
Loading summary
Steve Prentiss
From the CISO series, it's Cybersecurity Headlines these are the cybersecurity headlines for Monday, January 13, 2025. I'm Steve Prentiss. IRS Identity Protection PIN Now Available for Filing Season this week the IRS relaunched its Identity Protection Personal Identification Number program. The IP PIN is a six digit number assigned to an individual taxpayer and must be used when filing a tax return. Its number is only valid for the current year and a new one is assigned each year. The goal is, of course, to prevent scammers from filing a tax return using a stolen Social Security number and personal identification. As Bleeping Computer points out, this program is even more critical this year, with over 100 million people's Social Security numbers exposed in the massive national public data breach CISA sees Enrollment Surge in Cyber Hygiene for Critical Infrastructure A report released by CISA on Friday says that after analyzing 7,791 critical infrastructure organizations enrolled in the agency's Vulnerability scanning service between August 1, 2022 through August 31, 2020 24, there were significant increases in enrollment in the agency's Cyber Hygiene service. This is a program that helps organizations reduce their exposure to threats through proactive monitoring and attack mitigation plans. Organizations from communications, emergency services, critical manufacturing and water and wastewater systems registered in large numbers. As a result, CISA says it has found improvements across its six cybersecurity performance goals, mitigating known vulnerabilities no exploitable services on the Internet Strong and agile encryption Limiting OT connections on the public Internet Deploying a security TXT file and email security City Services in Winston Salem Affected by Cyber Attack Residents of Winston, Salem, North Carolina are currently unable to pay their utility bills online following a post Christmas Cyber attack on the city. Officials announced the attack on December 30 after discovering issues with their systems. Starting on December 26, computer systems for digital payment of water and electricity bills have been taken offline, but there have been no disruptions to fire and police abilities. Officials reiterated that there will be no service interruptions or late penalties charged to accounts. Residents can still pay in person with cash or checks, thanks to today's episode's sponsor. DropZone AI feeling buried under endless alerts. They get it. DropZone AI takes over the grind, investigating every alert 24 7. No more chasing false positives or wasting time on the noise. It's all about clarity and focus. Are you ready to transform your day? Well, head on over to DropZone AI to learn more. That is Drop Zone AI marijuana dispensary warns of data Breach this breach affected the California based company Steezy S T I I I Z Y and most specifically the vendor of its point of sale processing services for some of its retail locations. Data and customer IDs from its locations at Union Square and Mission in San Francisco as well as Alameda and Modesto, California were exposed between October 10th and November 10th of 2024. The data consisted of driver's licenses, medical cannabis cards and other personal information, but this varies per individual. In November, the Everest Cybercrime Group claimed responsibility for the attack, initially setting a ransom deadline of December 8, but later it announced the leak of the stolen data, likely after a failed negotiation. Slovakia's Land registry Hit by biggest cyber attack in the country's history the land registry agency, known as ugkk, shut its systems down and closed its physical offices last week following this alleged ransomware attack, the country's Agriculture minister, Richard Takak, said in a press conference that the systems would be restored with backups and that there is no risk of changes or fraudulent transcriptions of ownership data. Although there are no solid details as of yet regarding the group behind the attack, Takak said that there were strong indications that it originated from Ukraine. This may be due to rising tensions between Slovakia and Ukraine following Kyiv's suspension of Russian gas transit through Slovakian territory. 4000 hijacked back doors neutralized by Watchtower following up on a story we covered last week regarding the shadow IT and the problem of backdoors, researchers at Watchtower Labs, working in conjunction with the Shadow Server foundation, registered more than 4,000 abandoned but still active web backdoors sinkholing their communication infrastructure. These backdoors contained live malware and were deployed on web servers of high profile targets including government and university systems, and were ready to execute commands from anyone who took control of the communication domains. The registration obviously prevents these domains from falling into the hands of malicious actors. Microsoft sues hacking group exploiting Azure AI for harmful content creation this legal action is against a foreign based threat actor group which has been operating as a hacking as a service infrastructure to intentionally get around the safety controls of Microsoft's generative artificial intelligence services and produce offensive and harmful content. The threat actors allegedly developed software that exploited exposed customer credentials scraped from public websites and used services such as Azure OpenAI service, monetizing the access by selling the creds to other malicious actors and along with them the detailed instructions as to how to use these custom tools to generate harmful content. Microsoft said it has since revoked the threat actors group access and implemented new countermeasures and fortified its safeguards to prevent such activity from occurring in the future. We would love to get feedback about cybersecurity headlines, so please reach out to the CISO series on CISO series on LinkedIn or YouTube. Let us know how we're doing. Or you can shoot us an email@infososeries.com we would really love to hear from you. I'm Steve Prentice reporting for the CISO series. Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full stories behind the headlines.
