Transcript
Steve Prentiss (0:00)
From the CISO series, it's Cybersecurity Headlines these are the cybersecurity headlines for Monday, January 13, 2025. I'm Steve Prentiss. IRS Identity Protection PIN Now Available for Filing Season this week the IRS relaunched its Identity Protection Personal Identification Number program. The IP PIN is a six digit number assigned to an individual taxpayer and must be used when filing a tax return. Its number is only valid for the current year and a new one is assigned each year. The goal is, of course, to prevent scammers from filing a tax return using a stolen Social Security number and personal identification. As Bleeping Computer points out, this program is even more critical this year, with over 100 million people's Social Security numbers exposed in the massive national public data breach CISA sees Enrollment Surge in Cyber Hygiene for Critical Infrastructure A report released by CISA on Friday says that after analyzing 7,791 critical infrastructure organizations enrolled in the agency's Vulnerability scanning service between August 1, 2022 through August 31, 2020 24, there were significant increases in enrollment in the agency's Cyber Hygiene service. This is a program that helps organizations reduce their exposure to threats through proactive monitoring and attack mitigation plans. Organizations from communications, emergency services, critical manufacturing and water and wastewater systems registered in large numbers. As a result, CISA says it has found improvements across its six cybersecurity performance goals, mitigating known vulnerabilities no exploitable services on the Internet Strong and agile encryption Limiting OT connections on the public Internet Deploying a security TXT file and email security City Services in Winston Salem Affected by Cyber Attack Residents of Winston, Salem, North Carolina are currently unable to pay their utility bills online following a post Christmas Cyber attack on the city. Officials announced the attack on December 30 after discovering issues with their systems. Starting on December 26, computer systems for digital payment of water and electricity bills have been taken offline, but there have been no disruptions to fire and police abilities. Officials reiterated that there will be no service interruptions or late penalties charged to accounts. Residents can still pay in person with cash or checks, thanks to today's episode's sponsor. DropZone AI feeling buried under endless alerts. They get it. DropZone AI takes over the grind, investigating every alert 24 7. No more chasing false positives or wasting time on the noise. It's all about clarity and focus. Are you ready to transform your day? Well, head on over to DropZone AI to learn more. That is Drop Zone AI marijuana dispensary warns of data Breach this breach affected the California based company Steezy S T I I I Z Y and most specifically the vendor of its point of sale processing services for some of its retail locations. Data and customer IDs from its locations at Union Square and Mission in San Francisco as well as Alameda and Modesto, California were exposed between October 10th and November 10th of 2024. The data consisted of driver's licenses, medical cannabis cards and other personal information, but this varies per individual. In November, the Everest Cybercrime Group claimed responsibility for the attack, initially setting a ransom deadline of December 8, but later it announced the leak of the stolen data, likely after a failed negotiation. Slovakia's Land registry Hit by biggest cyber attack in the country's history the land registry agency, known as ugkk, shut its systems down and closed its physical offices last week following this alleged ransomware attack, the country's Agriculture minister, Richard Takak, said in a press conference that the systems would be restored with backups and that there is no risk of changes or fraudulent transcriptions of ownership data. Although there are no solid details as of yet regarding the group behind the attack, Takak said that there were strong indications that it originated from Ukraine. This may be due to rising tensions between Slovakia and Ukraine following Kyiv's suspension of Russian gas transit through Slovakian territory. 4000 hijacked back doors neutralized by Watchtower following up on a story we covered last week regarding the shadow IT and the problem of backdoors, researchers at Watchtower Labs, working in conjunction with the Shadow Server foundation, registered more than 4,000 abandoned but still active web backdoors sinkholing their communication infrastructure. These backdoors contained live malware and were deployed on web servers of high profile targets including government and university systems, and were ready to execute commands from anyone who took control of the communication domains. The registration obviously prevents these domains from falling into the hands of malicious actors. Microsoft sues hacking group exploiting Azure AI for harmful content creation this legal action is against a foreign based threat actor group which has been operating as a hacking as a service infrastructure to intentionally get around the safety controls of Microsoft's generative artificial intelligence services and produce offensive and harmful content. The threat actors allegedly developed software that exploited exposed customer credentials scraped from public websites and used services such as Azure OpenAI service, monetizing the access by selling the creds to other malicious actors and along with them the detailed instructions as to how to use these custom tools to generate harmful content. Microsoft said it has since revoked the threat actors group access and implemented new countermeasures and fortified its safeguards to prevent such activity from occurring in the future. We would love to get feedback about cybersecurity headlines, so please reach out to the CISO series on CISO series on LinkedIn or YouTube. Let us know how we're doing. Or you can shoot us an email@infososeries.com we would really love to hear from you. I'm Steve Prentice reporting for the CISO series. Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full stories behind the headlines.
