ProactiveIT

ProactiveIT Ep 28 – The Hidden Costs of Ransomware

1 h 3 min · 8 mei 2020
aflevering ProactiveIT Ep 28 – The Hidden Costs of Ransomware artwork

Beschrijving

THIS IS THE PROACTIVEIT PODCAST.  THIS WEEK: THE LATEST IN IT AND CYBER SECURITY NEWS PLUS CRITICAL VULNERABILITIES BEING PATCHED, BREACHES & CYBERSECURITY STATS ARE GLOOMY, AND THE COST OF RANSOMWARE THIS IS EPISODE 28 INTRO Hi Everyone and welcome to the Proactive IT Podcast.  Each week we talk about the latest in tech and cyber news, compliance, and more.  We also bring you real-world examples to learn from so that you can better protect your business and identity. This podcast is brought to you by Nwaj Tech – a client-focused & security-minded IT Consultant located in Central Connecticut.  You can find us at nwajtech.com. Thanks for listening to this podcast.  Show us some love on Apple or Google Podcasts.  Subscribe and leave us some positive feedback.  What are you waiting for? Also, go join the Get HIPAA Compliance Facebook Group.  Search for Get HIPAA Compliance PATCH TUESDAY UPDATE: Unpatched Oracle WebLogic Servers Vulnerable to CVE-2020-2883 [https://www.us-cert.gov/ncas/current-activity/2020/05/01/unpatched-oracle-weblogic-servers-vulnerable-cve-2020-2883] SaltStack Patches Critical Vulnerabilities in Salt [https://www.us-cert.gov/ncas/current-activity/2020/05/01/saltstack-patches-critical-vulnerabilities-salt] Firefox 76 released with integrated data breach alerts [https://www.bleepingcomputer.com/news/software/firefox-76-released-with-integrated-data-breach-alerts/] Microsoft releases May Office updates with fixes for auth issues [https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-may-office-updates-with-fixes-for-auth-issues/] Instacart Patches Security Bug That Would Have Let Attackers Spoof SMS Messages [https://www.darkreading.com/risk/instacart-patches-security-bug-that-would-have-let-attackers-spoof-sms-messages/d/d-id/1337734?&web_view=true] Google Releases Security Updates for Chrome [https://www.us-cert.gov/ncas/current-activity/2020/05/06/google-releases-security-updates-chrome] Cisco Releases Security Updates for Multiple Products [https://www.us-cert.gov/ncas/current-activity/2020/05/07/cisco-releases-security-updates-multiple-products] CYBER SECURITY NEWS Trump Declares National Emergency As Foreign Hackers Threaten U.S. Power Grid [https://www.forbes.com/sites/daveywinder/2020/05/02/trump-declares-national-emergency-as-foreign-hackers-threaten-us-power-grid/?fbclid=IwAR23zJbQadTSo5AF7graEubyD6jvULdt0VBI4XTlK6dzlHszC-pUo-zlmho#150f89593497] GoDaddy notifies users of breached hosting accounts [https://www.bleepingcomputer.com/news/security/godaddy-notifies-users-of-breached-hosting-accounts/] Ciitizen HIPAA Right of Access Study Shows Significant Improvement in Compliance [https://www.hipaajournal.com/ciitizen-hipaa-right-of-access-study-shows-significant-improvement-in-compliance/] Nearly 2,000 malicious COVID-19-themed domains created every day [https://www.techrepublic.com/article/nearly-2000-malicious-covid-19-themed-domains-created-every-day/?&web_view=true] US financial industry regulator warns of widespread phishing campaign [https://www.zdnet.com/article/us-financial-industry-regulator-warns-of-widespread-phishing-campaign/?&web_view=true] SAP announces security issues in cloud-based products [https://www.bleepingcomputer.com/news/security/sap-announces-security-issues-in-cloud-based-products/] Cyberattack on NTPC Further Exposes the Cybersecurity Risks of Energy Sector [https://cyware.com/news/cyberattack-on-ntpc-further-exposes-the-cybersecurity-risks-of-energy-sector-6896de5e] An Update on Cognizant [https://www.msspalert.com/cybersecurity-breaches-and-attacks/ransomware/cognizant-status-update/] Critical WordPress plugin bug lets hackers take over 1M sites [https://www.bleepingcomputer.com/news/security/critical-wordpress-plugin-bug-lets-hackers-take-over-1m-sites/] HOT TOPICS Topic 1: Consumers will opt for competitors after a single ransomware-related service disruption [https://www.helpnetsecurity.com/2020/05/04/ransomware-related-service-disruption/?web_view=true] Topic 2: Patients Notified Medical Records Exposed at Tornado Hit Secure Medical Record Facility [https://www.hipaajournal.com/patients-notified-medical-records-exposed-at-tornado-hit-secure-medical-record-facility/] Topic 3: Half of Companies Have Suffered a Cybersecurity Issue Amid COVID-19 Crisis [https://www.darkreading.com/vulnerabilities---threats/half-of-companies-have-suffered-a-cybersecurity-issue-amid-covid-19-crisis-/d/d-id/1337753?&web_view=true] HIPAA CORNER: https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf [https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf] BREACHES https://www.hipaajournal.com/category/hipaa-breach-news/ [https://www.hipaajournal.com/category/hipaa-breach-news/] Ep 28 Critical Vulnerabilities Being Patched, Breaches & Cybersecurity Stats are Gloomy, and the Cost of Ransomware IGS [https://nwajtech.com/wp-content/uploads/2020/05/Ep-28-Critical-Vulnerabilities-Being-Patched-Breaches-Cybersecurity-Stats-are-Gloomy-and-the-Cost-of-Ransomware-IGS-683x1024.jpg] Transcription (Unedited) This is the proactive it podcast this week the latest in it in cybersecurity news. Plus critical vulnerabilities being patched. breaches in cybersecurity stats are gloomy, and the cost of ransomware. This is Episode 28. Hi everyone and welcome to the productive it podcast each week we talk about the latest in tech and cyber news compliance and more. We also bring your real world examples to learn from so that you can better protect your business and your identity. This podcast is brought to you by wash tech a client focused and security minded consultant located in Central Connecticut, you can find us at and wash tech comm that’s NW Aj tech.com. Well, it’s been another fun week in isolation. I don’t know what to call it really, because it’s not real isolation, we can go out, but you’re trying to avoid it for the most part and I’m now entering week eight It is day 56 as I record this I don’t know. Good. Seems like there may be some some light at the end of the tunnel. But we’ll see. First of all, wherever you’re listening to this, if you could like share, review or comment, you know, whatever, we’ll get people to, you know, new people to listen to, if that would be awesome. You know, especially on Apple and Google, but also stitcher and anywhere else you listen to it. And if you’re in a HIPAA compliant business, if you can go over to Facebook, type in get HIPAA compliance, and join that group. You’ll be awarded with Lots of HIPAA information. And if you want to go to that now, are we you know, just you go do that, and I’ll wait right here. All right. Did you do you? Um, I did not. You know, I’ll be honest with you. I got asked a lot of questions this week, and I did not pick one to completely forgot about it, to be honest. So we’re not going to do a question of the week. We’re going to jump right into the updates for the week. And so it is the first week of May. We do not have Patch Tuesday updates from Microsoft, but we do have quite a few updates to talk about. So we’re gonna jump right into that, with the first one being unpatched Oracle WebLogic servers that are vulnerable to CVE 2020 2083 Oracle has released a blog post warning users that have previously disclosed Oracle WebLogic Server remote code execution vulnerability is being exploited in the wild Oracle disclose the vulnerability and provided software patches in April 20. 20 critical patch update over malicious cyber actors are now known to be targeting unpatched servers so if you’re using Oracle WebLogic Server get patched because it’s already been exploited saltstack which you may have heard about because it’s being it’s impacted some pretty big systems including ghost blogging platform saltstack does did patch a critical vulnerability in salt. So you should be if you’re, you shouldn’t be on anything prior to 2019 point 2.4 or three first salt. I’m sorry, should not be on anything prior to 2019 point 2.4 or two to 3,000.2. So get that updated ASAP because it is being actively exploited. Firefox 76 was released to integrate data breach alerts I I’m obviously I’m on Firefox 76 already, I have not checked out the data breach alert to see if it works at all. So we’ll be it’ll be interesting to see how that develops. There were some security vulnerabilities addressed with that release as well. Microsoft released May office updates with fixes for auth issues. There are no security updates as part of this rollout. But there is an issue with auth issues basically. Blank authentication prompts were being displayed. And I believe there was something that was crashing as well. I don’t I don’t remember what it wasn’t this point, but it’s a it’s a bug in feature update. So applied at will Microsoft Office 2016. PowerPoint 2016 outlook 2016 Project 2016 word 2016. And Skype for Business 2015 instacart did patch a security bug that would have led to tech spoof SMS messages. I’m only reporting this because sort of as an update, it’s not anything you need to take care of. But they did patch an issue with their system. Basically, it was sending a text message saying, if you’ve saw that they have an application on our website, you can happen, have them text you the link to the application. And link could have been compromised and sent a different link redirecting you to a malicious website. With that being said, if you ever want to download an app for anything, do it from the Google Play Store or from the Apple Store, don’t click on links and don’t download it from anywhere else. And we have a Google released a security update for Chrome you should be on at 1.0 point 404 4.138. That’s across the board. And finally Cisco released security updates for a bunch of products. That was just reported. Yesterday. So if you’re using Cisco products, check out their Cisco Cisco security advisories page and see if you need to update any of them. All right, we got lots of news to share this week. First up earlier this week on Forbes Trump declared national emergency as foreign hackers threaten us power grid. Combine that with another article that I saw a few days later that I don’t think I’m sharing today where a, an energy company in Canada was hit with a ransomware attack. So President Trump has signed an executive order that declares foreign cybersecurity threats to the US electricity system, a national emergency. We’ve known for a little while now that electric grid is a target. So President Trump signed an executive order may 1 to further secure the US bulk power system from foreign adversaries that he wrote are increasingly creating exploiting opportunities. The Executive Order declaring a national emergency over the hacking threat bans the acquisition, importation transfer or installation of bulk power system electricity equipment from companies under foreign adversary control. Executive Order also confirmed that the task force has been established with members including the Secretary of Defense Secretary of Homeland Security and the director of national intelligence to work to protect against national security threats to energy infrastructure, with the sort of did not do is go as far as naming any specific foreign adversaries and other companies. They may control so they left it a little vague on purpose, I’m sure. However, President Trump did state the acquisition or use of bulk power system or choosing equipment designed, developed, manufactured or supplied, subject to the jurisdiction of these unnamed foreign adversaries as to their ability to create an exploit vulnerabilities with potentially catastrophic effects. Acknowledging that an open investment, climate needs to be maintained for the growth of the economy, President Trump note wrote that this openness has to be balanced with the requirement to protect against a critical national security threat. Then Director of National Intelligence Dan arcos, published a ward worldwide threat assessment in January 2019. That warned of cyber attack capabilities both China and Russia when it came to the US electricity grid. That report stated that Russia has the ability to execute a cyber attack in the United States that generates localized temporary disruptive effects on critical infrastructure. The FBI and the Department of Homeland Security released an alert in 2018 warning of Russian government actions targeting among others the energy infrastructure sector in the US. US Secretary of Energy Dan relay, who will lead the newly established Task Force said it is imperative the bulk power system be secured against exploitation and tax by foreign threats. this executive order will greatly diminish the ability of foreign adversaries to target our critical electric infrastructure. The Department of Energy established the Office of cyber security, energy, security and emergency response in February of 2018 to approve energy, infrastructure security, including Preparedness and Response against cyberattacks. So there you have it. bleeping computer report GoDaddy notifies users are breached hosting accounts to secured an October 19 of 2018 and was discovered on April 23. I did see somewhere a number of accounts and don’t don’t believe it’s in this article. But it wasn’t attend. Oh, here it is approximate 28,000 accounts. They identified an SS de identified SSH usernames and passwords that were compromised through an altered SSH file in the hosting environment. This apparently only impacted hosting and nothing else. So if you are hosting on GoDaddy you should have received he received a notification at this point, an email or a letter saying that your account may have been compromised and enforced password changes. Citizen HIPAA right of access study shows significant improvement in compliance. So this was good news I wanted to share it. There has been a significant improvement in compliance with the HIPAA right of access. According to the latest patient records scorecard report from citizen to propel the report citizen conducted a study of 820 healthcare providers to assess how well each responded to patient requests for copies of their healthcare date. Data and wide range of healthcare providers were assessed for the study from single physician practices to large integrated healthcare delivery services or systems. So this is a so the HIPAA right of access rule is this you asked for your medical records to bring them to another doctor or just because you want Whatever it may be, they’re supposed to give them to you within a reasonable amount of time, which is 30 days or less. And you’re supposed to give it to for no less demand supposed to charge more than the cost of actually creating that record, which is usually a few dollars. They have a rating system for this, they’ve been doing this for a little while, I guess. They have a rating system of one to five stars, one being the worst and five being, you know, your name goes up in lights. The good news is that there was an increase of so there’s the latest study saw the percentage of one stars fall to 27% from 51%. That’s those that were not compliant. percentage of providers awarded four stars rose from 40 to 67%. And those with five stars rose from 20 to 28%. So that is good news, because we did see a few and they actually believed that this was because of the enforcement initiative on right of access, by the way by the OCR. And we did see a couple of penalties last year and we saw a few breach notifications for it as well. So maybe people are taking a little bit more seriously, let’s hope. On tech Republic, nearly 2000 malicious COVID-19 themed domains created every day. More than 86,600 new domains related to pandemic are considered risky or malicious according to a new report. And there was 1.2 million newly registered domain names containing words related to the COVID-19 pandemic from March 9 through April 26. And they believe that almost 87,000 of those are malicious in nature. And I’m just looking for the actual numbers here. Man, I’m not looking I’m not seeing what I’m looking for. So anyway, there’s 2000 rough almost 2000 domains registered every day related to COVID-19 that they believe will be malicious in nature, meaning it could be phishing sites or carry malware. And believe they believe that most of them will be crypto mining sites, but some of them will be fishing for sure. You know, they’ll say, Hey, we have a, we have masks, we have we have peepee, or we have a vaccine or we have a cure or whatever it might be, none of those things will be true. They will steal information and run with it and probably use it in another attack later on. And so that is the goal and there was some registered around zoom done. This article doesn’t cover the zoom ones. But that did occur when zoom was having all their problems. And it’s they’re still being used. And this is why you need to have DNS filtering in your environment because DNS good DNS filtering will take care of any newly registered domains. So they will not cause an issue with your business. Zd net us Financial Industry Regulatory warns of widespread phishing campaign. This is FINRA making a warning or issuing a warning I should say the US Financial Industry Regulatory Authority, also known as FINRA, probably more commonly known as FEMA. FINRA has issued a rare cybersecurity alert today warning member organizations have a widespread ongoing phishing campaign. FINRA said the malicious emails were aimed at stealing Microsoft Office and SharePoint account passwords. From its member organizations, FINRA, which is private industry group that works as a self regulatory body for brokerage firms and exchange Marcus said the campaign is still ongoing. According to the security alert, phishing emails were sent using a domain of app broker finra.org so you could see where someone might fall for that and made to look like they were sent by Bill woman or Josh drove Nick to FINRA as vice president presidents. FINRA said the phishing emails included the ads PDF, I’m sorry and attach a PDF file that contains a leak link redirecting users to a website prompting members to enter the respective Microsoft Office or SharePoint passwords. So this goes to a point where I’ve said before, don’t open attach attachments that you didn’t expect. Don’t click on links you didn’t expect, if in doubt with links and type them in manually and if and if in doubt about an attachment make a phone call and see if it really came from where it came from. bleeping computer SAP analysis security issues in cloud based products German software maker SAP announced on Monday that has started to fix security issues identified in several of its cloud based products. The company discovered the problems following an internal review and has already started working on eliminating the vulnerabilities. details about the security flaws have been have not been disclosed in an advisory This week the company says that fixing a post will largely be completed in the second quarter of 2020. The list of affected products includes sa p success, faster success factors. Sa p concur sa p callate. Is cloud Commission’s sa p Caldas cloud si p q as well as sa PC for si Sales Cloud sa p cloud platform in SAP analytics cloud. Some of these platforms along with their infrastructure were acquired over the years and company paid billions of US dollars for them. With this SAP inherited all the potential gaps and had to align them to the company’s present contractually agreed or statutory. IT security I’m sorry that should be contractually agreed on statutory IT security standards. It is estimated that around 9% of SAP is 440,000 customers are impacted by the vulnerabilities. They will be notified of the risk and will receive assistance to remedy the problems. Sa Pease investigation is not complete but the company does not believe that customer data has been compromised as a result of these issues. And then effort to ensure that the effective products meet relevant terms and conditions. And in addition to technical, cold remediation, SAP has decided to update its security related terms and conditions. These remain in line with the market peers. The security updates are not expected to have an impact on the company’s financial outlook for 2020. So I guess that’s good news for SAP. So roughly 440 thousand companies are impacted by this. So they will reach out to you and help you resolve it. So that’s that’s a step in the right direction, in my opinion, and here it is, I mentioned it earlier. cyber attack on NTPC further exposes the cybersecurity risks of energy sector so Northwest Territory is Power Corporation. A generator and distributor of electricity in Canada was hit with a ransomware attack. The ransomware attack hit NTPC shutting down its IT systems and impacting the power generation, transmission and distribution systems are company, my NTPC the online payment portal used by NTPC was not working properly and leading the customers to a message saying that the files were encrypted by networker, although not confirm for this case, but the spread of networker ransomware aka mail two is usually associated with the COVID-19 themed phishing phishing emails as observed during its previous attacks. And so here’s some of the previous attacks or the here’s, here’s actually information about an earlier data breach with NTPC. In January 2016 NTPC informed its customers that