
Loading summary
A
From the CISO series, It's Cybersecurity Headlines.
B
These are the cybersecurity headlines for Friday, January 10, 2025. I'm Steve Prentiss. Proton Recovers from Worldwide Outage the privacy firm Proton is dealing with a massive outage that started at 10am Eastern Time yesterday, leaving members unable to access ProtonVPN mail, calendar, drive Pass and wallet. Most services were restored quickly. ProtonMail was restored later at about 1:09pm Eastern and calendar was still not available as of the time of this recording. Explanations about the cause of the outage have still not yet been delivered. Baymark Health Announces Data Breach North America's largest provider of substance use disorder treatment and recovery services is now notifying patients that their personal and health information was stolen in a September 20202024 breach. Baymark said it learned of the breach on October 11th of last year following an IT systems disruption. End quote. The company determined that the attackers accessed ITS systems between September 24 and October 1. The number of individuals who were sent letters was not revealed. The data stolen includes Social Security numbers, driver's license numbers, date of birth, services received and insurance information. Based in Texas, the organization provides medication assisted treatment services for substance use and mental health disorders in more than 400 service sites across 35 states and three Canadian provinces. U.S. treasury breach linked to Silk Typhoon Group following up on a story we have been watching these past few weeks, it has now been revealed that the Silk Typhoon APT Group was responsible for the treasury hack using stolen remote support SaaS, API keys. Through third party cybersecurity vendor Beyond Trust, it was able to steal data from workstations in the Office of Foreign Assets Control as well as the Treasury Department's Office of Financial Research. Silk Typhoon's actual name is Hafnium and it is well known for hitting targets in education, healthcare, defence and non governmental organizations. As a side note, the Typhoon appellation is a Microsoft convention for labeling Chinese APT groups the same way Blizzard is used for Russian threat actors, Sleet for North Korean threat actors and Sandstorm for Iranian threat actors. Russian ISP confirms Ukrainian hackers destroyed its network Hacktivists from the Ukrainian Cyber alliance group announced on Tuesday they had breached the network of Russian Internet service provider Nodex and had wiped its systems after stealing sensitive documents, leaving only empty equipment without backups. The hackers showed off screenshots of the ISP's VMware Veeam Backup and Hewlett Packard Enterprise virtual infrastructure that were hacked during the breach. Thanks to today's episode's sponsor, Nudge Security Are you struggling to Secure your exploding SaaS footprint? Nudge Security has you covered. Start a free trial today and get immediate visibility of every SaaS account ever created by anyone in your organization. With Nudge Security, you can manage access, ensure secure configurations, vet unfamiliar tools, and automate ongoing governance tasks. Visit nudgesecurity.com cisoseries to get your free SaaS inventory today. That is nudgeesecurity.com cisoseries CISA adds Ivanti products and ZTA Gateways flaw to its KEV catalog the Ivanti Connect Secure vulnerability, with a CVSS score of 9.0, was added to the agency's known Exploited Vulnerabilities catalog alongside ZTA Gateways, also manufactured by Ivanti, the agency stated in an advisory. Successful exploitation of the flaw could lead to unauthenticated remote code execution. A related flaw could also allow a local authenticated attacker to escalate privileges, although as usual, private companies are also urged to update their systems. Federal agencies must address this vulnerability by January 15th. CAIO releases information on their October ransomware attack the electronics company has published a post mortem on the October 5 attack stating that 6,456 employees, 1,931 business partners and 91 customers were impacted by the ransomware incident. An outside cybersecurity firm blamed the ransomware attack on phishing emails that allowed the hackers into casio's servers on October 5th. The stolen data included PII employees. The business partners affected had basic company information stolen and the customer's data was PII along with product purchase information. The attack was claimed by the underground ransomware gang, which said it stole more than 200 gigabytes of data. And in addition to the data theft, this also caused the company weeks of delivery delays. Critical RCE flaw in GFI Kerio control allows remote code execution GFI Kerio Control is a network security solution that provides firewall functionality and unified threat management capabilities such as threat detection and blocking, traffic control, intrusion prevention and VPN features. Security researcher Adigio Romano published a write up of the vulnerability on December 16 and explained that the reflected cross site scripting attack vector can be exploited to perform one click RCE attacks. Threat intelligence firm Census says IT has observed 24,000 instances accessible from the Internet, many of which are in Iran. However, it is unclear how many of these are vulnerable. Medical billing firm MedusInd announces data breach the medical and dental billing and revenue cycle management company spelled Medusind says that an intrusion the Incident occurred on December 29, 2023 and involves the PII, health information, Social Security numbers and other government ID on just over 360,000 people. Security Week suggests that while Medusin's brief description of the incident suggests that the company may have been targeted in a ransomware attack, Security Week itself has not seen any known cybercrime group taking credit for the breach. End quote. Make sure to join us later today at 3:30pm Eastern for our Week in Review show. Bill Harmer, operating partner and CISO at Craft Ventures, will be our guest, providing his expert commentary on the news of the week. And we encourage participation and comments through our YouTube live channel. Just go to the events page@cisoseries.com I'm Steve Prentiss reporting for the CISO series.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Hosted by CISO Series
In this episode of Cyber Security Headlines, hosted by Steve Prentiss from the CISO Series, several critical events unfolded in the information security landscape. The discussion provides an in-depth analysis of major outages, data breaches, and vulnerabilities impacting organizations worldwide. Below is a comprehensive summary of the key topics covered.
