Cyber News: What You Need to Know, Weekly Edition, June 17
In this weekly blog, we’ll compile the top cyber news you need to know from the week before and provide an easy breakdown so you can get the news you need and skip the fluff you don’t.
City of Cleveland Confirms Ransomware Attack
The City of Cleveland publicly acknowledged on Friday, June 14 ransomware caused the closing of City Hall and the stoppage of several city services. The FBI and the Ohio National Guard’s Cyber Reserve Unit are currently assisting with the investigation and confirmed ransomware attack. The attack closed City Hall for Monday, June 17. Essential services are still listed as operational. In the released statement, official stated “abnormalities” started as early as Saturday, June 8.
What You Need to Know:
Attacks of this type have increased by 50%, and will likely continue to increase. In the first eight months of 2023, malware attacks increased by 148%, and ransomware attacks increased from 58% to 69% in a year-over-year comparison.
Implications:
Endpoint security incidents continue to be the vector for many attacks into municipalities and school districts. In 2023, endpoint security incidents like data breaches, unauthorized access, and insider threats, increased by 313%. In the University of Houston’s breakdown of the 2019 attack against municipalities in Texas, they noted, “Cyber extortion and disruption incidents are on the rise because many governments have poor security postures.” Sadly, when you’re trying to keep a city running, IT staff are usually more concerned with operations over cybersecurity. Municipalities typically lag behind the federal government when it comes to setting and implementing cybersecurity standards, despite being held to the same level of regulatory compliance. Partnering with private industry, like the feds, is the answer to keeping our local governments – and constituent data- safe.
Arlington, Mass Confirms $445,000 Payout to Cybercriminals
City Manager Jim Feeney experienced the distinct displeasure of writing a letter to his constituents informing them the City of Arlington was the victim of cybercrime, namely a business email compromise. Threat actors used phishing, spoofing, social engineering, and compromised email accounts to facilitate wire fraud in the amount of $445,945.73. While no sensitive or residential data was compromised, the city remains out nearly $446,000. The results of the local and federal investigation so far point to “an organization that is well resourced and located overseas.”
What You Need to Know:
The fairly sophisticated attack started in September of 2023, when a known vendor currently working on a project for the city sent legitimate emails discussing issues with payment processing. Because certain emails belonging to city employees were already compromised, threat actors seized the opportunity to impersonate the vendor. They control they exercised over these inboxes including fabricating and also deleting emails. They also manipulated inbox rules to manage and hide these messaging exchanges. Once the hijacked email confirmed payment methods, a series of four monthly payments were sent. These payments went to the threat actors’ account – not the account belonging to the legitimate vendor. This entire attack occurred in the town’s Microsoft environment between September 12, 2023 and January 30, 2024. Note the time frame. City employees would be busy with school updates, followed by the holiday madness.
Implications:
It’s a common misunderstanding that cybercriminals act immediately upon their opportunities. This couldn’t be further from the truth. If the actor is can keep an established breach open, they’re going to maximize their time in the hijacked environment for all it’s worth. Here’s the scariest part of the letter: “The monthly payments were diverted until the vendor reported not receiving payments in February of 2024.” The in-person or by phone interaction, with a real person, launched the investigation. The good news from this is that there were attempts to intercept wire payments totally approximately $5 million during the same four month period that were unsuccessful.
Gmail/Outlook Compatibility Ending June 30
If you rely on your device to sync your multiple calendars, you may want to rethink your planning. Microsoft’s updated security policies will end sync compatibilities with Gmail, effective June 30.
What You Need to Know:
Pick a virtual calendar and stick with it, or deal with the missed appointments and events.
Implications:
Microsoft is moving forward with privacy and security updates, and ending this compatibility feature and others as they do so. They addressed 51 vulnerabilities in June’s Patch Tuesday alone, including 18 remote code execution flaws to close vulnerabilities in the Microsoft Office environment.
Sp1d3r Selling Cybersecurity Company Cylance’s Data
The Snowflake breach continues to give…and give. Cylance described the data Sp1d3r is trying to sell for $750,000 as old and from a third-party vendor (wink, wink). “Old” as it may be, the data includes 34,000,000 customer and employee emails, plus personally identifiable information belonging to Cylance customers, partners, and employees.
What You Need to Know:
Researchers found that the leaked samples appear to be old marketing data from 2015-2018.
Implications:
While a BlackBerry Cylance spokesperson said that “BlackBerry Cylance is not a Snowflake customer,” similar breaches at Santander, Ticketmaster, Quote Wizard/Lending Tree and Advance Auto Parts have all been linked to the Snowflake account compromised on May 20, 2024.
Update Your Fortinet Firewall Firmware – NOW
Speaking of updates, don’t miss the FortiOS v7.4.4 update. It addresses a high-severity flaw in Fortinet firewall firmware, capable of exposing sensitive information like passwords to attackers. The flaw allowed, in a worst-case scenario, unauthorized users with access to a configuration backup of a Fortinet firewall, to decrypt the file and read user credentials.
What You Need to Know:
It’s vital to stay up to date on both firmware and software updates, so you don’t miss wide open doors like this one in your IT policies. This flaw served up passwords on a silver platter to attackers who knew what to look for, and where. The flaw was originally created in the firmware of a firewall appliance with a hard-coded crypto key built into it. Users were advised to change. The patch issued by the vendor in 2019? “Please use a different key.” Even rock solid companies like Fortinet can get it wrong sometimes.
Implications:
The actual fix, not the “recommended” advisory, was released on June 10, 2024, with the advisory published June 11. Fortinet responsibly informed their vendors as well as provided the patch.