it had wrongly sent some personal details of its customers to third party, resulting in breach of personal data file containing a list of customer names, meter addresses, and balance account balances was sent out to some customers while responding to some customer inquiries. Other attacks on energy sectors and April 2020, the Portuguese multinational energy giant energy SMD portrait Goal UDP, was hit with Ragnar locker ransomware, where no hackers stole 10 terabytes of sensitive company files and asked for 1500 and 80 Bitcoin which is roughly $10.9 million. In March 2020, the European electricity association was targeted by cyber intrusion incident, although no further details about the incident were disclosed. In February 2020 of the reading municipal light department, our mld was targeted by cyber criminals in an attempt to extort money by encrypting data in an ancient in the station’s computer system. In January 2020, a hacking campaign by Iranian hackers was observed targeting the European energy sector, in which the attackers tried to steal sensitive information using the pupae rat malware. Other attackers by networker in other attacks by networker sorry, in March 2020 network or ransomware was observed using Coronavirus themed phishing emails to target its victims in the same month. Just ransomware was also used to target The Champaign Urbana Public Health District and in February 2020, the Australian toll group admitted that they were targeted by network a ransomware. The toll group by the way, Australian toll group was hit with another attack within the last couple of days. So not not a good year for them. Cognizant we have an update on Cognizant you may remember Cognizant is an MS MSP. So similar type businesses me as my business, except that they make quite a bit more money than I do. And we’ll get to that in a moment. They are. I believe they’re the largest the world’s largest MSP, but I could be wrong, but Cognizant believes it has contained in Mays ransomware attack that hit the MSP in IT consulting firm in late April 2020. According to the first quarter earnings statement, released May 7 still yesterday. In their statement, Congress has said the company believes it has contained the attack and that the actor is no longer operating in the company’s environs. Since becoming aware of the attack, the company has taken decisive actions to remediate the threat while keeping clients regularly informed. The company believes these measures enabled it to continue its operations in a timely, secure manner. In addition, the company has and will continue to take any necessary steps to protect the integrity of its systems. Cognitive provably previously disclosed at the attack may impact company revenues. More details about the attack and remediation are expected to surface on cognisance earnings call for quarter 120 20. Cognizant says revenue was 4.2 billion up 2.8% from a year ago quarter, including a negative 50 basis points impact from the exit of certain content services businesses and a net income was 367 million compared to 441 million a year ago. Now that being said, mes doesn’t just hit you with a ransomware attack. There’s still data. They have not said if that has happened here in Mesa has not released any data. So that tells me one of two things Mays is not done yet. Or Cognizant may have paid some money. But I’m sure we’ll learn more as the day’s progress here. So when there’s another update on Cognizant, I will share and last bit of news before we move on to our hot topics. Critical WordPress plugin bug lets hackers take over 1 million sites. That doesn’t mean they have it means it’s possible. So Elementor Pro and ultimate add ons for Elementor. WordPress plugins have critical vulnerabilities that Elementor Pro has released release patches for so if you are using those in your on your WordPress website, you should be updating Elementor Pro to version 2.9. point four immediately. There’s vulnerabilities that are being attacked as we speak. ways you can check to make sure that your site hasn’t already have been compromised check for any unknown subscriber level users on your site this may indicate that your site has been compromised as part of this Active Campaign. If so, remove those accounts. Check for files named WP dash XML or PC dot php these can be considered an indication of compromised, so check your site for evidence of this file and delete any unknown files or folders found in WP content slash uploads slash element or slash custom dash icon slash directory files located here after a rogue subscriber level account has been created our clear indication of compromise. So again, that is almost 1 million. I think it’s actually a little more than 1 million sites that are using Elementor Pro and another hundred and 10,000 sites using ultimate add ons for Elementor. So if you’re using those, get them updated immediately. Let’s talk some numbers because this if you know, not gonna lie, I try to scare you guys. I try to scare business owners, because they need to be scared. I don’t do it because I want you to purchase on fear I do it because you need to be educated you need to understand the risks that are out there. So if you’re not willing to consider the risk of, you know, you being breached your client information being stolen or whatever else, maybe you’d be concerned about this risk. consumers will opt for competitors after a single ransomware related service disruption. While most consumers are taking necessary security precautions to protect their online accounts. I don’t believe that but if but some of them are. Businesses may not be doing enough to protect their information inadvertently driving sales to competitors that can that can an ark serve research reveals and I found this on help. NET security calm by the way 7% will switch to a competitor. If your systems and applications are back online within 24 hours. 41% will walk away if they still can’t access systems and applications within two to three days. They serve a survey of nearly 2000 consumers across North America, the United Kingdom, France and Germany found that 70% believe businesses are not doing enough to adequately secure their personal information and assume it has been compromised without them knowing it. And as consumers become more educated and cyberattacks become well known, perceived trust becomes more influential and a purchasing decisions, with the study also finding that nearly nine out of 10 consumers consider the trustworthiness of a business prior to purchasing a product or service and 59% of consumers would likely avoid doing business with an organization that had experienced a cyberattack in the past year. These findings suggest businesses must manage Uncharted challenges within the use of cyber criminals, or I’m sorry within the rise of cyber criminals. Now making breaches public regardless ransom pay. So again, we’re talking about me’s and the apple painter. I think Raju and a few others are clop are now publishing the data that they steal if you don’t pay up ransomware related service disruption consumer tolerance thresholds, cyberattacks, have arguably become the largest business threat. However, the quantifiable impact on consumer behavior has not been widely understood. The study found that one in four consumers will abandon a product or service in favor of a competitor after a single ransomware related service disruption, failed transaction or instance of an inaccessible information. It also found that tolerance for these events quickly deteriorates with over 66% of respondents setting that they would turn to a competitor. If an organization couldn’t restore systems and applications within three days following a cyber attack. And over a third of those would be willing to switch after a mere 24 hours of waiting to access their information or make a transaction Moreover, the potential damage doesn’t stop during a shortly during or shortly thereafter a cyber attack. More than eight and 10. respondents admit to sharing their negative ransomware related experiences with family friends or colleagues posting about their experiences online or medium and lying about the incidents. Note these attacks are usually very well publicized. So you have to think about that perspective as well. certain industries fared better than others. While the report concludes their debt consumers are generally intolerant of cyberattacks. There are a few industries where businesses are under even more pressure to keep data secure and operations running. The survey found that nearly half of consumers would walk away from their banking or security provider immediately upon experiencing ransomware related event which would which prohibited them from transacting or accessing information and 43% would immediately seek out a competitive communication product or service and I can’t say I blame them. While there are many negative ramifications caused by cyber attacks, businesses that take protective or I’m sorry, proactive steps in many To get ransomware quickly will benefit in the long run. Over half of the respondents would be willing to pay more for products and services they believe to be more reliable and secure in the banking and securities industry in over 40% would pay more if they believe products and services were more secure from companies in the healthcare insurance and retail categories. So all of you, businesses, these are all almost all of them. compliant type businesses that say you can’t afford cybersecurity because it’s too much money. Well think about that over half of the respondents would be willing to pay more for products and services they believe to be more reliable and secure in the banking and securities industry, and over 40% would pay more if they believe products and services were more secure from companies in the health care insurance and retail categories. Consumers are clearly already hesitant about working with companies hit by cyberattacks, and it just won’t tolerate disruption as businesses figure out recovery and remediation plans after the fact. The findings represent a stark warning for organizations given that one in four of their customers will be gone immediately upon disruption with many more losing patients within 48 hours, and the numbers are there, the ransomware attacks take in many cases take more than 48 hours to recover from. businesses must do more to ensure they’re protecting your data from cyber criminals and mitigating the chance. They’ll experience extended downtime, we recommend a two pronged approach where cyber security backup and disaster recovery are deeply intertwined. So if the thought of your clients data being stolen, or the thought of your business coming to its knees, or you know, I don’t know why business owners wouldn’t already be concerned and we’re going to go over another article in a moment that shows that some businesses are not concerned that maybe this is another one you get hit, you’re going to lose reputation immediately and I’m going to look up the hit that target took after they were their credit card information was stolen a few years ago. Just to give you an idea, but before we do that, patients notified medical records expose that tornado hit secure medical record facility. So I’m going to go through this first and then I’m going to explain why I’m bringing this up. Several healthcare providers have been affected by an unusual data breach at wapa. Wisconsin base stat information informatics solutions LLC. stat provides secure medical records services to several health care providers, which includes scanning paper files so they can be added to hospital medical record systems. On March 3, a staff facility in Lebanon, Tennessee was hit by a tornado, which caused extensive damage to the building and some of the records stored in a facility that notified all affected clients the same day, and representatives of those health care providers visited the site to assist with locating and securing medical records in the facility. to limit the potential for unauthorized access. A tall fence was erected At around the building while the medical records were located and secured to security guards were also posted on the site 24 seven to prevent unauthorized individuals from accessing the building. The majority of the medical records were found in the remnants of the building, but the records were determined to be unsalvageable, and have now been securely destroyed. While it is possible that to an authorized individuals, that unauthorized individuals may have viewed some paperwork relating to patients, no evidence has been uncovered to suggest that this was the case and patients are not believed to be at risk of financial harm. Out of the abundance of caution patients whose records were stored in a building are being notified by mail and will be offered complimentary credit monitoring services. The medical records at the facility contain the following types of information, full names, social security numbers, addresses, dates of birth, medical record numbers, account numbers, medical images, diagnosis, nursing and physician documentation, test results, medications and other types of information typically found in medical records. And so here’s the of the health care providers who were impacted by this Bayfront health in Port Charlotte, Florida, Bayfront health and Buta gorda, Florida. Commonwealth health Wilkes Barre General Hospital, Pennsylvania, Commonwealth health, Moses Taylor Hospital in Pennsylvania and Poplar Bluff Regional Medical Center in Missouri. Now, why did I bring this up? This illustrates a very important point. Your security risk analysis is supposed to go through every risk that is believed to be in existence for your practice for your metal for your covered entity or business associate, associate, whatever it might be. Tennessee is in an area where they do get tornadoes. So tornado is a very real risk. I’d be willing to bet that this business stat did not do a security risk analysis that included tornado potential for tornadoes. So in other words, if you live in an area where you’re you’re constantly under hurricane threats so Florida, South Florida, then you should include that in your security risk in house. If you live in the northeast where blizzards are very real threat, you should include that in your security risk analysis. If you live in an a coastal area where water is an issue, you should you should include really you should include flooding, whenever you have a covered entity or business associate, but that needs to be in your security risk analysis. The security risk analysis should take every possible risk, analyze it and prepare your healthcare practice or business associate for that risk. It’s not meant to be a checklist. It’s not meant to say okay, well, we are we have anti malware software in our computers. So we’re secure. That’s not what it’s meant to be. And that is part of it. You know, that’s, that’s part of your security risk analysis. And every every healthcare practice should have that. You should, you should make sure that your systems are secure from breach and from malware and from ransomware, and all that stuff, you know, and that includes data backups and all that. But this I’m sure that could have done more to prevent something like this from happening, it is tragic. And I’m sure that the numbers will show that the chances of that building getting hit by a tornado were pretty small, but it’s still a possibility and it’s still something that needs to be looked at when you run your security risk analysis at least once a year. So that’s the point of me sharing it is it’s a rare HIPAA breach, but it’s still a HIPAA breach and it still could happen. You know, we’ve we’ve, with Florida you get hurricanes all the time. And they do say that 20 is going to be an act of hurricane season in a way this year is going to wouldn’t shock me the least bit. So, that’s something to think about if you have a healthcare practice and that could be anything, it could be a dentist, the chiropractor, a physician, an optometrist, any hip any business that that falls under the HIPAA umbrella needs to run a security risk analysis and say, okay, we could get hit with a hurricane. Are we prepared for that? And what do we need to do to prepare for that better? So that is, that was the whole point of me sharing that. And plus, it’s one less HIPAA breach I need to report later on in this podcast. And we’re going to go back to the we’re not going back to the article, but we’re going to go back to that topic. So I found this some dark reading. It’s a real short read. Dark reading.com half of companies have suffered a cyber security issue a mid COVID-19 crisis. survey shows 49% expect to experience a data breach or cybersecurity incident in the next month. But it gets scarier than that. Social Justice, social justice sensing and working from home may be helping to stem the tide of the COVID-19 pandemic but they aren’t doing much good for enterprise cybersecurity. According to the results of new study, nearly half, which is 46% of global businesses have encountered at least one. cybersecurity scare since shifting to remote working model, and 49% of the survey respondents anticipate suffering and data breach or security incident in the next month as a result of moving employees to work from home. The study conducted by Barracuda found that an increase in perceived risk has not been accompanied by an increase in security spending. So that’s where it gets scary. So you saw that you getting hit with a ransomware attack which will directly impact your bottom line and your reputation. And then you see this where it says some 40% of companies surveyed said their response to COVID-19 as included cutting their cybersecurity budget in 50% said they would consider cutting staff. If cybersecurity could be maintained. Cutting, they cut it. They didn’t. They didn’t just they didn’t just say, Alright, we need to make sure we’re still doing the same thing. They cut it. And the problem with that is, you now have this population of employees that are working from home. And they are not cybersecurity aware. And that is opening up a whole new wormhole for your business. I’ve worked with a number of employers, businesses over the last now eight weeks to help secure it and I got to tell you some of the things I’ve seen from municipalities from small businesses from healthcare practices from law firms, it’s unreal, and you know that a lot of them are BYOD. So you’re working from home now you need to use your own device. to remote back into the office, they’ll set up Remote Desktop with no security at all use very simple password. They will make sure that you can still access your email but they’re not securing that you don’t turn on multi factor authentication. They’re not educating their people in phishing. They’re not doing anything to secure the business and secure in many cases secure client files and not spending on it is not the answer. That is the opposite of the answer. So I thought it was scary that you know 40% said they are they are cutting spending on cybersecurity during COVID-19. Hopefully that is not a trend going forward. But COVID-19 might be here for a little while. So who knows? All right, we’re gonna continue on our hip education. With a review of the technical Volume One cybersecurity practice for small healthcare organizations that was part of the 405 D project. And as the I never remember what h ICP stands for, but it’s it’s h ICP, also known as hiccup. That is part of the part of the it’s a plan to make sure that healthcare practices are more cyber secure. So we’re going to talk about today cybersecurity practice number four data protection and loss prevention. Let’s start with and again this is all this is all based off of the NIST cybersecurity framework. So that means if you’re familiar with the NIST cybersecurity framework, none of this should come as a surprise to you. But and apparently it does, because I see him care practices across the board USING IT support or other business associates what’s supposed to be business associates support, that are not familiar with this and are not using best practices. So let’s jump in here set the expectation for how your workforce is expected to manage the sensitive data at their fingertips. Most healthcare employees work with sensitive data on a daily basis very true. So it is easy to forget how important it is to remain vigilant about data protection. organizational policies should address all user interactions with sensitive data and reinforce the consequences of lost or compromised data. And so we just talked or we will talk about sorry about employees getting fired for viewing data that they shouldn’t be viewing towards it. A couple of those this week. Establish a data classification policy that categories data as for Israel, sample, sensitive internal use or public use identify the types of records relevant to each category. For example, this sensitive data category should include pH I social security numbers. And if you don’t know what pH is, its protected health information. credit card numbers and other information that must comply with regulations may be used to commit fraud, or may damage the organization’s reputation. And credit card numbers also fall into PCI By the way, so you need you need to look at both of those. So we have classification highly sensitive data that can be