Overview: Privacy-focused firm Proton suffered a significant service disruption beginning at 10:00 AM Eastern Time on January 9, 2025. The outage affected multiple Proton services, including ProtonVPN, ProtonMail, calendar, drive, Pass, and wallet functionalities.
Service Restoration:
Cause of Outage: Proton has not yet disclosed the underlying cause of the disruption, leaving members uncertain about the factors leading to the outage.
Notable Quote:
"Proton is dealing with a massive outage that started at 10am Eastern Time yesterday, leaving members unable to access ProtonVPN mail, calendar, drive Pass and wallet."
— Steve Prentiss [00:07]
Incident Details: Baymark Health, North America's largest provider of substance use disorder treatment and recovery services, disclosed a data breach affecting patients' personal and health information. The breach occurred between September 24 and October 1, 2024.
Detection and Response:
Company Profile: Based in Texas, Baymark Health provides medication-assisted treatment and mental health disorder services through a vast network of facilities.
Notable Quote:
"North America's largest provider of substance use disorder treatment and recovery services is now notifying patients that their personal and health information was stolen in a September 20202024 breach."
— Steve Prentiss [00:07]
Incident Overview: An update on the breach within the U.S. Treasury Department has revealed that the Silk Typhoon APT Group, also known as Hafnium, was responsible for the attack. The group exploited stolen remote support SaaS API keys via the cybersecurity vendor Beyond Trust to infiltrate Office of Foreign Assets Control and the Treasury Department's Office of Financial Research.
Group Profile: Hafnium is notorious for targeting sectors such as education, healthcare, defense, and non-governmental organizations. The "Typhoon" nomenclature is part of Microsoft's convention for categorizing Chinese APT groups, paralleling other labels like "Blizzard" for Russian actors.
Notable Quote:
"Silk Typhoon APT Group was responsible for the treasury hack using stolen remote support SaaS, API keys."
— Steve Prentiss [00:07]
Attack Details: Hacktivists from the Ukrainian Cyber Alliance group successfully breached the Russian Internet Service Provider Nodex. They wiped the ISP's systems, deleting sensitive documents and leaving the infrastructure barren, sans backups.
Evidence Presented: The attackers shared screenshots showcasing compromised VMware Veeam Backup and Hewlett Packard Enterprise virtual infrastructure systems, highlighting the extent of the breach.
Notable Quote:
"Hacktivists from the Ukrainian Cyber alliance group announced on Tuesday they had breached the network of Russian Internet service provider Nodex and had wiped its systems after stealing sensitive documents."
— Steve Prentiss [00:07]
Vulnerability Details: The Cybersecurity and Infrastructure Security Agency (CISA) added two Ivanti products to its Known Exploited Vulnerabilities (KEV) catalog:
Action Required: Federal agencies are mandated to address these vulnerabilities by January 15, 2025. Private companies are also strongly encouraged to update their systems to mitigate potential threats.
Notable Quote:
"The Ivanti Connect Secure vulnerability, with a CVSS score of 9.0, was added to the agency's known Exploited Vulnerabilities catalog alongside ZTA Gateways."
— Steve Prentiss [00:07]
Incident Overview: CAIO released a post-mortem report on their ransomware attack dated October 5, 2024. The breach impacted:
Attack Vector: The ransomware infiltration was attributed to phishing emails that granted hackers access to CAIO’s servers. The incident resulted in the theft of personally identifiable information (PII) and caused significant delivery delays.
Attacker Claims: An underground ransomware gang claimed responsibility, stating they stole over 200 gigabytes of data.
Notable Quote:
"The stolen data included PII employees... and customer's data was PII along with product purchase information."
— Steve Prentiss [00:07]
Vulnerability Details: Security researcher Adigio Romano identified a critical reflected cross-site scripting (XSS) vulnerability in GFI Kerio Control that can be exploited to perform one-click Remote Code Execution (RCE) attacks.
Impact: Census, a threat intelligence firm, reported observing 24,000 instances of GFI Kerio Control accessible from the Internet, with many located in Iran. The exact number of vulnerable systems remains unclear.
Solution: Organizations using GFI Kerio Control are urged to apply patches and implement security measures to prevent exploitation.
Notable Quote:
"GFI Kerio Control is a network security solution that provides firewall functionality and unified threat management capabilities."
— Steve Prentiss [00:07]
Incident Details: MedusInd, a medical and dental billing and revenue cycle management company, reported a data breach occurring on December 29, 2023. The breach compromised:
Attack Attribution: While the company suggests the breach may have been the result of a ransomware attack, no cybercrime group has claimed responsibility as of the report.
Notable Quote:
"MEDUSIND says that an intrusion the Incident occurred on December 29, 2023 and involves the PII, health information, Social Security numbers and other government ID on just over 360,000 people."
— Steve Prentiss [00:07]
Event Details: Listeners are invited to join the Week in Review show scheduled for later the same day at 3:30 PM Eastern Time. The session will feature Bill Harmer, Operating Partner and CISO at Craft Ventures, who will provide expert commentary on the week's news.
Participation: Engagement is encouraged through comments and participation via the CISO Series' YouTube live channel. Details can be found on the events page at cisoseries.com.
Closing Quote:
"Make sure to join us later today at 3:30pm Eastern for our Week in Review show."
— Steve Prentiss [07:12]
For comprehensive details and full stories behind these headlines, listeners are directed to visit cisoseries.com.
This summary encapsulates the critical cybersecurity events discussed in the January 10, 2025, episode of Cyber Security Headlines by the CISO Series. Stay informed and secure by regularly following trusted sources and implementing recommended security measures.