Cyber Security Today, Sept. 29, 2021 – A new ransomware gang pops up, another open database found, Nobelium has a new hacking tool and more

A new ransomware gang pops up, another open database found, Nobelium has a new hacking tool and more.

Welcome to Cyber Security Today. It’s Wednesday September 29th. I’m Howard Solomon, contributing writer on cybersecurity for ITWorldCanada.com.

A new ransomware strain has been discovered. Given the nickname Colossus by researchers at ZeroFox, the threat actor claim it has already victimized an American firm that owns several car dealerships. The attacker is threatening to make public 200 GB of stolen data unless the company pays $400,000. That ransom will go up the longer the company waits.

As always the best ways to defend against ransomware – and any cyber attack – include making sure corporate antivirus and intrusion detection software are up to date, enabling multifactor authentication for all employees and contractors, restricting access to sensitive data to only those who need it, and segmenting network resources so ransomware can’t spread across different systems.

Another person has apparently been careless with a corporate database. This time the company involved runs the children’s book website called FarFaria. Security researcher Bob Diachenko at Comparitch discovered an open database belonging to the site with information on almost three million users such as their email addresses, login authentication tokens and other data. When Diachenko alerted the company access to the database was restricted. Often the fault of such incidents is a user not properly configuring the database for security.

Attention administrators of the on-premise version Microsoft Exchange email server: Microsoft has added a new feature in the September cumulative update to help improve security. Called the Emergency Mitigation service, it automatically applies mitigations to Exchange created by Microsoft. Mitigations are temporary fixes for issues until a security update can be installed. While the Emergency Mitigation service is installed automatically with the September cumulative update, it can be turned off if the admin prefers to use the identical but cloud-based Exchange On-premises Mitigation Tool.

Microsoft has also discovered that the threat actor behind the SolarWinds attack that it calls Nobelium has a new tool in its arsenal. It’s another backdoor into IT systems. Its goal is to steal the configuration database of a compromised Active Directory Federation Services server. The directory would have all of the usernames and passwords of employees. It’s vital that Windows administrators audit their on-premise and cloud infrastructure to make sure they haven’t been compromised. There’s a link to the detailed report here.

Another report this week again warns software developers of the dangers of writing unsafe applications. Palo Alto Networks says when it was hired to test a large, unnamed software-as-a-service provider it found lots of misconfigurations. In fact it took only one researcher three days to find critical software development flaws that could have led to a successful cyber attack. The lesson is cloud applications can be just as vulnerable as on-premise software to what are called supply chain attacks that insert bad code or flaws. These problems can range from using flawed frameworks to bad open-source code. DevOps and security teams must gain visibility into the bill of materials in every cloud workload before final code is approved, says the report.

Finally, last week I reported that a Canadian-based voice over IP phone provider had been badly hit by a distributed denial of service attack. This week’s victim is a U.S.-based VoIP and messaging provider called Bandwidth.com. Its service is used by other VoIP providers. By Tuesday Bandwidth.com said it had mitigated much of the attack. But hackers appear to have realized that VoIP providers, as well as internet providers, are vulnerable to DDoS attacks.

That’s it for now Remember links to details about podcast stories are in the text version at ITWorldCanada.com. That’s where you’ll also find other stories of mine.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

Note: This article have been indexed to our site. We do not claim ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Solana Looks Ready for Relief Rally to $200 thumbnail

Solana Looks Ready for Relief Rally to $200

Solana appears to be forming a local bottom after enduring a three-month downtrend. Key Takeaways Solana is down more than 50% from its all-time high recorded in November. SOL appears to be trading in oversold territory, suggesting a rally may be incoming. A spike in upward pressure could see SOL rise toward $200. Multiple buy…
Read More
Public sector growing with Australia: Australian Bureau of Statistics thumbnail

Public sector growing with Australia: Australian Bureau of Statistics

Earnings are calculated across the year, but headcount is based on the last pay period of the year, prompting the ABS to advise against estimating average public sector earnings from the data.The data confirms that state governments are by far the largest employers in the country and include police and safety, teachers and healthcare workers.Employees
Read More
2930_Corn Starch (fdcecs2211) Shares_Oriental Fortune Net Shares thumbnail

2930_Corn Starch (fdcecs2211) Shares_Oriental Fortune Net Shares

发表于 2022-01-10 21:12:23 东方财富期货Android版 郑重声明:用户在财富号/股吧/博客社区发表的所有信息(包括但不限于文字、视频、音频、数据及图表)仅仅代表个人观点,与本网站立场无关,不对您构成任何投资建议,据此操作风险自担。 郑重声明:用户在社区发表的所有资料、言论等仅仅代表个人观点,与本网站立场无关,不对您构成任何投资建议。用户应基于自己的独立判断,自行决定证券投资并承担相应风险。《东方财富社区管理规定》
Read More
Index Of News
Total
0
Share