easily used to commit financial fraud or to cause significant damage to the organization’s reputation. Examples of such data for patients include social security numbers, credit card numbers, mental health information, substance abuse information and sexually transmitted infection information. access to these data should be restricted to users who require it and who demonstrate proper identification at login. Such data must be managed in compliance with applicable regulatory requirements. Sensitive All other pH I, especially data associated with the designated records, clinical research data, insurance information, human employee data, and organizational board materials. internal data that should be protected yet are not considered sensitive. Examples include organization policies and procedures, contracts, business plans, corporate strategy, and business development plans, internal business communications and in public all data that can be sanitized and approved for distribution to the public, with no restriction on use, prohibit the use of unencrypted storage such as thumb drives, mobile phones or computers require encryption of these mobile storage mediums before everything should be encrypted, not just mobile. Because there have been a few cases in the last few months of servers walking away and desktops walking away all these things walking away. The document references The different NIST framework as well when it comes to the different practices in this document, and we have use of classifications to establish data usage procedures identify, identify authorized users of sensitive data and the circumstances under which such data may be disclosed. So in other words, identify who’s allowed to access it and make sure they’re the only ones accessing it. Train your workforce to comply with organizational procedures and OMC guidance. When transmitting pH I through email, encrypt all pH I sent via email or text, however, patients can request and receive access to their HIV unencrypted electronic communication following a brief warning to the patient that unencrypted communication could be accessed by a third party in transit. And the patient confirms that they will still want to receive an unencrypted communication. So in other words, if you’re going to send an email, and that person is asking you to send it to their free gmail account or free Pop your email account there for let’s say Comcast since we’re talking about them earlier, you need to warn them of the risks because Comcast does not encrypt their email. When emailing pH I use a secure messaging application such as direct secure messaging, which is nationally adopted secure email protocol and network for transmitting pH I DSM can be obtained from EHR vendors and other health information exchange systems. It was developed and adopted through Meaningful Use program and many medical organizations nationwide. Now use DSM networks when you texting pH, I use a secure texting system. And there are quite a few secure test texting systems. But I would, to the point here use the one that your EHR provides if you’re going to use anything, not just a texting system, implement data loss prevention technologies to mitigate the risk of unauthorized access to pH I check with your IT provider to determine if this is feasible for your organization, or reference cybersecurity, practice number four Data Protection and prevention. So data loss prevention is having a disaster recovery, business continuity, disaster recovery system set up. And so the way we do it is we set it up where you have a local backup and then you have an off site backup done through the cloud. And if something goes down, you’re able to get back up virtually within minutes. train staff never to back up. data on control uncontrolled storage devices on Personal Cloud or Personal Cloud services. For example, do not permit employees to configure any workplace mobile device to backup to a personal computer unless the computer has been configured to comply with your organization’s encryption and data security standards. I saw this once where they employee installed their personal Dropbox account on the work computer. I don’t know how they how they were allowed to do that. And why would that wasn’t preventable, but they did and a place picked up on a security scan and the employee they didn’t I don’t know if there were ever recommend, I don’t know what the HR outcome was, but obviously, the Dropbox account was removed. And when they did find stuff in the Dropbox account that shouldn’t have been there. Not only that, but the employee had information in the Dropbox account that he probably did not want anybody else to see. Remember to protect archived data such as records for previous patients to to to it is important to monitor access to the data which may be used infrequently so that cyber attack is detected immediately ensure the absolute absolute absolute data removed or destroyed properly so they cannot be accessed by cyber thieves. Just as paper medical and financial records must be fully destroyed by shredding or burning. digital data must be properly disposed of to ensure that it cannot be inappropriately discovered, recovered sorry. Discuss options for properly disposing of outdated or unneeded data with your IT support. Do not assume that deleting or erasing files means the data are destroyed. And if not, by the way, it’s easily recoverable. Retain and maintain only data that your organization requires to complete work comply with record storage requirements minimize your organization’s risk by regularly removing unnecessary data. And so what are the threats mitigated by this ransomware loss of depth or equipment or data and accidental or unintentional data loss? So, data protection and that is a big part of HIPAA. Not just HIPAA, but healthcare in general healthcare IT protecting your patients information, your clients, those are your clients to protect their information. Right, it’s time for the HIPAA breach report. We have quite a bit of breach news not necessarily breaches but news to share shareholder suicide Last quarter to recover losses caused by data breaches a lab Corp shareholders taking legal action against labcorp. And its executives and directors over the loss in share value that was caused by two cyber attacks experienced by the company in the past 12 months. So you may recall those breaches from last year where labcorp was breached 10,251,784 patients and in companies like quest were were part of that. And so a lot of you know, obviously it was a big breach. labcorp was one of the companies worst affected by data breach at the medical debt collection company, American Medical medical collection agency AMC, so that was also quest was also part of that. They use labcorp services to infiltrate MCA systems and at least 24 of the MCs clients were affected by the breach a second labcorp data breach was reported by TechCrunch In January of this year that involved around 10,000 labcorp documents, which the lawsuit alleges was not publicly disclosed by the company nor mentioned in any SEC filings. The breach was the result of a website mis configuration and allowed the documents to be accessed by anyone. The breach was also not reported to the HHS Office of Civil Rights. Even though TechCrunch researchers confirm that the documents contain patient data. Ramin Eugenio holds shares in labcorp, which lost value as a result of the data breaches and filed a lawsuit on April 23. To recover those and other losses. The lawsuit names labcorp as the defendant along with 12 of the company’s executives and directors, including labcorp CIO Landsberg, Varian, CFO, Glen Eisenberg and actor I’m sorry director Adam shuck Schecter. The lawsuit alleges that prior to the AMC a breach and subsequently labcorp failed to implement appropriate cybersecurity procedures and did not have sufficient oversight of cybersecurity which directly resulted in the two data breaches in an S sec filing labcorp explained the AMC a data breach it costs the company $11.5 million in 2019 in response and remediation costs, but the lawsuit points out that the figure is just a fraction of the total losses and does not cover the costs of litigation default. Several class action lawsuits have been filed by victims of the AMC a data breach that name labcorp. So the total losses are not known to its shareholders and it probably won’t be known for years. Also lawsuit also states that the second breach has not been acknowledged, publicly or in any SEC filings as such Eugenio alleges lab corpse failed in its responsibility to its shareholders and breached its duties of loyalty care and good faith. The lawsuit alleges labcorp failed to implement effective internal policies, procedures and controls to protect patient information. There was insufficient oversight of compliance with federal and state regulations and its internal policies and procedures. labcorp did not have a sufficient data breach response plan in place pH I was provided to MCA without ensuring the company had sufficient cyber security controls in place. labcorp did not ensure that the individuals and entities affected by the breach were noticed, notified in a timely manner, and that the company did not make adequate public disclosures about the data breaches. The lawsuit seeks reimbursement for damages sustained as a result of the breaches and public acknowledgement of the January 2020. data breach. The lawsuit also calls for a reform of corporate governance and internal procedures and requires a board level committee to be set up for an an executive office or position appointed to ensure adequate oversight of data security. So we’ve talked about the hidden costs of of HIPAA breaches before obviously, this was a very large data breach last year, large HIPAA breach last year, but these are the hidden costs. So, you know, OCR hasn’t even I don’t know where they are in the investigation of this breach, and I’m sure there will be something type of settlement when all of a sudden done but did lawsuits and everything else that’s going to come from this are going to be probably far worse than the actual HIPAA breach. settlement. bjc healthcare has announced the email counts of three of its employees had been accessed by an unauthorized individual after the employees responded to phishing emails suspicious activity was detected in the email accounts on March 6, and accounts were immediately secured. A leading computer forensics firm was engaged to conduct an investigation which revealed the three accounts and only been accessed for a limited period of time on March 6, it was not possible to tell if the patient data was viewed or obtained by the attacker. review of the accounts revealed did contain the data of patients at 19, bjc and affiliated hospitals protected health information in emails and attachments vary from patient to patient and may have included the following data elements, patient names, medical record numbers, patient account numbers, dates of birth, limited treatment and or clinical information. which included provider names visit dates, medications diagnosis, testing information, the health insurance information, social security numbers, driver’s license numbers of certain patients were also potentially compromised. All patients affected by the breach will be notified by mail when the email account review is completed. So they did notify and exactly 60 days so good for them. However, three email breaches means no MFA, no training is occurring on a routine basis at bjc. And there is a list of 19 facilities here. Alton Memorial Hospital Barnes Jewish hospital, Barnes Jewish St. Peter’s hospital Barnes Jewish West County Hospital bjc behavioral health PGC in corporate health services bjc homecare bjc Medical Group boom Medical Group Poon Hospital Center, Christian hospital Memorial Hospital Daleville Memorial Hospital East Missouri Baptist Medical Center Missouri Baptist physician services LLC Missouri Baptist Solomon hospital, Parkland health center Boone tear Parkland Health Center at Farmington progress West hospital and Louis Children’s Hospital. Patients notified medical records expose this tornado hit secure medical record facility. We already talked about that. But again, just to review if you when you run your your security risk analysis, you need to consider all potential loss not just things that are common, like theft, but anything that could occur. And and Robert H Lurie Children’s Hospital of Chicago has terminated employee for improperly accessing the medical records of patients without authorization over a period of 15 months. The privacy violations were identified by the hospital on March 5. Employees access to hospital systems was immediately terminated while the investigation was conducted. After reviewing access logs, the hospital found that the employee had access to medical records of 4824 patients without authorization between November 2018 and February 2022. types of information access by the employee including names addresses, dates of birth diagnosis, information, medications, appointments, medical procedures no health insurance information, financial information or social security numbers where access. No reason was given as to why the medical records were access but the hospital says it does not believe the employee obtain misused or disclosing information to anyone else. hospital setting the employee no longer works at the hospital. This is not the first incident of its type to occur at Lurie Children’s Hospital. A similar incident was discovered in November 2018 when the hospital learned that a former employee access to medical records of patients without authorization between September 2018 and September 2019. So it sounds like they have an issue with access controls which we talked about in last week’s podcast so you know, mercy health and we talked about that breach earlier. Last when did it occur in March so we did talk about it a couple months ago. Mercy health fires nurse for multiple privacy violations. This one’s interesting mercy health has also recently taken action against an employee for alleged violations of HIPAA Privacy Rule. A nurse at hackley Hospital in Muskegon, Michigan was terminated on April 3 determination came shortly after the nurse raise concerns in media interviews about the level of preparedness of the hospital for the COVID-19 pandemic, and how the alleged lack of preparedness but put safety at risk. The nurse contacted the Michigan Nurses Association, labor union, which claimed at Mercy Mercy health fire the nurse for speaking out the labor union also filed a charge with the National Labor Relations Board. House termination came on the evening of April 3 days after he had publicly raised concerns about lack of appropriate PCP and the need for improved screening measures to keep nurses and healthcare workers safe during the COVID-19 pandemic. So the labor union in April 21 press release 10 days after the nurse was fired in one day after the press release was issued by the labor union. Mercy health released a press release of its own stating the nurse was fired for multiple violations of HIPAA rules. Mercy health said it does not usually share details about employment matters related to its workers but what’s compelling To speak out due to the misinformation campaign led by the labor union. Mercy health claims the fire nurse Justin Howe was terminated for accessing the medical records of multiple patients over a period of several days. The records were not were were not for patients receiving treatment at campus where the nurse worked and there was no legitimate work reason for accessing those records. Mercy health claims that how was not the only nurse terminated for improper medical record access according to mercy health press release. We have mechanisms in place to monitor for inappropriate access of privileged information. As part of this review process, Mr. Howe, along with the others were terminated for the same just investigative effort is still in process. So kind of interesting case. We’ll wait to see what comes with that. And then we have three more breaches that were reported early this morning. St. Francis healthcare partners in Connecticut is notifying 38,529 patients that some of their protected health information has potentially been obtained by hackers as a result of so instigated cybersecurity incident that allowed an unauthorized individual to gain access to its email system. The attack occurred on December 30, but it took until March 20. Further forensic investigation to determine that patient’s protected health information was potentially compromised. The types of information stored in the email system that could have been accessed included names, medical histories, medical record numbers, clinical and treatment information, dates of service diagnosis, health insurance or health insurance. provider names and count numbers prescription information in all types of procedures performed, no financial information or social security numbers were compromised. The investigation uncovered no evidence to suggest patient information was accessed stolen or misused. steps have now been taken to improve data security practices and all affected patients were have been notified by mail. There’s a few failures here one, obviously with this took more than 60 days to notify. Make your breach notification to sophistication it’s not a thing. phishing attacks are not so sophisticated. If you set up multi factor authentication, and you train your employees, then it’s not a sophisticated attack it can’t happen. The the the statement here is that a sophisticated cyber security incident that allowed an unauthorized individual to gain access to its email system tells me that somebody was fished. Florida internal medicine practice suffers ransomware attack Daniel Ben. Ben data what’s Md ffensive pa is notifying 3314 patients that the protected health information has been exposed as a result of a ransomware attack. The attack occurred on March 25 2020, resulting in the encryption of its computer systems including patient records backup files were not affected so files could be recovered without paying the ransom. And these types of ransomware attacks. files are not typically accessed by the attackers prior to file encryption. However, data access cannot be ruled out. So notification letters have been sent effective paid to affect a patient’s doctor Then debits explained in a breach notification letters that names addresses dates of birth, social security numbers, health insurance, information and medical information were potentially compromised. Either the abundance of caution identity theft protection services have been offered to all affected patients. steps have also been taken to improve security to prevent further attacks in in the future. So here’s a here’s the here’s the thing with this one. They say that in these types of ransomware attacks, files are not typically accessed That is incorrect. And that is a very poor assessment. Very poor statement. Because as we’ve seen multiple times now in the last few months, they’re stealing the files before they encrypt you. They’re spending time to peruse your network, so to speak in encrypting your files. Houston Methodist Hospital is notifying 1987 heart patients that some of their protected health information was stored on portable storage devices that were stolen from vehicle a vendor representative in mid February. The individual was employed by the medical device manufacturer and operated to 3d imaging technology in the hospitals cardiac cath third is Catherine ization lab. The hard drives were left in a vehicle from where they were stolen. The hospital reports that the room where the hard drives were stored, was locked in removal of the devices was against hospital protocol and violated established technical safeguards and contractual obligations. The representative believed the room was only locked due to the lead hour of the day. The hard drives contain medical images that included a patient’s name, gender, date of birth and code number. The images could only be viewed with specialist software that clinic reported the theft to law enforcement and hired a private investigator, but the hard drives could not be located. So means the hard drives were not encrypted. An email an employee of Ascension Eastwood clinic in Southfield Michigan sent an email to patients on April 15th. I’m just explaining the practice was transitioning to telehealth services due to COVID-19 to help prevent the spread of The disease in error was made sending email patients email addresses were not added to the BCC field of the email and could therefore be viewed by other patients. As a result of the error email addresses and in some cases, patients names were disclosed to other patients. Apart from allowing a patient to be identified as a patient of the clinic, no other information was exposed. The HHS Office of Civil Rights breach portal shows 999 patients were affected and that is going to do it for the HIPAA breach roundup and that is going to do it for this podcast. So until next week, stay healthy, stay safe and stay secure. Transcribed by https://otter.ai The post ProactiveIT Ep 28 – The Hidden Costs of Ransomware [https://nwajtech.com/proactiveit-ep-28-the-hidden-costs-of-ransomware/] appeared first on Nwaj Tech - Information Tech & Cloud Support [https://nwajtech.com].

