Author: nlqip
Change Healthcare: Patient Data Exposed In Breach Includes Medical Diagnoses, Test Results, Prescriptions
- by nlqip
The medical data exposed in the cyberattack earlier this year may have included ‘diagnoses, medicines, test results, images, care and treatment,’ according to Change Healthcare. Change Healthcare disclosed that it now believes sensitive patient medical data was exposed in the widely felt cyberattack earlier this year, as the UnitedHealth-owned company said it is preparing to…
Read MoreA pair of cyberattacks against software maker CDK continues to impact thousands of car dealerships and has spurred threat actors to launch impersonation attacks. The CDK Global outage affecting thousands of car dealerships continued Friday, while the attempts to recover from cyberattacks earlier this week were compounded by reported impersonation scams targeting dealership staff. While…
Read MoreThe Treasury Department’s Office of Foreign Assets Control (OFAC) has sanctioned twelve Kaspersky Lab executives for operating in the technology sector of Russia. These sanctions came after the Biden administration announced yesterday the ban of sales and software updates for Kaspersky antivirus software in the USA, which started in July, over potential cybersecurity risks to national…
Read MoreCVE-2024-28995: SolarWinds Serv-U Path/Directory Traversal Vulnerability Exploited in the Wild
- by nlqip
Following the publication of proof-of-concept exploit details for a high-severity flaw in SolarWinds Serv-U, researchers have observed both automated and manual in-the-wild exploitation attempts; patching is strongly advised. Background On June 5, SolarWinds published an advisory for a vulnerability in its Serv-U file transfer protocol (FTP) and managed file transfer (MFT) solutions: CVE Description CVSSv3…
Read MoreA federal jury in Las Vegas convicted five men for their involvement in the operation of Jetflicks, one of the largest and most popular illegal streaming services in the United States. Jetflicks operated for 12 years, from its launch in 2007 until its shutdown by the FBI in 2019. At its peak, the service offered…
Read MoreImage: Midjourney UnitedHealth has confirmed for the first time what types of medical and patient data were stolen in the massive Change Healthcare ransomware attack, stating that data breach notifications will be mailed in July. On Thursday, the company published a data breach notification warning that the ransomware attack exposed a “substantial quantity of data”…
Read MoreFor the week ending June 21, CRN takes a look at the companies that brought their ‘A’ game to the channel including Nvidia, Hewlett Packard Enterprise, Huntress, Digital Ocean and Riverbed. The Week Ending June 21 Topping this week’s Came to Win is Nvidia which – for a short time, at least – became the…
Read MoreCISA Releases Guidance on Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses: (SMBs) | CISA
- by nlqip
Today, CISA released Barriers to Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses: Identifying Challenges and Opportunities, a detailed report exploring challenges to SSO adoption by small and medium-sized businesses (SMBs). The report also identifies potential ways to overcome these challenges and improve an SMB’s level of security. CISA also released a related blog…
Read MoreJuniper Networks released a security bulletin to address multiple vulnerabilities affecting Juniper Secure Analytics optional applications. A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following and apply the necessary updates: Source link lol
Read MoreJun 21, 2024NewsroomMalware / Threat Intelligence A previously undocumented Chinese-speaking threat actor codenamed SneakyChef has been linked to an espionage campaign primarily targeting government entities across Asia and EMEA (Europe, Middle East, and Africa) with SugarGh0st malware since at least August 2023. “SneakyChef uses lures that are scanned documents of government agencies, most of which…
Read MoreRecent Posts
- Month in security with Tony Anscombe – October 2024 edition
- Google ‘Hiring Less’ As Operating Income Surges At Google Cloud
- LastPass warns of fake support centers trying to steal customer data
- Dell PowerMax And Dell PowerScale Get Big AI Upgrades
- Synology hurries out patches for zero-days exploited at Pwn2Own