How Hackers Phish for Your Users’ Credentials and Sell Them

November 28, 2023 at 06:24AM Account credentials are highly valuable in cybercrime, with stolen credentials posing a significant risk to organizations. External parties are responsible for 83% of breaches, with 49% involving stolen credentials. Phishing is a common method of credential theft, with threat actors using multi-channel attacks and targeting mobile devices. Phishing-as-a-service (PhaaS) has … Read more

Data De-Identification: Balancing Privacy, Efficacy & Cybersecurity

November 28, 2023 at 04:50AM Data privacy laws aim to protect consumer data by implementing best practices for businesses. However, recent data breaches suggest that these regulations have not been successful in safeguarding consumer data. One reason is the need for companies to balance privacy protection, product efficacy, and cybersecurity. Data de-identification is a key … Read more

India’s CERT given exemption from Right To Information requests

November 28, 2023 at 01:38AM India’s Computer Emergency Response Team (CERT-In) has been granted immunity from Right To Information (RTI) requests. The reasons for the exemption are unknown, but it comes after an embarrassing incident where an RTI request revealed low compliance with CERT-In’s infosec incident reporting requirements. This move has been criticized by the … Read more

Ardent Health Hospitals Disrupted After Ransomware Attack

November 27, 2023 at 04:43PM Ardent Health Services experienced a ransomware attack in November, affecting its entire network and 30 hospitals across six states. Patient care was not disrupted, but some emergency cases are being redirected to other hospitals. Ardent has reported the attack, launched an investigation, and suspended user accounts. The restoration of access … Read more

Healthcare giant Henry Schein hit twice by BlackCat ransomware

November 27, 2023 at 02:50PM Healthcare company Henry Schein has reported a second cyberattack this month by the BlackCat/ALPHV ransomware gang, following a breach in October. The company has restored its U.S. e-commerce platform and expects the platforms in Canada and Europe to be back online soon. The BlackCat gang claims to have stolen 35 … Read more

Ardent hospital ERs disrupted in 6 states after ransomware attack

November 27, 2023 at 12:56PM Ardent Health Services, a healthcare provider with 30 hospitals across six U.S. states, experienced a ransomware attack, leading to the entire network being taken offline. Impacted hospitals are diverting emergency care to other facilities while still providing medical screening and stabilizing care. Non-urgent elective surgeries have been temporarily halted. Ardent … Read more

Henry Schein Again Restoring Systems After Ransomware Group Causes More Disruption

November 27, 2023 at 10:24AM Healthcare solutions company Henry Schein is in the process of restoring its systems after a ransomware group re-encrypted files during negotiations. The group, known as Alphv and BlackCat, claimed responsibility for the attack, saying they encrypted files and stole sensitive data. Henry Schein confirmed a data breach and potential theft … Read more

Data De-Identification: Balancing Privacy, Efficacy & Cybersecurity

November 27, 2023 at 10:04AM Global data privacy laws aim to protect consumer personal data, but recent data breaches highlight ongoing vulnerabilities. One potential reason for this is the delicate balance that companies must strike between protecting privacy, maintaining product efficacy, and mitigating cyber breaches. Data de-identification, a key safeguard measure, is necessary, but full … Read more

Ransomware-hit British Library: Too open for business, or not open enough?

November 27, 2023 at 04:38AM The British Library, known for its public knowledge and vast collection of items, recently fell victim to a cybersecurity breach. Ransomware bandits stole HR data and disrupted the institution’s infrastructure, causing inconvenience to researchers and delaying their work. The attack on the British Library is just one of many corporate … Read more

General Electric investigates claims of cyber attack, data theft

November 25, 2023 at 05:44PM General Electric (GE) is investigating a possible cyberattack in which a threat actor breached their development environment and leaked alleged stolen data. The threat actor, known as IntelBroker, attempted to sell access to GE’s development and software pipelines on a hacking forum but later claimed to be selling the network … Read more