Reacties

0

Wees de eerste die een reactie plaatst

Meld je nu aan en word lid van de ProactiveIT community!

Probeer gratis

Probeer 14 dagen gratis

€ 9,99 / maand na proefperiode. · Elk moment opzegbaar

  • Podcasts die je alleen op Podimo hoort
  • 20 uur luisterboeken / maand
  • Gratis podcasts

Alle afleveringen

30 afleveringen

aflevering ProactiveIT Ep 30 – Breach Statistics for Business & Healthcare artwork

ProactiveIT Ep 30 – Breach Statistics for Business & Healthcare

THIS IS THE PROACTIVEIT PODCAST.  THIS WEEK: THE LATEST IN IT AND CYBER SECURITY NEWS PLUS PAYING RANSOM DEMANDS DOESN’T PAY, BREACH STATISTICS FOR BUSINESS AND HEALTHCARE, AND PREPARING FOR THE NEW NORMAL (WFH) THIS IS EPISODE 30 Intro Hi Everyone and welcome to the Proactive IT Podcast.  Each week we talk about the latest in tech and cyber news, compliance and more.  We also bring you real world examples to learn from so that you can better protect your business and identity. This podcast is brought to you by Nwaj Tech – a client-focused & security-minded IT Consultant located in Central Connecticut.  You can find us at nwajtech.com. Thanks for listening to this podcast.  Show us some love on Apple or Google Podcasts.  Subscribe and leave us some positive feedback.  What are you waiting for? Also, go join the Get HIPAA Compliance Facebook Group.  Search for Get HIPAA Compliance PATCH TUESDAY UPDATE: Unpatched Oracle WebLogic Servers Vulnerable to CVE-2020-2883 [https://www.us-cert.gov/ncas/current-activity/2020/05/01/unpatched-oracle-weblogic-servers-vulnerable-cve-2020-2883]SaltStack Patches Critical Vulnerabilities in Salt [https://www.us-cert.gov/ncas/current-activity/2020/05/01/saltstack-patches-critical-vulnerabilities-salt]Firefox 76 released with integrated data breach alerts [https://www.bleepingcomputer.com/news/software/firefox-76-released-with-integrated-data-breach-alerts/]Microsoft releases May Office updates with fixes for auth issues [https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-may-office-updates-with-fixes-for-auth-issues/]Instacart Patches Security Bug That Would Have Let Attackers Spoof SMS Messages [https://www.darkreading.com/risk/instacart-patches-security-bug-that-would-have-let-attackers-spoof-sms-messages/d/d-id/1337734?&web_view=true]Google Releases Security Updates for Chrome [https://www.us-cert.gov/ncas/current-activity/2020/05/06/google-releases-security-updates-chrome]Cisco Releases Security Updates for Multiple Products [https://www.us-cert.gov/ncas/current-activity/2020/05/07/cisco-releases-security-updates-multiple-products]VMware Publishes Workarounds for Vulnerabilities in vRealize Operations Manager [https://www.us-cert.gov/ncas/current-activity/2020/05/11/vmware-publishes-workarounds-vulnerabilities-vrealize-operations]Adobe Releases Security Updates [https://www.us-cert.gov/ncas/current-activity/2020/05/12/adobe-releases-security-updates]May 2020 Patch Tuesday: Microsoft fixes 111 vulnerabilities, 13 Critical [https://www.bleepingcomputer.com/news/microsoft/may-2020-patch-tuesday-microsoft-fixes-111-vulnerabilities-13-critical/] New Chrome 83 released with massive security and privacy upgrades [https://www.bleepingcomputer.com/news/google/chrome-83-released-with-massive-security-and-privacy-upgrades/]Drupal Releases Security Updates [https://www.us-cert.gov/ncas/current-activity/2020/05/21/drupal-releases-security-updates]Apple Releases Security Update for Xcode [https://www.us-cert.gov/ncas/current-activity/2020/05/21/apple-releases-security-update-xcode]ISC Releases Security Advisory for BIND [https://www.us-cert.gov/ncas/current-activity/2020/05/20/isc-releases-security-advisory-bind]Adobe Releases Security Updates [https://www.us-cert.gov/ncas/current-activity/2020/05/20/adobe-releases-security-updates]VMware Releases Security Update for Cloud Director [https://www.us-cert.gov/ncas/current-activity/2020/05/20/vmware-releases-security-update-cloud-director]Microsoft Releases Security Advisory for Windows DNS Servers [https://www.us-cert.gov/ncas/current-activity/2020/05/20/microsoft-releases-security-advisory-windows-dns-servers] CYBER SECURITY NEWS Paying Ransomware Crooks Doubles Clean-up Costs, Report [https://threatpost.com/paying-ransomware-crooks-doubles-clean-up-costs-report/155767/] Criminal group that hacked law firm threatens to release Trump documents [https://www.nbcnews.com/tech/security/criminal-group-hacked-law-firm-threatens-release-trump-documents-n1208366?&web_view=true] Likely Breach Shuts Down Arkansas Unemployment Program [https://www.securityweek.com/likely-breach-shuts-down-arkansas-unemployment-program?&web_view=true] Security threats associated with shadow IT [https://www.helpnetsecurity.com/2020/05/18/security-shadow-it/?web_view=true] REvil Ransomware found buyer for Trump data, now targeting Madonna [https://www.bleepingcomputer.com/news/security/revil-ransomware-found-buyer-for-trump-data-now-targeting-madonna/] Ransomware attack impacts Texas Department of Transportation [https://www.bleepingcomputer.com/news/security/ransomware-attack-impacts-texas-department-of-transportation/] FBI warns of ProLock ransomware decryptor not working properly [https://www.bleepingcomputer.com/news/security/fbi-warns-of-prolock-ransomware-decryptor-not-working-properly/] Bluetooth Bugs Allow Impersonation Attacks on Legions of Devices [https://threatpost.com/bluetooth-bugs-impersonation-devices/155886/] Ukrainian Police Arrest Hacker Who Tried Selling Billions of Stolen Records [https://thehackernews.com/2020/05/ukrainian-hacker-arrested.html] Vigilante hackers target ‘scammers’ with ransomware, DDoS attacks [https://www.bleepingcomputer.com/news/security/vigilante-hackers-target-scammers-with-ransomware-ddos-attacks/] HOT TOPICS Topic 1: Home office technology will need to evolve in the new work normal [https://www.zdnet.com/article/home-office-technology-will-need-to-evolve-in-the-new-work-normal/] Topic 2: Verizon Data Breach Report: DoS Skyrockets, Espionage Dips [https://threatpost.com/verizon-data-breach-report-dos-skyrockets-espionage-dips/155843/] Topic 3: April 2020 Healthcare Data Breach Report [https://www.hipaajournal.com/april-2020-healthcare-data-breach-report/] HIPAA CORNER: https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf [https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf] BREACHES https://www.hipaajournal.com/category/hipaa-breach-news/ [https://www.hipaajournal.com/category/hipaa-breach-news/] Paying Ransom Demands Doesn’t Pay, Breach Statistics for Business and Healthcare, and Preparing for the New Normal (WFH) IGS [https://nwajtech.com/wp-content/uploads/2020/05/Paying-Ransom-Demands-Doesn’t-Pay-Breach-Statistics-for-Business-and-Healthcare-and-Preparing-for-the-New-Normal-WFH-IGS-683x1024.jpg] Transcript (Edited) Is the proactive IT podcast this week the latest in it in cybersecurity news. Plus paying ransom demands doesn’t pay breach statistics for business and healthcare and preparing for the new normal work from home. This is Episode 30 Hi everyone and welcome to the productive it podcast each week we talk about the latest in tech and cyber news compliance and more. We also bring your real world examples to learn from so that you can better protect your business and your identity. This podcast is brought to you by wash tech, a client focused and security minded consultant located in Central Connecticut, you can find us at and wash tech comm that’s NW Aj tech.com. Alright, as always, thank you for joining us in this week’s episode of the productive it podcast. We have lots of stuff to share with you today updates, and HIPAA news, security news, all kinds of interesting cyber security and compliance news. But before we jump into it, I want to tell you that I am now part of the 405 D task force which is a federal task force that is that goal is to improve cybersecurity in healthcare, so be looking for more of that to share with you in the future. It’s a lot of what I’ve been sharing with the HIPAA education in the last few weeks. So I’m excited to be a part of that. And my first meeting will be in July. So look for more of that to come. We do have a number of updates to talk about. But before we jump into that, I want to again, thank you for listening. Wherever you’re listening to this, if you could like share, comment or review. We’re just trying to reach the masses so that we can share all of this relevant information with them as well. And that will better prepare business owners, healthcare providers, lawyers, financial firms, just really any business owner to be prepared for the inevitable and that is to be a victim of cyber attack. Also, if you’re in a HIPAA compliant business, if you could go to Facebook, in Facebook search, type in get HIPAA compliance and join that group. That’d be awesome too, because then you’ll learn everything that I learned, plus what I already know, plus the information that I get to share out to people and you’ll be better prepared in your healthcare practice for HIPAA compliance in cybersecurity. All right, as I mentioned, we do have a number of updates to talk about software updates. And first, we have chrome 83 one was released, with quite a few security upgrades and privacy upgrades, but also some cool feature upgrades. The security upgrades, probably the most important. So that is the reason you should update your Google Chrome ASAP. They do did redesigned DNS over HTTPS. They also included a new safety check feature in Chrome. So kind of a future kind of security, both of those, right? Easier security and privacy control. So it’s easier to manage your security now. Enhanced Safe Browsing protection. And what that means is that when you go to a website, it will show you can enable it to show the full URL, instead of just a partial URL, which could be important, especially for phishing purposes. Actually, that is a separate feature in its own so enhanced Safe Browsing is when enabled, Google will perform real time check of URLs that will visit that you visit. For known threats, so they’ve kind of already been doing that, but I guess they’ve enhanced that even more. The cool feature that’s been added to this is group tab groups, which means you can group your tabs into, you know, like if you have Facebook, Twitter and LinkedIn all open, it could be your social media tab. If you have bleeping computer and spyware open, that could be your security, your cybersecurity tabs, things like that. So you could group your tabs into how you want to tab them and have less tabs open, I guess, in a sense, a little more organized organization. So that’s pretty cool feature. And it did address 38 security vulnerabilities in total in the update, so get it updated right away. It’s real simple to update Google Chrome. So make sure you take care of that. Drupal did release a security update. You should update to anything above and beyond a point eight So there is a a vulnerability that is impacting Drupal seven 8.7 and 8.8 that could allow a remote attacker to exploit the vulnerability to take control the affected system. Apple released a security update for Xcode. Again, I think that’s the second one this month. So get that updated. ISC released a security advisory for bind bind being Berkeley internet named domain that is a protocol in Windows. So there is a security advisory for that there is not necessarily an update, but there is a workaround. So make sure you check out the the advisories on that that is available on system and it is in regards to CVE 2020 8616 and 8617 Adobe released updates for Premiere Pro audition and premiere rush. So if you use any of those project products, update them ASAP. VMware really security update for cloud director. I think that might be the second one this month as well. There is a security VMware security advisory linked to the system Bolton and that is at VMware comm slash security slash advisors slash VM sa dash 2020 dash 00 10 dot html. And finally, Microsoft did release a security advisory for Windows DNS servers. Microsoft has released a security advisory that addresses a vulnerability affecting windows DNS servers an attacker could exploit this vulnerability to cause a denial of service condition. We talked about that a little bit on the daily episode, that is the advisor is a dV 200009. So make sure you check out that advisory it is not an update it is an advisory So Microsoft is aware of a vulnerability involving packet amplification that affects windows DNS servers and attacker who successfully exploited This vulnerability could cause a DNS server service to become non responsive. And there is mitigation and workarounds for it. Now of course we are approaching the end of the month which means Patch Tuesday is already past. So we did have a number of updates to begin a month. And if you want to listen to those that would be previous episodes for the month of May I really should start a blooper reel because the number of times I have to edit these things is go back and re record it is pretty funny. So we’re gonna jump into the news now. First up on threat post paying ransomware crooks doubles cleanup costs according to a report. The report summarizes essentially the The to summarize it, it costs $730,000 on average to recover from a ransomware attack. But if you pay the ransom, that’s if you don’t pay the ransom. If you do pay the ransom, then it will cost you approximately $1.4 million on average. And that’s according to the state of ransomware 2020 report on Sophos few other interesting statistics 73 51% of those polled said they were hit with ransomware attacks in the last year. And 73% of those said data was encrypted in the attack. So just over half of the businesses polled, and that was that’s 5000. It manages across 26 countries. So that’s quite a few businesses. I think that’s a pretty good representation of the global economy. Just over half have been attacked and 73% of those have been have had files encrypted. So 27% were Able to fend off the attack 94% of organizations that experienced data encrypted got back more than twice as many 56% recovered their data caused using backups rather than paying ransom, which was 26%. So 26% of those polled that were hit with ransomware paid the ransom, which means the recovery costs are quite a bit higher. The private sector was hit harder, though ransomware attacks in the public sector, which is believed to be one of the hardest hit by these attacks are high profile. The report shows that actually, that sector is less affected by ransomware attacks than the private sector. I also believe that probably more so the private sector is under reporting. And so that might lead to even bigger numbers if if the businesses reported cloud data is vulnerable to ransomware. There is a common misconception that cloud data is not if you’re if your infrastructure is Or ransomware, that your cloud data is safe. And that is not necessarily true. It really depends on how it is set up. So don’t just rest on your laurels when it comes to cloud security. Or I’m sorry, security overall involving cloud. Cloud infrastructure as a service is what it’s called. For the most part. We have a report on NBC News This has been reported all over the place about criminal group that hacked law firm threatens to release Trump documents we reported this last week. We talked about it a few times on the daily episode as well. A law firm in New York City was hit with a ransomware attack the law firm is Grubman Shire masalas and sacks or GSM law, I believe is I believe, it’s either GSM large GSM s law. And the law firm is a law firm for and, you know, celebrities, entertainers and so forth. And so we’re talking big names like Lady Gaga, Madonna, Bruce Springsteen, a bunch of big names in us in last week we saw the file structure for what they claimed for the information that they claim to have so that we saw the hierarchy. And there were files that said Lady Gaga and Bruce Springsteen and so forth. Now, this week they claim early in the week they claim that they had, or maybe late last week, they claimed that they had information on Donald Trump, that they were going to leak unless they received a $42 million demand. They have since said that they’ve sold that information to someone else. And now they’re looking for a buyer for that information on Madonna. I, the law firm says that they did not represent Trump at any time. So it’s hard to say whether or not they have information to supposedly there was some emails released that were somehow had something to do with Trump. I have not seen the email. So I don’t know what the what the content of those emails was. Doesn’t seem like anybody really cares about About the continent owes emails at this point. So I have to believe they don’t really have anything sensitive about Donald Trump, President Trump. But they have supposedly have sold that information now. So we’ll wait to see if anything else comes with that. That is where we’re staying at this moment. The law firm has refused to pay the ransom. They obviously do have information on other celebrities. So we’ll see what happens. on security week. That’s security. week.com likely breach shuts down Arkansas unemployment program. Now there was a few of these Massachusetts had some issues and I believe maybe Arizona was another one. A state program that was created to process on employment applications or Arkansas for self employed individuals or gig economy workers appears to have been illegally accessed and has been shut down. officials announced Saturday governor Asa Hutchinson said he learned Friday evening that an applicant for the program is believed to have somehow access the system prompting an investigation of a possible data breach. probe will determine if any personal data from applicants was obtained. If any individuals had their data compromised, they will be notified and steps will be taken to address the situation, including possible credit monitoring. Hutchinson said an outside it expert was brought in to review the system. We want to make sure that the system is in good shape. before it goes back online. The governor said news of the program breach was first reported on Friday by the Arkansas times that being last Friday, about 30,000 people have applied to the program which has had other problems earlier this month that computer glitch forced some who had already applied to resubmit supporting documents. So that’s all the details that are on that compromise. have not seen any updates to that but that was reported on Monday, the 18th the attack or the compromise. I don’t know if it was unintentional attack but the compromise occurred on May 15, Friday 2020 on hope net security we have an article here that talks about how shadow IT threats are a set shadow it is a threat to businesses a security threat to businesses. And now that we’re we’re experiencing more remote workers, that threat continues to grow. So as cyber threats and remote working challenges linked to COVID-19 continue to rise IT teams are increasingly pressured to keep organizations security posture intact. When it comes to remote working one of the major one of the major issues facing enterprises shadow it so once what is shadow IT. And users are eager to adopt a newest cloud application to support the remote work or bypassing IT administrators and in doing so unknowingly opening both themselves and organizations up to new things. Right, so I’ll give you an example of what shadow IT IS. You work for a company, you want to be able to remote into your work computer from home. So you set up TeamViewer on your work computer, you set up TeamViewer on your home computer and now you’re able to log in to your computer from home and I believe there was a HIPAA breach just recently similar to that. That is shadow it is not an approved application, you’ve somehow got the ability to install applications on your work computer which should never happen you should you should not have an administration ministry or account unless you are of course an administrator. And that creates a problem because now TeamViewer, which has been using impasse in the past, to attack other other businesses other other computer users is now running on a computer all the time somebody gets access to the count very ways that can happen. Now they have access to that work computer, and now they have access to the internal network of you of the business you work for. And now they may be able to do more damage based on that, especially since you probably have administrator access to be able to install their program in the first place. So what are the risks to not having this under control? First of all, there is the increased risk of data breaches, which basically what I just said, right, so if you have a while back, we’ll call it a backdoor. It’s not really a backdoor in the sense of you’ve been compromised. But it’s a backdoor in the sense that it administration might not be aware that it exists, they should be. And it shouldn’t have never happened in the first place. But they may not be aware that it exists, and which means it’s not being monitored, which means it could be easier access, maybe you’re not using complex passwords, like you should be multi factor authentication. Now the bad guys have a way in they get in and they still doubt compliance issues and regulation issues regularly. Issue violations. So now you have you know, you have to deal with HIPAA GDPR and some places ccpa the shield law in New York, FINRA, anything with law firm Sox, even PCI DSS right now you might be violating compliance and again I think I do recall the scenario I just talked about in a healthcare environment so Miss financial goals due to unforeseen costs. According to Gartner shadow, it represents as much as 30 to 40% of total it spin which can be attributed to several factors, oftentimes