Skip to main content

Colorado-Based Cybersecurity Company – Managed Business I.T.

Cyber News: What You Need to Know, Weekly Edition

Cyber News Header

In this weekly blog, we’ll compile the top cyber news you need to know from the week before and provide an easy breakdown so you can get the news you need and skip the fluff you don’t. 

Operation Endgame: Worldwide Effort Takes Down 100 Servers Responsible for Hundreds of Millions in Damages

Law enforcement in Ukraine, Bulgaria, Romania, Portugal, Lithuania, and Switzerland moved in a coordinated attack, conducting searches, executing warrants, questioning and arresting suspects, and confiscating servers. These efforts targeted four cybercrime groups in particular, IcedID, Smokeloader, Pikabot, and Bumblebee. “These malware groups have infected millions of computers and claimed countless victims around the world and throughout the United States, including a hospital network, which not only cost millions of dollars but alarmingly put people’s lives at risk due to the compromised critical care online system.”

What You Need to Know:

This was the first coordinated, global cybersecurity takedown, but it definitely won’t be the last. Operation Endgame will be an ongoing operation, and likely one of many more to come. 

Implications:

Global cybersecurity task forces are the future, and we’ll definitely be seeing more takedowns like this. Cyber crime is very similar to the war on hard drugs – if there’s money to be made, then there will be criminals there aking it. However, every takedown is worth celebrating.

Catholic Health Organization, Ascension, Still Recovering from Ransomware Attack

Can you imagine waiting four hours for a CAT scan or MRI for a brain bleed? What about sending confidential prescriptions via fax? This was a reality for Ascension, a Catholic health organization containing more than 140 hospitals and senior care centers. Black Basta is claiming the ransomware attack, which forced the organization to have to turn away ambulances, cut off critical diagnostic care, revert to paper record keeping, and cancel all non-emergent appointments. Ascension was hoping to have made significant progress in its recovery by Memorial Day weekend.

What You Need to Know: 

Lawsuits are already pending against the healthcare giant following the ransomware attack. The feds also issued a warning about the ransomware-for-hire group, Black Basta. 

Implications: 

What is new, however, is a growing call for CISOs and other C-suite executives to be held both civilly and criminally liable for the deaths that occurred as a direct result of the attack, which tripled (or more) wait times for care.

Microsoft Warns of New Trends of Cyber Attacks Against IoT Devices

With growing global conflicts, like the continued war in Ukraine and the escalating conflict in Israel, Microsoft issued a warning regarding increasing attacks on typically less secure IoT devices, especially those manufactured in or by Israel, or deployed in Israel. These attacks are targeting Programmable Logic Controllers (PLCs) or human machine interfaces (HMI). In the attack, set points are maxed out or removed altogether, altered settings, removed warnings or notifications, and changed passwords to lockout the real authorized users.

What You Need to Know:

Your IoT devices should not be on a public-facing internet. You must have stratified internet access to control your office or organization’s most vulnerable points. 

Implications: 

By targeting PLCs and HMIs, hacktivists can effectively sidetrack the set points you depend on to safeguard your processes and valuable equipment. This effectively cripples your business and locks any authorized users out of your systems to fix it.

FBI Plays Whack-a-Mole with Dark Web Marketplace BreachForums

In a now-temporary win, the FBI was able to take down the dark web marketplace, BreachForums, where stolen data from breaches or data harvesting takes place. The website was taken down on May 15th, and by May 28th, was back in operation under a new administration name. An earlier admin of the marketplace, Conor Brian Fitzpatrick, was arrested in 2023, and consequently sentenced to 20 years of supervised release in January. The ongoing tension between cybercriminals and the FBI is becoming more and more a game of whack-a-mole as operators use backups to recreate the website as quickly as possible on a different domain. 

What You Need to Know:

What’s interesting about this takedown and re-emergence is that the Department of Justice hasn’t commented on it- at all- in contrast to the heavily covered Operation Endgame. Also of note – even the bad guys use backups. So you should, too. 

Implications: 

The sad truth is, as long as there is money to be made from stolen data, the whack-a-mole game of takedown and re-emergence will continue. Your best option to safeguard your business or organization’s mission is to implement cybersecurity best practices, fortify your digital environment, and consistently train your endpoint users. 

New Research Out on Offboarding Management Risks

A recent study published by Wing Security found that 63% of businesses may have offboarded employees who still have access to organizational data. Failure to quickly and effectively offboard an employee, especially a potentially disgruntled employee, can create longlasting havoc. This is compounded when you have mass layoffs like what have been happening at Google (12,000); Microsoft (10,000); Meta (10,000); Disney Pixar (175) and more. 

What You Need to Know:

It is very important that your HR and IT teams work together to effectively offboard to allow for proper data stratification,  file access, and operational data access. For every system onboarded, there has to be some form of accountability for system offboarding (Microsoft Office in, Office out. Share drive in, share drive out, etc.).

Implications:

Lack of secure offboarding practices can lead to theft of intellectual property, compliance violations, (a hospital in Pagosa Springs had to pay $114,000 in damages in 2018 because a former employee had remote access to PHI) and insider threats. Translation: don’t be that guy that caused that thing. 

 

Want to schedule a cybersecurity audit for your business, practice, or organization? Hit the button below to get started.

Leave a Reply

Your email address will not be published. Required fields are marked *