain America, the X-Men, and hundreds of other characters, is born in New York City.
- ...in 1963, Dr. Martin Luther King, Jr. gives his famous "I Have A Dream" speech at the Lincoln Memorial.