users and departments by shadow solutions within a similar product category already covered by company wide enterprise agreements, doubling up on capabilities and spending budget without the IT departments knowledge. And depending on who pays the bill shadow it tends to skew reporting, decrease, decreasing efficiency due to time consuming In redundant tasks, so in the case of TeamViewer, you know, you could do it for free, but let’s say you opted for the paid version. Now you’re paying for it, but they already have software, or maybe they use remote desktop protocol. You know, whatever the case may be, now we’re adding to the costs of the IT budget. So what are the solutions to help manage shadow it? First of all, it’s not in this article, but I will say this administrator should be the only one to have access to install programs on employee computers. It shouldn’t, should not. Most employees should not have access to that. So that would alleviate a lot of the issues. But at the end of the day, you want to make sure you’re providing it teams with a SaaS s a s management solution that brings visibility into the usage renewal schedules, costs policy enforcement and security to avoid the consequences of shadow it s s is short for software as a service when option is to introduce broad sa s management and discovery capabilities to check apps using a number of discovery methods. This would provide IT departments with full picture of their si s environment including all applications and users through a single dashboard si s management will call a SAS going forward. As a SAS management solutions also have the potential to educate users on the apps available through the business, choose the best solutions and utilize those platforms to their full potential. Now you so if you’re using Google G Suite or Microsoft 365 in your environment, then you already have a lot of SAS programs that are available to you. So check those out. But there are other dashboards, other offerings out there that you may want to take advantage of. So something to think about in your environment, make sure that shadow it is not an issue. And then, you know, give the employees what they need to do their job. Especially now that work from home is becoming a more common trend after during COVID-19 and post COVID-19 sounds like Twitter did announce that work from home would be permanent for most employees and Facebook is now working on 50% work from home as well. bleeping computer revel ransomware found buyer for Trump data now targeting Madonna we just talked about this from I think I said CBS or NBC. I don’t remember who it was. But there was another article posted a few days later that I want that I shared because it was said that it was rebel which is also sold in a KB and it is GSM law, by the way. So now they are looking for a buyer for the Trump data. So the first article shared that they had information on Trump they wanted 42 million sounds like they weren’t going to get it. So now they sold the data that they allegedly have, and they’re looking for a buyer for the Madonna data. ransomware attacks impacts Texas Department of Transportation. This is also on bleeping computer. This is also the second attack on on Texas in the last week. A new ransomware attack is affecting the Texas government. This time hackers got into the network of the state’s Department of Transportation, Texas DLT. Less than a week ago on May 8, which is now little almost two weeks ago to Texas core system was the victim of this same type of attack which resulted in servers being taken offline to prevent malware from spreading to the network. In a brief announcement on social media, Texas, d o t said it detected the attack on Thursday, May 14, after finding unauthorized access to the agency’s network. further examination determined that the event was part of a ransomware incident. immediate action was taken to isolate infected computers from the network and block further unauthorized access. It is unclear how many systems are impacted or the ransomware family used by the intruder. Some operations have been affected by this incident but Texas DLT executive director James bass says that the agency is working to ensure critical operation Continuing during the interruption, agencies website forms that technical difficulties make some features unavailable and that they are working to resolve the issues promptly. As it usually happens with this type of cyber attack, the FBI was alerted and evolved a new investigation. So, Texas has now had two ransomware attacks in two weeks on their different government departments. FBI warns of pro lock ransomware decrypter not working properly. So pro lock which was formerly pawned locker, p w, and D. locker is now called prologue. prologue is another ransomware group that is now working with another malware quack something to gain so quack. I forget what it’s called. It may be hearing an article, but it is a a banking Trojan which means it’s grabbing credentials so that they have access even after the ransomware is removed crackpot that’s it QAQQ ak bought. But pro lock, the decrypter itself doesn’t work properly. So this is one of those cases where you pay the ransomware demand and you get the decryption key and it doesn’t work. And the reason it doesn’t work is files larger than 64 megabytes may become corrupted during the decryption process and integrity loss of one byte per one kilobyte is possible with files over 100 megabytes and additional work may be needed to make the decrypter work properly. So this is a case where paying the ransomware probably is going to cause more problems than than if you just restore from backups. So assuming you have backups, that is a prologue is as serious a threat as the others which is me so don’t panic. You wrote in locker Gaga, or locker goga. That is, those are now telling people that if you don’t pay the ransom, they’re going to release data that they have stolen. And I believe prologue is now doing the same thing. So paying might not help you restore, but it will certainly, hopefully help prevent a data breach from becoming public. Now, I’ll say it again. ransomware attacks should be considered data breaches. They’re not in most cases, they should be at this point. Threat post shared an article that said Bluetooth bugs allow impersonation attacks on legions of devices. So a host of unpatched security bugs that allow bi s attacks, effects Bluetooth chips from Apple, Intel, Qualcomm, Samsung and others, which is pretty much every smartphone that’s out there. academic researchers have on Covered security vulnerabilities in Bluetooth classic that allows attackers to spoof pair devices. They found that the bugs allow an attacker to insert a rogue device into an established Bluetooth pairing masquerading as a touch a trusted endpoint. This allows attackers to capture sensitive data from the other device now, I shared last week, the plan going forward for COVID-19 and contact tracing and it was going to use Bluetooth. And Apple and Google were both going to come up with a way to do this at the operating system level. And my concern was Bluetooth is always vulnerable. There’s always vulnerabilities that pop up a Bluetooth in here we go. So now what could happen the bugs allow Bluetooth impersonation attacks, which is big for short bias on everything from Internet of Things, gadgets to phones to laptops, according to researchers at the equal equal Polytechnique Federal de Lausanne EP FL in Switzerland. The flaws are not yet patched in the specification those some effective vendors may have If implemented workarounds, we conducted B is attacks on more than 28 unique Bluetooth chips by attacking 30 different devices the researcher said, at the time of writing, we were able to test chips from Cyprus, Qualcomm, apple, Intel, Samsung and CSR, all devices that we tested were vulnerable to be is attack. The issue lies in pairing bonding protocols used in the specification when two Bluetooth devices are paired for the first time they exchange a persistent encryption key, the long term key that will be will that will then be stored so that the endpoints are therefore bonded and will connect to each other without having to perform the lengthier pairing process every time. And if you’ve ever paired a Bluetooth device, you know, it’s not always fun for the attacks to be successful and attacking device would need to be within wireless range of a vulnerable Bluetooth device that was previously established bonding with a remote device with the Bluetooth address known to the attacker, which isn’t that hard because if the Bluetooth I’ve so I have Been places where somebody is trying to connect to a Bluetooth device, and it pops up on my phone, and I can choose to accept or decline and of course, I was declined. But if I accept it, I now have access to that device, potentially. So it’s really not that hard to grab the MAC address of the of another device. The post pairing connections are enabled because of devices, let’s call them Alice and Bob perform a background check to make sure both possess the long term key. This is done using the legacy secure connections or secure connections protocol. Inside the Bluetooth specification, which verify three things Alice’s Bluetooth address Bob’s Bluetooth address and a shared long term key. And then it goes on to talk about how the technical, the technical, the technical information behind the attack and what could occur. But essentially, if the attack happens, they could read all of the data on your phone. Potentially. So, remediation is forthcoming there is there has not been any updates to anything yet. And as you know, if you own an Android, you have to wait for the specific vendor of your Android device unless you have a Google phone. You have to wait for the vendor to release the update. And then with Apple that’s always update to everything when they release the update. So this was the concern that I expressed when it came to contact tracing. And here we have it. On Hacker News, UK Ukrainian police arrest, Haku tried selling billions of stolen records sold. The Ukrainian police have arrested a hacker who made headlines in January January last year by posting a massive database containing some 773 million stolen email addresses and 21 million unique plaintext passwords for sale on various underground hacking forums. And an official statement released on Tuesday the Security Service of Ukraine. SBU said it identified the hacker behind the suit them sanics who was resident of ivano? Friends victory friends frankest. I don’t know how to say that. It’s ivano iba and oh, dash f ra nk IV sk region of Ukraine, but it did not reveal his actual identity to the media in January last year, the hacker tried to sell the massive 87 gigabyte database labeled as the largest array of stolen data in history, which according to security experts, was just a fraction of the stolen data sanics collected according to authority sanics had at least six more similar databases of stolen and protect and broken passwords totaling in terabytes in size, which also included billions of phone numbers, payment card details and social security numbers. So here’s the crazy part. So he had all this information, email addresses, he wallets all kinds of stuff, pin numbers, bank card pin numbers. He was selling the databases for between 45 and 65. dollars each. That’s not a lot of money. And so when I tell you that if your data is stolen, it’s going to be in multiple hands before you know it, that is exactly going to be what happens. Search of at his residence resulted in a seizure of computer equipment with two terabytes of stolen data, phones and evidence of illegal activities of more than $10,000 in cash from illegal transactions, which was 190,000 Ukrainian heaviness, which is approximately 70 $100 and then $3,000 in US sanics is now facing Ukrainian criminal charges for unauthorized interference with computers and unauthorized sale disseminate or dissemination of information with limited access stored in computers, if found guilty could be facing up to eight years in prison. And which, I don’t know it doesn’t seem like a lot for the amount of damage you potentially have caused. But what can I say? And if you thought vigilantes were just a thing in movies, They’re not if you thought it was just all about Batman it’s not vigilante hackers target scammers with ransomware and DDoS attacks. This is on bleeping computer hacker has been talking just or taking justice into their own hands by targeting scam companies with ransomware and denial service attacks. Last week his new ransomware was discovered called milkman victory that a hacking group stated date created to attack scammers. In a conversation with bleeping computer the hacking group known as cyber where stated that they have started targeting companies performing what they call loan scams. The victims are saying that they give loan but you first have to pay and then you get nothing to hacking group told bleeping computer. The as part of their attacks the threat actors are sending phishing emails containing links to executables masquerading as PDF files. They’re also conducting denial service attacks to bring down the company’s websites. The ransomware is being distributed as its destructive wiper attack as it does offer a way to contact the attackers and does not have the encryption key. I do not ask money because scammers do not deserve money for scamming innocent people the hackers told us instead the victims are left with a ransom note stating the computer was destroyed because we know you are a scammer. So I think it does a typo there don’t have a way to contact. The hacker group claims to have targeted the German Luz union loan company, whose website is currently down with a DDoS attack and email spreading ransomware. The attacker state that this ransomware is based on hidden tier which means that even if a key is not saved, it can still be decrypted using the brute force attacks. Anyone who is encrypted by hidden tear variant may be able to recover their files for free using Michael Dilip Michael Gleb sees hidden tear decrypter so vigilantes using ransomware sounds pretty cool. Right hot topics for the week, we have a few things we’re going to discuss. The first one on Zd net home office technology will need to evolve in the new work normal. And what does that mean? So Twitter announced either earlier this week or late last week that work from home would be a permanent option for employees. Facebook announced, I believe, yesterday that they would like to have more than 50% of their work force to be worked from home by 2030. So work from home is going to become more of a reality for a lot of companies. I know that it’s not new, and it has been growing for some time. And there were some people that said it’s great and others say it’s not. I believe it is good for those that like it’s not, it’s not good for everybody. Not everybody wants to work from home. I believe those that like to work from home are more productive. They’re just not going to work. Their traditional hours if it’s possible, they’re not Going to work through the traditional hours, the nine to five to eight hours a day. They’re going to work, you know, typically I work from roughly seven in the morning, so, three to four in the afternoon, and then I go back to work around 830 at night for a few hours. So that’s, you know, that’s my typical day. I’m still monitoring throughout the day. But that’s typical. And I think that’s true for a lot of work from home people. They break their days up around different factors that impact their schedule. So the new normal for work will be more remote spirit home, office innovation wave make edge computing, more mainstream and require more automation, immersive experiences and robotics. Those are just some of the takeaways from my conversation with Dell Technologies. CTO john Royce This is written by Larry dignam dignan di gnn on ZD net and as he says, the conversation revolves around what we’ve learned so far from the great work from home experience, experiment that and where we’re going next. So the great work from home experiment, I’m assuming is linked to another article, I’m assuming he’s talking about COVID-19 which kind of forced work from home on everybody. Here are the two key takeaways in in there is a video included if you want to go over to Xena and and watch the video. Of course the link will be in the show notes. Culture and home Environment Matters. Not surprisingly, Dell didn’t have a hard time moving more than 100,000 people to work from home arrangements. After all, Dell says wise thin clients laptops and virtual desktop platforms. Roy said when you move everyone then you start to discover some of the things you didn’t know about. We clearly understood that people weren’t would work from home. So we had the proper equipment, the proper VPN access to proper network capacity, VDI, all those things. But we started to realize that maybe we didn’t have the right environment at home. Maybe we didn’t have the right culture and a sense of people We’re getting overwhelmed but we would call zoom fatigue and other new normal scenarios. So those are good points. So first of all I want to say VPN access is critical. If you’re going to use remote desktop, it is even more critical. vd eyes, which is virtual desktops. Also a good viable option if sending them home with a laptop is not a good option. And they’re going to use their own device then VDI is another option. You can lock that down much better than you can lock down a person’s personal laptop. Zoom fatigue is becoming a real problem for some people. I think to some extent, I feel it because I’m I do hop in and auto zoom meetings probably at least two or three times a day. And then on top of that, I’m getting my kids in and out of zoom meetings right now because of the school from home. The the there are they do make something called Blue. I think they’re called Blue glasses that was supposed to help us zoom to zoom fatigue. But so there’s that. And it’s not. It’s called zoom fatigue. It’s not just zoom, it’s teams. It’s Google, it’s Facebook, it’s all of those things. This idea that part of what we do will be virtual, and part of what we do will be physical. But more importantly, those two worlds are going to intersect, we’re going to run into each other. And so some examples of that are, for instance, in our client businesses. We’ve already seen this, we have material scientists, we have mechanical engineers, we have people that actually have to work on a physical device in a lab somewhere, they can’t do that work from home exclusively. So initially, we set up programs to allow scheduling of lab space and sanitation of labs to develop a lab environment. And to get through that, but as we look forward, what we’re going to see is the environments are either going to become more automated with robotics. So that person can actually do mechanical work from somewhere else. or more importantly, maybe one person is in the lab but other person. Other people now have better visual representations better immersive technology, so they can be part of that. experience. So sort of a hybrid model, which we’ve also discussed today, whether it’s education or healthcare or any other industry, virtual and physical experiences will evolve and meld together, the definition of working from home will change. And I agree with that as well, our assumptions around that about what it meant to work from home were wrong collectively. We had we had this idea that work from home was about work life balance, you were working, or you were doing home stuff. That was what worked from home had to deal with. And what we almost immediately discovered was it wasn’t that simple. In fact, there were at least four different contexts that people had to live in or experience sitting at their desk at home at any given time over the course of a day. an immersive work experience such as zoom call, or interacting with people, a non immersive work experience, where you have different deliverables, a personal it experience, such as answering email and paying bills, and entertainment experience. The funny thing is, all of that had to happen in the same space. And so we discovered that the monitors weren’t configured properly. was hard to context switch between them. We didn’t have enough bandwidth. In some cases the devices people had in their houses weren’t powerful enough to do all these tasks and voice. technology will have to nor context to home technology experience will have to adapt to our various modes and have the capacity to manage to compute requirements. There is a very large innovation cycle coming to really make the work world at home adaptable to all of these contexts. As we look forward, edge computing we will will come to the home. As remote work evolves more to include augmented and virtual reality as well as video conferencing and data intensive applications IT infrastructure at home will change. Roy said that edge computing devices may be deployed in homes by enterprises to beef up home infrastructure. Early when we were talking about edge It was about all smart factories, in smart cities and smart hospitals. But there’s another class of edge compute that’s really interesting and This new world said Royce, and there’s their that is to augment the compute capacity of the devices that attach to that edge. AR VR and applications that need horsepower would use these edge compute devices and laggards will invest heavily now, digital transformation, laggards will invest heavily now. So what does that mean? So basically, we’re going to have some new devices. And they didn’t really talk about security in here that will also play a big role in this because typically the home