Host: Steve Prentiss
Podcast: Cyber Security Headlines by CISO Series
Timestamp: [00:30]
The IRS has relaunched its Identity Protection Personal Identification Number (IP PIN) program for the current filing season. This six-digit number is assigned annually to individual taxpayers and is mandatory for filing tax returns. The primary objective of the IP PIN is to thwart scammers attempting to file tax returns using stolen Social Security numbers and personal identification information.
Steve Prentiss highlighted the program's increased importance this year, noting, “With over 100 million people's Social Security numbers exposed in the massive national public data breach, the IP PIN program serves as a critical defense mechanism” ([00:45]).
Key Points:
Timestamp: [02:15]
The Cybersecurity and Infrastructure Security Agency (CISA) reported a significant uptick in enrollments for its Cyber Hygiene service among critical infrastructure organizations. Analyzing data from August 1, 2022, to August 31, 2024, CISA observed increased participation from sectors such as communications, emergency services, critical manufacturing, and water and wastewater systems.
Steve Prentiss emphasized the impact of these enrollments: “The surge in Cyber Hygiene enrollments has led to tangible improvements across our six cybersecurity performance goals, including mitigating known vulnerabilities and implementing strong encryption practices” ([02:25]).
Key Points:
Timestamp: [04:10]
Residents of Winston-Salem, North Carolina, are experiencing disruptions in paying utility bills online due to a cyberattack that began on December 26, 2024. The city officially announced the breach on December 30, revealing that computer systems for digital payments of water and electricity bills were taken offline. However, essential services such as fire and police operations remained unaffected.
Steve Prentiss reassured listeners, stating, “There will be no service interruptions or late penalties charged to accounts, and residents can still pay in person with cash or checks” ([05:00]).
Key Points:
Timestamp: [06:30]
The California-based marijuana dispensary, Steezy (STIIZY), announced a data breach that impacted its point-of-sale processing vendor. The breach affected retail locations in Union Square and Mission in San Francisco, as well as Alameda and Modesto. Between October 10 and November 10, 2024, unauthorized access led to the exposure of driver's licenses, medical cannabis cards, and other personal information.
Steve Prentiss reported, “The Everest Cybercrime Group claimed responsibility for the attack, initially demanding ransom by December 8, but later opted to leak the stolen data after negotiations failed” ([07:00]).
Key Points:
Timestamp: [08:45]
Slovakia's land registry agency, UGKK, faced its most significant cyberattack to date, resulting in the shutdown of its systems and the closure of physical offices last week. Agriculture Minister Richard Takak confirmed that systems would be restored using backups, assuring the public that there was no risk of data tampering or fraudulent ownership changes.
Steve Prentiss noted potential geopolitical underpinnings, saying, “There are strong indications that the attack originated from Ukraine, possibly linked to rising tensions following Kyiv's suspension of Russian gas transit through Slovakian territory” ([09:15]).
Key Points:
Timestamp: [10:30]
Addressing the ongoing issue of shadow IT and the proliferation of backdoors, Watchtower Labs in collaboration with the Shadow Server Foundation successfully neutralized over 4,000 abandoned but active web backdoors. These backdoors were dormant yet contained live malware, deployed on high-profile targets including government and university systems.
Steve Prentiss explained, “By sinkholing their communication infrastructure, we prevent these backdoors from being exploited by malicious actors, thereby enhancing overall cybersecurity resilience” ([11:00]).
Key Points:
Timestamp: [12:45]
Microsoft has initiated legal action against a foreign-based threat actor group that exploited Azure AI services to generate offensive and harmful content. The group operated as a hacking-as-a-service infrastructure, bypassing Microsoft's AI safety controls by using stolen customer credentials sourced from public websites. They monetized this access by selling credentials and detailed instructions for creating harmful content.
Steve Prentiss highlighted Microsoft's response, stating, “We have revoked the threat actors' access and implemented new countermeasures to fortify our safeguards, ensuring such activities are thwarted in the future” ([13:15]).
Key Points:
In this episode of Cyber Security Headlines, Steve Prentiss delivered a comprehensive overview of significant cybersecurity events ranging from national identity protection initiatives to sophisticated cyberattacks on critical infrastructure and corporate entities. The discussions underscored the evolving landscape of cyber threats and the proactive measures various organizations are implementing to safeguard against them.
For more detailed stories behind these headlines, listeners are encouraged to visit CISOSeries.com.
This summary captures the key discussions and insights from the January 13, 2025, episode of Cyber Security Headlines. Notable quotes are attributed to Steve Prentiss with corresponding timestamps for reference.