user has a home router. And that’s the extent of their security. They may have a you know, maybe an ABG or an Avast or some other relatively cheap malware protection. Things like that. And then so that’s, that could create a problem. There, they’re also probably less likely to be security focused at home. So that’s going to create a bit of a struggle for for us It teams around the world. those are those are concerns on the digital transformation. laggards will invest heavily now, do we have some some companies learned really quickly that they’re going to have to invest in work from home. And they saw that over the last few months. And they saw the struggles and I saw it across different industries. Personally, we handled, you know, everything from healthcare to law firms to even a municipality. So, it is it is something that that should have been addressed a while ago. You know, this, the ability to work from home has been fairly easy now for probably close to 10 years. And it’s gotten easier over the last few years, especially with the with the explosion of zoom and other collaboration platforms, slack and teams. So now that it’s easier than ever, those that didn’t invest in that are going to invest in that and probably more than ever before. Alright, so we have a couple of reports to go over. We have one from Verizon Verizon data breach report. DDoS skyrockets, that’s denial service and espionage tips. So you may or may not be aware of Verizon issues an annual report. That is called the data breach investigations report DBI RS for short. They released it. This Week in denial service attacks have spiked over the past year while cyber espionage campaigns have spiraled downwards. That’s according to Verizon 2020 data breach investigations report released Tuesday, so that was Tuesday, May 19. And so they analyze 32,002 security incidents and 3950 data breaches across 16 industry verticals. Notably this year’s DDoS attacks increased in number by 13,000 incidents and we’re also seen as a bigger part of cyber criminals tool boxes DDoS attacks made up 40% of security incidents reported beating else to cry beating out crimeware. In web applications while DDoS attacks use different tactics, they most commonly involve sending junk network traffic to overwhelm and crash networks systems. It doesn’t help that cyber criminals have created new and dangerous botnets to launch DDoS attacks like Kashi and Mariah variance over the last over the past few years. While the amount of this traffic is increasing, as mentioned in DDoS, which we don’t just look at the number of attacks that are conducted, said researchers, we also look at the bits per second, which tells us the size of the attack and the attacks and the packets per second, which tells us the thruway of the attack, in other words, how much traffic is coming through. What we find is that regardless of the service used to send the tax, the packet to bit ratio stays within a relatively tight band and PPS hasn’t changed that much over time, sitting at 570 megabits per second for the most common mode. Cyber cyber espionage attacks, meanwhile, have seen a diurnal downward spiral dropping from making up 13.5% of breaches in 2018 to a mere 3.2% of data breaches in 2019. That may come as a surprise given that espionage campaigns were actually on the rise in 2019. Verizon DVR, in addition, a slew of cyber espionage campaigns such as ones targeting the who, that’s the World Health Organization, several governments in Asia Pacific region and more were on earth over the past year, but researchers say underreporting which we talked about earlier, some some of the private sector anyway might be under reporting may be a factor in the duping statistics, drop and wrong numbers could be due to either under reporting or failure to detect these attacks. But the increase in volume of this other patterns is very much responsible for the reduction in percentage said researcher So in other words, if last year you had 100 cyber attacks and you 15 of those were cyber espionage and 10 of them were DDoS then your number of cyber espionage looks bigger than DDoS. But this year, there’s 50 DDoS. And still 15 cyber espionage hasn’t changed, but this percentage goes down. In fact, financially motivated breaches continue to not only be more common than espionage campaigns, but a wide margin by a wide margin making up 86% of all breaches but also increasing over the past year, they said, financial origins financial, motivated breaches that really shouldn’t come as a surprise the amount of ransom to dollar amount for ransom demands has continued to rise year over year, month over month and it’s going to continue to rise because people keep paying when it comes to data breaches almost half 45% stemmed from actual hacks while 22% use social attacks that social engineering, and we’ve talked about social engineering extensively. 22% breaches involve malware and 17% were created by errors and 8% of breaches stem from misuse of authorized users by authorized users. In fact, internal actors were only around 30% of the breaches with the majority 70% actually coming from external actors, while researchers said that incidents stemming from inside actors have grown over the past few years, that’s likely due to increased reporting of internal errors rather than evidence of actual malice from these actors. External attackers are considerably more common in our data than are our internal act attackers and always have been said researchers This is actually an intuitive finding as regardless of how many people there may be in a given organization. There are always more people outside. Nevertheless, it is widely held opinion that insiders the biggest threat to an organization security but one that we believe to be erroneous. malware has been on a country consistent and steady decline as a percentage of breaches over the last five years, researchers said due in part to the increasing level of access by cyber criminals to credentials. So in other words, it’s easier to get credentials, so why bother with malware? We think that the other attack types, such as hacking and social breaches benefit from the theft of credentials, which makes it no longer necessary to add malware in order to maintain persistence, said researchers now some attackers add to both they steal their credentials, just steal the data, and it will add malware because they may want to come back later. According to accordingly, the top malware varieties and data breaches was taught by password dumpers which are used to collect credentials, followed by Capture App Data and ransomware ransomware attacks continue to grow over the past year and have created high profile clients and headaches for companies such as Norsk hydro ransomware is the third most common malware breach, variety and second most common malware incident variety party If this continued growth can be explained by the ease with which attacks can kick off a ransomware attack. Researchers researchers stress in 7% of the ransomware threads found in criminal forms and marketplaces service was mentioned, suggesting that attackers don’t even need to be able to do the work themselves, said researchers they can simply rent a service kickback, watch, eat, watch cat videos and wait for the loot to roll in. So in other words, I could pay someone to run a ransomware attack for me and not have to worry about all the all the technical details. The Verizon DVR also poked down data breaches by vertical to show that cyber criminals are drastically changing how they are targeting industries for instance, point of sale related attacks once dominated breaches in accommodation and food services industry However, they have been replaced by malware attacks and web application attacks is instead responsibilities spread relatively evenly among several different action types such as malware error. And hacking via stolen credential said researchers. Financially motivated attackers continued to target this industry for the payment card data it holds. The educational services industry saw phishing attacks trigger 28% of breaches and 23% of breaches stem from hacking via stolen credentials. ransomware is a top threat for education space, with ransomware accounting for approximately 80% of malware infections. In the incident data ransomware attacks triggered by financial motivations also plagued the healthcare industry. Other top security issues leading to breaches include lost and stolen assets basic human error, however, privileged misuse, which has topped data breach causes for healthcare in the past, for the first time this year wasn’t an issue in the top three in the 2019. Report, privileged misuse at 23% of attacks, while 2020 has dropped to just 8.7%. So that’s good news and healthcare. I will say this the sectors, the verticals that saw the most activity, education, finance, healthcare information, manufacturing professional public. Well, those aren’t really verticals but yeah. I think that’s it. So those are the so you have you have Let’s do that again. So there’s healthcare. He has healthcare, information, finance, education, manufacturing. Those are the verticals that seem to have the most activities. All right. And then we also have the April health, April 2020, healthcare data breach report. There were 37 incidents, healthcare data breaches of 500 or more records again, pretty much on pace for the last six months. You know, going back all the way back to November was 36 December 41 January 33. February 39, March 36th and April 37th. So that is pretty much on par with what it’s been. What is down is the number of healthcare records that were breached for April 442,943. So just shy of 443,000 versus march was 129,000. And February was 1.5 million. So we’re back to January levels, which was 463,000, roughly. So that is good news. The 10 largest breaches most of them were relatively small compared to previous months. All were health care providers with the exception of beacon Health Options Inc, which was number 10. On the list that was a business associate that had 6723 and that was lost other portable electronic device, which means those were not encrypted. And I’m not sure I have to double check but I believe that was the one in Texas where hard drives went missing. So the the top nine Beaumont health 112,000 email meridian health services Corp 111,000 email Arizona endocrinology center 74,000 electronic medical record advocate Aurora health 27,000 email network server, doctors community Medical Center 18,000 email injures braces 16,000 network server Andrews braces By the way, so that is a dentist provider. A dental provider 16,622 individuals were impacted and it was a network server UPMC Altoona Regional Health Services almost 14,000 email, Colorado Department of Human Services Office of Behavioral Health 8000 network server and agility center orthopedics 7000 email, causes of April 2020 healthcare data breaches hacking our it incident 18 unauthorized access disclosure 16 theft two loss one so those bottom two theft two and last one, not a lot. And by the way, it was Are those are mitigated by encrypting your devices. So if you had to encrypted those devices then those three aren’t even reported location or the breached pH I pH I again being protected health information location is other two other portable electronic devices three paper and film eight the fact that eight of the breaches for April were still paper and film is, is I don’t know it just seems a little crazy to me. Email 18 44% of all breaches for April. Again, email in this just tells me yet again, we’re still not taking the precautions to make sure that PHP is not an email, and that we’re not locking down those email accounts and we’re not training our employees on phishing, network server five laptop three electronic medical records to now we’ll laptops, three and other portable electronic devices also threats. So that’s six. Those two, six of those are mitigated with encryption, electronic medical records, if you have multi factor authentication turned on, maybe that doesn’t happen. So that’s eight right there eliminated. And then finally, what data breaches by covered entity type so you have three or business associates to forward health plans in 30 of them were healthcare providers. So healthcare providers are, are appear to be dropping the ball in April. It’s going to be different. Um, you know, we we’ve only had one one financial penalty imposed so far this year, and I believe that was in January. So COVID-19 has definitely taken away from from the enforcement activity for the year so far. Now that we’re starting to reopen. Perhaps we’ll See more enforcement. I don’t know what will happen yet. But remember one of those breaches was in Connecticut. We are based in Connecticut. One of those breaches did occur in Connecticut in April. I think it was April that it happened. So that’s it for the HIPAA data breach report for April. We’re gonna move on to our HIPAA education. All right, we’re going to continue on with our 405 D Task Force best practices cybersecurity practices for small healthcare organizations. This being the taskforce that is trying to improve the cybersecurity posture for healthcare organizations around the world and we are on practice number six network management. So computers communicate with other computers through networks. These networks are connected wirelessly or via wired can actions like network cables and networks must be established before systems can interoperate networks that are established in a secure insecure manner sorry increase an organization’s exposure to cyber attack. Proper cybersecurity hygiene ensures that networks are secure and that all network devices access networks safely and securely. Even if network management is provided by a third party IT support vendor the organization must be must understand key aspects of the proper network management and ensure that they are included in contracts for these services. Well, so these are smaller healthcare practices. So that would mean that more than likely to have do have outside it vendor third party it vendor. This is probably going to change now with the work from home push that we’re going to see in the coming months and years because of COVID-19 and COVID-19. The first part of this is network segmentation. And remember, this is all based on the NIST cybersecurity framework right? So we get the information from NIST cybersecurity framework. The first part is network segmentation, configure networks to restrict access between devices to that which is required to successfully complete the work. This will limit any cyber attacks from spreading across the network. So what does that mean? If you have a piece of medical equipment, and this happens a lot now, so we have medical equipment out there that’s running outdated versions of Windows, or whatever operating system Am I have, so a lot of windows seven still exists? I think there’s even some Windows XP out there still. And these are a lot more susceptible than Windows 10 right now. those devices should be segmented from your office staff network, they should not have the same they should not be on the same network. It is called network segmentation, meaning they’re not they they may be connected to the same devices but they cannot communicate with each other is what it means. This allow all internet bound access in to your organization network, if your host servers that interface with the internet, consider using third party vendor who will provide security as part of the hosting service, restrict access to assets with potentially high impact in the event of compromised. This includes medical devices and Internet of Things, items like security cameras, badge readers, temperature sensors, and you’re going to see more of those building management systems. And by temperature sensors. They mean building temperature sensors, but also you’re going to see temperature sensors now, for people. Just as you might restrict physical access to different parts of the medical building, which is a medical office. That’s a good point. So you you’re going to lock up offices with hope you lock up offices that might have files and maybe computers and so forth that people shouldn’t have access to. Although I gotta tell you, I don’t see that a lot of the time. It’s important to restrict access of third party entities including vendors to separate networks allow them to connect only through tightly controlled interfaces. This limits the Exposure to an impact of cyberattacks on both the organization and on third party entity established and enforced network traffic restrictions. These restrictions may apply to applications and websites as well as to users in the form of role based controls restricting access to personal websites eg social media couponing online shopping limits exposure to browser add ons or extensions, in turn, reducing the risk of cyber attacks. So you can also include some DNS filtering that will block out different types of traffic that you don’t want on on your network. So in other words, if you want to block social media sites, you can block those if you want to block adult oriented websites, you can block those which you should block those. Then you have physical security and guest access. Just as network services need to be secured physical access to the server and network equipment should be restricted to IT professionals configure physical rooms and wireless networks to allow internet access only Always keep that in network closets locked Of course grant access using badgers rather than traditional key locks disable network ports that are not in use. maintained network ports is inactive until an activation request is authorized. This minimizes the risk of unauthorized users plugging in to in an attempt to it to an empty port to access to your network. This used to happen a lot I don’t think it happens as much anymore, but people used to just walk in with a laptop with an ethernet cable plugged into the network and do what they have to do. In conference rooms or waiting areas established guest networks that separate organizational data and systems the separation will limited accessibility of private data from guests visiting organization, validate that guest networks are configured to access authorized Guest Services only. I would take that a step further and say you shouldn’t have separate networking devices for those networks. So Know the the trend now is to have a device one device that has separate networks. So you have your internal network your guest network. Well, that could the potential the risk that exists that that guest network can be used to access the internal network. While it’s minimal, it is higher than if you had to separate two separate devices, maybe even two separate networks. For you know, if you have separate internet connection coming into your practice for the guests that would mitigate any chance of being able to access your internal network and intrusion prevention. So implement intrusion prevention systems as part of your network protection plan to provide ongoing protection for your organization network. Most modern firewall technologies that are used to segment your network include an intrusion prevention system component, implementing IPS and configuring them to update our Automatically reduces the organization’s vulnerability to known types of cyber attacks. IPS are available as part of a suite of next generation network applications or standalone products that can be added to existing networks. So you may have heard of intrusion prevention systems, what they do is they watch for traffic on your network that wasn’t there before maybe, you know, there’s different ways there’s different ways of doing it. But typically they watch for traffic that wasn’t there before. And if they see it, and they block it, that’s kind of layman’s terms. threats that are mitigated by this type of by this practice include ransomware attacks, loss of depth or equipment or data, insider accidental or intentional loss of data attacks against medical service that may affect patient safety. So we just talked a few minutes ago about the April 2020, healthcare data breach report and some of that included theft or lost devices. So those threats would be mitigated by instituting these practices. Heard it is time for the HIPAA breach report for the week. I don’t recall if we shared last Friday’s on last Friday’s podcast, so I’m going to share it today and if it’s redundant and it’s redundant, but we do have a few from last Friday, and then we have a few more that reported a couple of days ago. Management and Network Services LLC, a Dublin Ohio based provider of administrative support services to post acute health care providers has discovered the email accounts of some of its employees have been compromised. You might be wondering why I’m stressing the word some, and it may 4 2020 Breach Notification Letter Mns explained that it learned on or around August 21st 2019 that’s several employee email accounts had been subjected to an unauthorized access between April and July of 2018. The analysis of the email accounts recently revealed five accounts contain a protected health information of patients of its accounts. So that five accounts that’s a lot of accounts that are compromised the information and emails and email attachments vary from individual to individual, and may have included the following data elements name medical treatment, information, diagnosis information codes, medication information, dates of service, insurance provider, health insurance number, date of birth and social security number. a limited number of individuals also had their driver’s license number, state ID, card number and or financial account information exposed. And then SS takin

22 mei 20201 h 13 min
aflevering ProactiveIT Ep 29 – Privacy vs. Health artwork

ProactiveIT Ep 29 – Privacy vs. Health

THIS IS THE PROACTIVEIT PODCAST.  THIS WEEK: THE LATEST IN IT AND CYBER SECURITY NEWS PLUS PRIVACY VS. HEALTH, HEALTHCARE BREACH NOTIFICATIONS FOR NON-HIPAA APPS, & THE MOST EXPLOITED VULNERABILITIES SINCE 2016 This is Episode 29 INTRO Hi Everyone and welcome to the Proactive IT Podcast.  Each week we talk about the latest in tech and cyber news, compliance, and more.  We also bring you real-world examples to learn from so that you can better protect your business and identity. This podcast is brought to you by Nwaj Tech – a client-focused & security-minded IT Consultant located in Central Connecticut.  You can find us at nwajtech.com. Thanks for listening to this podcast.  Show us some love on Apple or Google Podcasts.  Subscribe and leave us some positive feedback.  What are you waiting for? Also, go join the Get HIPAA Compliance Facebook Group.  Search for Get HIPAA Compliance PATCH TUESDAY UPDATE: Unpatched Oracle WebLogic Servers Vulnerable to CVE-2020-2883 [https://www.us-cert.gov/ncas/current-activity/2020/05/01/unpatched-oracle-weblogic-servers-vulnerable-cve-2020-2883]SaltStack Patches Critical Vulnerabilities in Salt [https://www.us-cert.gov/ncas/current-activity/2020/05/01/saltstack-patches-critical-vulnerabilities-salt]Firefox 76 released with integrated data breach alerts [https://www.bleepingcomputer.com/news/software/firefox-76-released-with-integrated-data-breach-alerts/]Microsoft releases May Office updates with fixes for auth issues [https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-may-office-updates-with-fixes-for-auth-issues/]Instacart Patches Security Bug That Would Have Let Attackers Spoof SMS Messages [https://www.darkreading.com/risk/instacart-patches-security-bug-that-would-have-let-attackers-spoof-sms-messages/d/d-id/1337734?&web_view=true]Google Releases Security Updates for Chrome [https://www.us-cert.gov/ncas/current-activity/2020/05/06/google-releases-security-updates-chrome]Cisco Releases Security Updates for Multiple Products [https://www.us-cert.gov/ncas/current-activity/2020/05/07/cisco-releases-security-updates-multiple-products] NEW VMware Publishes Workarounds for Vulnerabilities in vRealize Operations Manager [https://www.us-cert.gov/ncas/current-activity/2020/05/11/vmware-publishes-workarounds-vulnerabilities-vrealize-operations] Adobe Releases Security Updates [https://www.us-cert.gov/ncas/current-activity/2020/05/12/adobe-releases-security-updates] May 2020 Patch Tuesday: Microsoft fixes 111 vulnerabilities, 13 Critical [https://www.bleepingcomputer.com/news/microsoft/may-2020-patch-tuesday-microsoft-fixes-111-vulnerabilities-13-critical/] CYBER SECURITY NEWS Update on Cognizant [https://www.msspalert.com/cybersecurity-breaches-and-attacks/ransomware/cognizant-status-update/?utm_medium=email&utm_source=sendpress&utm_campaign] RIP: Microsoft to drop support for Windows 10 on 32-bit systems [https://www.bleepingcomputer.com/news/microsoft/rip-microsoft-to-drop-support-for-windows-10-on-32-bit-systems/] DigitalOcean Data Leak Incident Exposed Some of Its Customers Data [https://thehackernews.com/2020/05/digitalocean-data-breach.html] Hacker group floods dark web with data stolen from 11 companies [https://www.bleepingcomputer.com/news/security/hacker-group-floods-dark-web-with-data-stolen-from-11-companies/] REvil ransomware threatens to leak A-list celebrities’ legal docs [https://www.bleepingcomputer.com/news/security/revil-ransomware-threatens-to-leak-a-list-celebrities-legal-docs/] Thunderbolt flaws affect millions of computers – even locking unattended devices won’t help [https://www.zdnet.com/article/thunderbolt-flaws-affect-millions-of-computers-even-locking-unattended-devices-wont-help/] Texas Courts hit by ransomware, network disabled to limit spread [https://www.bleepingcomputer.com/news/security/texas-courts-hit-by-ransomware-network-disabled-to-limit-spread/] WordPress plugin bugs can let hackers take over almost 1M sites [https://www.bleepingcomputer.com/news/security/wordpress-plugin-bugs-can-let-hackers-take-over-almost-1m-sites/] Maze ransomware fails to encrypt Pitney Bowes, steals files [https://www.bleepingcomputer.com/news/security/maze-ransomware-fails-to-encrypt-pitney-bowes-steals-files/] Ransomware Hit ATM Giant Diebold Nixdorf [https://krebsonsecurity.com/2020/05/ransomware-hit-atm-giant-diebold-nixdorf/?web_view=true] Healthcare giant Magellan Health hit by ransomware attack [https://www.bleepingcomputer.com/news/security/healthcare-giant-magellan-health-hit-by-ransomware-attack/] US warns of Chinese hackers targeting COVID-19 research orgs [https://www.bleepingcomputer.com/news/security/us-warns-of-chinese-hackers-targeting-covid-19-research-orgs/] Topic 1: FTC Seeks Comment on Breach Notification Rule for Health Data [https://healthitsecurity.com/news/ftc-seeks-comment-on-breach-notification-rule-for-health-data] Topic 2: US govt shares list of most exploited vulnerabilities since 2016 [https://www.bleepingcomputer.com/news/security/us-govt-shares-list-of-most-exploited-vulnerabilities-since-2016/] Topic 3: Leaked NHS Docs Reveal Roadmap, Concerns Around Contact-Tracing App [https://threatpost.com/leaked-nhs-docs-roadmap-concerns-contact-tracing-app/155719/] Woman stalked by sandwich server via her COVID-19 contact tracing info [https://nakedsecurity.sophos.com/2020/05/14/woman-stalked-by-sandwich-server-via-her-covid-19-contact-tracing-info/] Utah Says No to Apple/Google COVID-19 Tracing; Debuts Startup App [https://threatpost.com/utah-apple-google-covid-19-tracing-startup-app/155742/] HIPAA CORNER: https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf [https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf] BREACHES https://www.hipaajournal.com/category/hipaa-breach-news/ [https://www.hipaajournal.com/category/hipaa-breach-news/] [https://nwajtech.com/wp-content/uploads/2020/05/Privacy-vs.-Health-Healthcare-Breach-Notifications-for-Non-HIPAA-Apps-the-Most-Exploited-Vulnerabilities-since-2016-PIN-683x1024.jpg] Transcription (Unedited) This is the proactive IT podcast this week the latest in it in cybersecurity news, plus privacy versus health, healthcare breach notifications for non HIPAA apps and the most exploited vulnerabilities since 2016. This is Episode 29. Hi everyone and welcome to the productive it podcast each week we talk about the latest in tech and cyber news compliance and more. We also bring your real world examples to learn from so that you can better protect your business and your identity. This podcast is brought to By watch tech a client focused and security minded IT consultant located in Central Connecticut. You can find us at and watch tech comm that’s NW Aj tech.com. Alright, let’s jump into it. We got a lot to talk about this week along the lines of privacy and COPPA COVID-19. Not a lot of HIPAA breach news. So that’s good, I suppose. But before we jump into anything, of course, this week was also Patch Tuesday. Before we jump into Patch Tuesday, let’s talk about whether or not you’re going to comment like, share or review this podcast because if you do, we will. I don’t know. I guess I could think you live on the show. If you do. Just shoot me an email so I know you did it. And you can shoot the email to support at nwaz tech and wha tech. Go follow us on Facebook at unwashed tech and wha tech and if you’re in a HIPAA compliant business If you can join our Facebook group does centered around HIPAA compliance, it is get HIPAA compliance just search for get HIPAA compliance on Facebook. Now, as far as Patch Tuesday updates, we went over a bunch of updates that were released last week. So if you there’ll be in the show notes, but if you want to you can go back to listen to last week’s episode and get the update on all those patches to this week that was not as many but it is, of course Microsoft Patch Tuesday week. So we have First up we have VMware publishes workarounds for vulnerabilities in V realized operations manager. So not necessarily an update, as far as patching goes, but it is a workaround for a known vulnerability. Adobe did release security updates for Adobe Reader, Adobe Acrobat and for Adobe dng software development kit. So especially Acrobat and reader, get those updated, but if you’re also using Adobe dng software development Kitt patched that as well. And then Microsoft did release patches that addressed 111 vulnerabilities 13 of which were critical most of them centered around the usual suspects remote code execution. What do we got Microsoft Edge elevation privilege vulnerability that one is not as common but you have remote graphics components, remote code execution, color management, remote code execution vulnerability, Microsoft SharePoint Server remote code execution vulnerability, Microsoft SharePoint I’m sorry, scripting engine memory corruption vulnerabilities chakra scripting engine memory corruption vulnerability which we seem to see those every month. Media foundation memory corruption vulnerability, media foundation memory corruption vulnerability again, Visual Studio Code Python extension remote code execution vulnerability and that was the last one so we Did patch all of our client machines in our own machines this week? Already? No issues that we’ve seen. And of course you have the vulnerabilities the the patching from last week. So we’ve addressed all the patches we have in our environment so that you know, that includes browsers and Adobe and things like that. And we have not seen any issues. So make sure you take care of your patching. As AP as warranted, of course test and then push out. I have not seen any reports of problems either. So get it done. Okay, we have lots of news to share this week. going to start with an update from Cognizant, Cognizant, you may remember from last week they were hit with mais ransomware Tak cognitive being probably the world’s largest MSP and with earnings in the hundreds of millions every quarter, or Yeah, so we’ll get to the numbers in a moment. But anyway that were hit with Mays ransomware attack we know from previous episodes, that means typically exfiltrate the data first and then launches the ransomware. There has not been any indication that that has occurred here. But let’s let’s go with the update here. So Mays ransomware attack hit the MSP in IT consulting firm in late April. According to a first quarter earnings report statement, released May 7, the attack will impact cognizance, second quarter of 2020 revenue for obvious reasons and there may be an additional financial impact implications thereafter. So this is you know, there were a lot of ransomware attacks to report this week. But this is two Cool. Have any business when you hit hit with ransomware it’s not just pay ransom or restore your data from backups and be done with it. That’s not how it works. It doesn’t work that way. It’s going to cost you some money no matter what. So Cognizant in April 2020 disclose that the attack may impact company revenues. During a may 7 earnings call Cognizant CEO Brian Humphreys and CFO Karen McLachlan provided additional details about the attack mssp alert. I’m reading this from mssp alert By the way, has paraphrased the comments and company updates in these 10 points. So number one ransomware attack costs so far, the attack will cost cognisant about 50 to 70 million in lost revenue and, and margin for second quarter of 2020. Additionally, the company expects to incur certain legal consulting and other costs associated with the investigation, service restoration and remediation of breach so now you’re gonna have to deal with your clients who may have lost money, last had downtime and so forth to executive efforts. Cognizant mobilized its entire leadership team when the attack was discovered in April. The company also notify law enforcement agencies at that time. Three hundreds of customer communications and communications with clients were transparent from the start. The effort included hundreds of individual client calls with Cognizant security organization. Cyber experts and executive team along with to client conference calls in April for indicators of compromise. So Cognizant is proactively providing clients with indicators of compromise so that they can also do their own investigations. Five latest conference calls attack contained early in the week of May 4 Cognizant held a third conference call with customers could confirm that the attacks were contained. What that leaves a one to two week window where they may have been on the network and then we’d all know before that how long they were on the network. Six ransomware attacks ransomware attacks financial impact of ransomware attack will negatively impact Cognizant second quarter results for reasons First, the attack encrypted some of the IT consulting firms internal systems, effectively disabling them and Cognizant proactively took other systems offline to disruption impacted work from home enablement such as VDI, which is virtual desktops and the provisioning of work from home laptop second, some clients opted to suspend and cognizance access to their networks. For obvious reasons, again, billing was therefore impacted for a period of time yet to close the staffing those projects remain on cognizance books. So access to the networks because if ransomware is on cognizance network, it could jump in you know, we just talked about on the daily episode, we talked about the risk with RDP. And so this this is the risk now that you have some remote desktop protocol application running not necessarily Microsoft RDP, but windows RDP but something third party and maybe that makes sense. Clients vulnerable. Seven work from home issues are now largely have now largely been addressed. Eight regaining customer trust. Customer network trust Cognizant has meaningfully progressed in addressing the concerns of clients that have suspended our your our access to the networks. We expect to substantially complete this by the end of the month on preset nine financial impact timing most of the ransomware attacks impact on revenue margin will occur in the second quarter however, ongoing remediation costs will continue throughout this subsequent quarters. Cognizant plans to disclose the financial impact on a quarter but quarterly basis to ensure visibility and in 10. Lessons Learned Cognizant is applying lessons learned applying learnings from the attack to further harden its network. First quarter of 2020 Cognizant revenue was 4.2 billion up 2.8% a year ago quarter including a negative 50 basis points impact from the exit of certain content services businesses and then income was 367 million Compared to 441 million a year ago, so Cognizant is taking a big financial hit. And we have not seen the all the fallout from that yet. But Tom will continue to update as we get more information. On bleeping computers reporting that Microsoft will drop support for Windows 10 on 32 bit systems shouldn’t really come as a surprise, nor should you be using 32 bit systems at this point, you’re just not getting the full benefit of using any not just Microsoft Windows 10. But any operating system if you’re using a 32 bit system, you can’t use the memory like you can with a 64 bit system and the other resources that are available because of 64 bit system, you’re really not getting the full benefit So Microsoft will stop supporting windows 1032 bit in the near future. Hacker News reported Digital Ocean data leak incident exposed some of its customer data. Digital Ocean one of the biggest modern web hosting platforms recently hit with a concerning data leak incident that exposed some of his customer data to unknown and unauthorized third parties. Though the hosting company has not yet publicly released a statement it did. It did start warning affected customers of the scope of the breach via an email. According to a breach notification email that affected customers received the data leak happened due to negligence where digital Digital Ocean unintentionally left an internal document accessible to the internet without requiring any password. Now Digital Ocean is a competitor to Microsoft Azure and Amazon AWS. You know those those being the big players in the game. Then you have Google Cloud Platform and Alibaba. Digital Ocean is in there, but not quite as big. The document contained this document contain your email address and or account name, the name you give your account at signup, as well as some data about your account that may have included droplet account bandwidth usage, some support or sales, communication notes and the amount you paid during 2018. The company said in a warning email, the end they did include a screenshot of the email here. So what’s the concern? The concern is now they have enough information to potentially fish customers or past customers of Digital Ocean. So if you are a Digital Ocean client, make sure you if you get this letter, make sure you read it, understand it and make sure you’re aware that you could now potentially be fished or be compromised in some other manner because of it. hacker group floods dark web with data stolen from 11 companies. So they’re, like I said, there’s been a lot of random ransomware and data leaks this week. So this hacker group hacking group has started the floated dark web hacking marketplace with databases containing a combined total of 73.2 million user records. Over 1111 different companies. And so here are the list of the companies there’s total total pedia home Chef mineka. minted style share. g komen. I’m not sure what that is as ggu m i am mindful Star Tribune chapbooks The Chronicle of Higher Education in Zoosk, and then we we know, there was I think we reported last week a large Indian Education platform that was compromised in the datastore unit Academy here it is 30 to 22 million unit Academy user records are also on the dark web, as well. Hi, bleeping computer also reports revolution. Somewhere threatens to leak a list celebrities legal docs so rants, sort of leukemia. ransomware group threatens to release hundreds of gigabytes of legal documents from a prominent entertainment and a law firm that counts dozens of international stars as their clients and we’re talking big names here. So they grab data. As soon as leukemia and me’s and some others do exfiltrated the data in hit them with ransomware This is a law firm in New York City. I’m looking for the name of the New York of the law firm Grubman Shire, Musa lists and saxes GSM law, which is based in New York and represents dozens of heavyweight artists. So some of the clients that they have on their list on their roster, I should say, Madonna, Lady Gaga, elton john Robert De Niro, Nicki Minaj. Chris Brown, assure you to Timberland, Rick Ross and many others. Now, there is a screenshot of some of the data They claim to have so as you can see the hierarchy of the folder structure here and I see things like Lady Gaga Madonna, Priyanka Chopra, you to Kathy savate, Mary J. Blige, Nicki Minaj. Run DMC, you have another one for you, too. So, you can imagine Bruce Springsteen that Midler you can imagine the concern here, but they they still don’t Okay, me too. People behind Sodano KB claimed to have all of this information and are threatening to release the list to the dark web. Legal docs That is, if of course their ransom demands are not met. Thunderbolt on CD net thunder and Thunderbolt flaw affects millions of computers even locking unattended devices won’t help so Thunderbolt type of connection on Men are on all Macs after 2011 and some Windows computers and Linux computers as well. So Microsoft says this sufficiently was sufficiently concerned about the vulnerability of Thunderbolt three to direct media access attacks that it opted against including it on the Surface devices. But some of the Microsoft OEMs still added Thunderbolt and all Apple Mac computer since 2011 include Thunderbolt and there are also some Linux computers that have it as well. So the vulnerability is called Thunder spy. And while all Thunderbolt equipped computers are vulnerable to fulness by Intel, which develops Thunderbolt technology says the attacks were mitigated at the operating system level with kernel DMA protection but this technology is limited to computer sold since 2018. So if you have a computer between 2011 and 2019 with Thunderbolt, you may You may be exposed. Even if your computer is put to sleep or or locked, you are still vulnerable is the point of this vulnerability. So there is a little bit of back and forth between Ruttenberg who identified the vulnerability with Thunderbolt. Two thunders by and Intel as to whether or not the vulnerability is legitimate. with Intel saying that they developed Thunderbolt three which includes a policy management feature called security levels that lets Admins use cryptographic authentication to whitelist PCIe connections to to approve peripherals but Ruttenberg contends that Thunder spy completely breaks Intel security levels because Thunderbolt suffers from inadequate firmware verification, weak device authentication use of under unauthenticated device metadata and is vulnerable to version downgrade attacks. So I don’t use Thunderbolt. I can’t tell you. You know, I wouldn’t even I wouldn’t even I don’t even think I have any devices with Thunderbolt. So there’s that. bleeping computer reports Texas courts, Texas courts hit by ransomware network disable to limit spread. This was earlier in the week will actually last week a week ago today. The Texas core system was hit by ransomware on Friday night, may 8. And we’ve talked about this before where a lot of times ransomware attacks occur right before the weekend and right before a holiday. And that is to allow them more time to do damage. So this led to a branch network including websites and servers being disabled to block the malware from spreading to other systems. On Friday, May 8, Office of court administration the information technology provider for appellate courts, is state traditional agencies within the Texas judicial branch. identified a serious security event in the branch network, which was later determined to be ransomware attack. His statement published today on the site of Texas judicial branch says I didn’t see an update to this. So they were hit with a ransomware attack and took everything offline to prevent the spread of the attack. And, you know, Texas seems to be a popular target for ransomware attacks. It does not say who the ransomware attacker was. I’m not sure if it’s one of the ones that also exfiltrate data. We will I will see if I can find update for everybody. But remember last year, Texas was also hit 23 local governments and in if I’m not mistaken, that was done through open VPN, and maybe RDP. So, Texas again, popular target, kind of like Louisiana. bleeping computer also reported WordPress plugin bugs can let attackers take over almost 1 million sites. So this is The page builder WordPress plugin which is installed on more than 1 million sites. The vulnerabilities are cross site request forgery CSRF and deletes really, that leads to reflected cross site scripting attacks. And they affect all page builder versions up to an including two point 10 point 15. Attackers can exploit these security flaws by tricking WordPress site administrator into clicking specially crafted links or attachments and execute malicious code and browsers as well as forge requests on their behalf. The they are then able to inject malicious code. And I’m looking to see if there was an update to this but I can tell you that no millions of WordPress sites waiting for patches page builders development team updated to plug into two point 10 point 16 almost a week ago to fix the two security flaws and users are urged to patch their installations to avoid attacks so I should have included this on the on the patch report Patch Tuesday report but this is another WordPress vulnerability there have been quite a few of these over the last few weeks. And there was one last week that affected over a million websites so on bleeping computer Mays ransomware fails to encrypt, Pitney Bowes steals files so amaze ransomware got in and was able to exfiltrate some files, but they were they were unsuccessful in launching the ransomware attack of their the ransomware portion of their attacks so they did not encrypt anything. But they did get in and exfiltrate files this occurred on does not say when it happened but it’s it is recent. This was reported on May 11. So that would have been Monday and so probably over the weekend and They did have the wherewithal to prevent the encryption, but it looks like it sounds like the data leak, data was stolen, some data was stolen. It looks like they grabbed financial information, the names of their other directories in the screenshots. So there’s some screenshots here that you know may sent to say, hey, we’ve grabbed your information. So list of phones, customers and current employees, and I see a file files here for apps, eBay and PayPal, e commerce and finance final reporting forecast. So this looks like probably a network drive of some sort. So they did get the data. They did not encrypt anything they do. They failed in that respect. All right, we have a report from Krebs on security and I did not interestingly enough, I did not see this anywhere else. But a ransomware hit ATM giant Diebold. nixdorf Diebold nixdorf, a major provider of automatic teller machines and payment technology to banks and retailers. suffered a ransomware attack that disrupted some operations company says the hackers never touched the CTS or customer networks, and that the intrusion only affected its corporate network Canton, Ohio based Diebold is currently the largest ATM provider in the United States with an estimated 35% of the cash machine. Market worldwide to 35,000 employee company also produces point of sale systems and software used by many retailers according to Diebold on the evening of Saturday, April 25. So a weekend company security team discovered a non anomalous behavior on its corporate network suspecting a ransomware attack. Diebold said it immediately began disconnecting systems on a network to contain the spread of the malware. So it’s just told Krebs on security that dipoles response affected servers or services for over 100 of the company’s customers die boasted the company’s response to detected disrupts system that automates Field Service Technician requests, but the incident did not affect customer networks or the general public. Diebold has determined To spread it a malware has been contained I bought said in a written statement provided to Krebs on security incident did not affect ATMs, customer networks or the general public and its impact was not material to our business. Unfortunately, cybercrime is an ongoing challenge for all companies. Diebold nixdorf takes the security of our systems and customer service very seriously. Our leadership has connected personally with customers to make them aware of the situation and how we address it. So once again, another weekend ransom attack ransomware attack and this one was pro lock ransomware which when it comes to ransomware they’re not they’re clearly not one of the leaders but they are trying they are definitely trying so change was formerly known as porn pond locker. p p w. d locker is now called pro lock. We have a report us that the US warns of Chinese hackers targeting COVID-19 research or organizations This is coming from FBI and from Cisco. The threat actors affiliated to the People’s Republic of China are attempting to compromise and collect COVID-19 information from organizations in the US healthcare, pharmaceutical and research industry sectors. The ongoing attacks are currently investigated by the Federal Bureau of Investigation and the cybersecurity infrastructure security agency. As stated in a joint public service announcement that was published on May 13. China’s efforts to target these sectors pose a significant threat to our nation’s response to COVID-19. The FBI said this announcement is intended to raise awareness for silver institutions in the American public and provide resources and guidance for those who may be targeted. These actors have been observed attempting to identify and illicitly attain valuable intellectual property and public health data related to vaccines treatments and Testing from networks and personnel affiliated with the COVID-19. related research to potential death of this information jeopardizes the delivery of secure effective and efficient treatment options. So, this also comes on the heels of there was, I believe, a warning about North Korea, and also maybe one from Russia again. There was some vague warnings about the power grid electric grid for the US and for Canada and Canada was a Canadian electric or energy company was hit with a ransomware attack last week. So there appears to be an uptick in threats from that part of the world. And I suspect we’ll see even more targeted COVID-19 research in response organizations are advised to take defensive measures to block potential attacks. Assume that that press attention affiliating your organization with COVID-19 related research will lead to an increased interest in cyber activity. If your name is in the news, then they will Probably look at that and say, hey, let’s try. Patch all systems for critical vulnerabilities prioritizing timely patching for known vulnerabilities of internet connected servers and software processing internet data. Actively scan web applications for unauthorized access modification or anomalous activities. And let’s add to that. Well, we’ll get to in a moment approve credential requirements and require multi factor authentication, and identify suspend access of users exhibiting unusual activity and with that, I identify and suspend access of people no longer with the company or people that change departments. And that is going to do it for the news. So we will move on to our hot topics. All right, so first up This was on health IT security comm FCC FTC seeks comment on Breach Notification rule for health data and this is applying to third party applications not through EHR, IRS or covered entities, stakeholders are being asked to provide comments on the FTC Breach Notification rule, which requires vendors not covered by HIPAA to inform consumers and FTC of breaches within 60 days. The Federal Trade Commission is seeking comment from industry stakeholders on breach notification requirements for entities that collect personally identifiable health information but aren’t covered by HIPAA regulations, as noted by a host of others in the past, including the Department of Health and Human Services, third party apps chosen by patients are not typically covered by HIPAA, the only ones that are covered by HIPAA, not third party applications that would be through EHR vendors. So like follow my health is through all scripts, I believe instead The FTC Breach Notification rule enacted in 2009 requires vendors and related entities not covered by privacy regulations to inform individuals, the FTC and the media and in some cases of breaches. of unsecured personally identifiable health data. HIPAA an FTC Breach Notification rule requires notifications to occur within 60 days of discovering the breach, and if more than 500 individuals, the FTC must be notified within 10 days, which is a little more strict than HHS, the HIPAA rules. The rule certain rule created certain protections for personal health records, or PHR electronic records of identifiable health information that can be drawn from multiple sources and are managed, shared and controlled by or primarily for the individual FTC officials explained. Specifically, the Recovery Act recognized that vendors of personal health records and PHR related entities were collecting Consumers health information. But we’re not subject to the privacy and security requirements of HIPAA that continued. The rule requires these entities in their third party party, third party service providers to provide notification of any breach of unsecured, individually identifiable, identifiable health information. FTC is currently reviewing its health Breach Notification rule, as part of an overall periodic review to ensure the agency keeps pace with the changes in the economy, technology and business models. Reviews typically occur every 10 years, and includes standard questions around the effectiveness and, and potential benefits. The FTC is also reviewing whether the rules self should be retained, changed or eliminated and request the stakeholders to provide comment on key issues posed by the rule, such as whether it has resulted in under notification over notification or an efficient level of notification. industry leaders can also provide feedback on whether there is a need to notify to modify the rule to reflect the legal economic and technological changes as well as whether the time is requirements in breach reporting methods are adequate for the FTC is asking for insights into possible conflicts between rule and state, local and or federal regulations. FTC is also seeking insights into enforcement implications raised by direct to consumer technologies and services such as mobile health apps, virtual assistance and platform health tools along with potential ways. The rule should address developments in healthcare products or services tied to COVID-19 say like contact tracing apps, which we’re going to talk about shortly. Stakeholders were also asked whether they feel there’s a continuing need for specific provisions of the rule as well as needed benefits for consumers and evidence to support those asserted benefits. The FCC also requested insights on potentially significant costs imposed on consumers caused by the rule. Notably, the agency would also like feedback into whether the rule benefits or hinders their harmonization of the rule with HIPAA as well as if the rule indeed accomplishes the recovery x goal. advancing the use of health information technology while strengthening the privacy and security protections for health information, industry stakeholders will have 90 days to review the request for comment. And that is posted on the Federal Register. Now, a few things first of all, 10 years is a long time in the tech world. So 10 years ago, we didn’t have all these mobile health applications that we have now. And we’re not just talking about things like, like follow my heart, even though that is not a third party app, but something similar, where a patient can request information transferred to that application, but we’re talking about things like um, like, My Fitness Pal or your smartwatch that tracks your heart rate and things like that. Those are third party applications that do track health information and could conceivably lead to a data breach that would include health information for a person, they would not be covered under HIPAA because they’re not a covered entity, and they’re not a business associate. So they would not be covered under HIPAA. And that’s where the FTC steps in. A lot has changed in 10 years. So there’s definitely a need for changes to the rules around this. Also, there was a point here that I wanted to address. And that is the COVID-19 tracing apps. We’re going to talk about that in a moment. But we don’t really know 100% what that looks like yet. And I think there will be issues when it comes to privacy with these things. Google has been trying to get their hands and I think even Apple to an extent has been trying to get their hands on healthcare data for a long time. For obvious reasons. The reasons are in the healthcare is a business that’s never going to go away. And in fact, in some ways it will probably grow. They want to remain relevant and remain finally Eventually secure. These are massive organizations that have access to things that most organizations don’t have access to. So they want more. So it’ll be interesting to see how that develops, how this rule develops. And I think we’re going to see that this may, at some point tie into some of the data breach rules, data breach laws, data breach laws, we’re starting to see like ccpa in California and the shield law in New York and things like that. So I’m 90 days to review this was posted earlier this week. If you want to comment on it, it is available on the federal federal register that is regulations.gov you can go there and comment on it. The second thing we’re going to share today, US government shares list of most exploited vulnerabilities since 2016. This is on bleeping computer. US government cyber security agencies and specialists today have released list of Top 10 routinely exploited security vulnerabilities between 2016 and 2019. This was shared on Tuesday, cyber security and infrastructure security agency which assists the Federal Bureau of Investigation and the broader US government issued the a 20 dash 133 A alert through the National Cyber awareness system to make it easier for organizations from the public and private sector to prioritize patching in their environments. The public and private sectors should could degrade some foreign cyber threats to us interest through an increased effort to patch their systems and implement program to keep system patching up to date now, so what does that mean? It means that the US government has recognized that North Korea, China, Russia and some other countries, some other nation states may be trying to exploit these vulnerabilities that exist. And some of these vulnerabilities go back years. And so they recognize that also there are businesses in the private and public sector that have the vulnerabilities still, a concerted campaign to patch these vulnerabilities would introduce friction into foreign adversaries operational tradecraft and forced them to develop or acquire exploits that are more costly in western law widely effective and probably harder to deal with. Based on US government’s analysis of cyber attacks, abusing security vulnerabilities threat actors have most often exploited bugs in Microsoft’s object linking and embedding only OLED technology with the Apache struts web framework being the second most reported exploited technology of the top 10 to three vulnerabilities used most frequently across state sponsored cyber attacks from China, Iran, North Korea and Russia are CVE 20 1711 A to 2017 0199 2012 0158. Now the first set of numbers on these CVE are the year so this one goes back. That last one goes back to 2012. So that is eight years old. So says all three of these vulnerabilities related to Microsoft’s LTE technology over Chinese hackers have frequently exploited CVE 2012 10158, starting with December 2018, showing that organizations have failed to patch it, and that the malicious actors will continue abusing such flaws as long as they’re not fixed. In 2020. Cisco says that attackers have been hard at work exploiting unpatched security Citrix VPN, which was CVE 2019 11510 and pull secure VPN 2019 19781. So these are both last year. And pulse secure VPN is a big problem because even if you’ve patched it, and they’ve already, if they’ve already compromised it, they’ve already on your network and they’re already still able to continue to exploit other vulnerabilities in your network after them and so now that more people are working from home, that’s an even bigger issue. So here is the top 10 routinely exploited security flaws since 2016. So I want to start with the CVE 2012 0158. The Associated malware was trying to exploit the exploit. The vulnerability is found in various versions of Microsoft Office and Microsoft SQL Server and so forth. So it’s Microsoft products, which are routinely routinely have patches available to them. That is not getting pitch, not getting patched sorry. I just tried to combine patch and fixed so but we have vulnerabilities going back to 2012 2015 2017 1819. You know, 19 not being that long ago, but still so these are the list of the Top 20 Top 10. vulnerabilities are linked to this article. And the associated malware you so you have loci form book apone verite fins by Leighton bot Dried x we already mentioned Jack’s boss, China chopper dog call internal synergy and eternal blue you remember you may remember eternal blue from wanna cry Tosh LIFFE on warrior and kitty. The eternal blue compromised versions of Windows Vista, Windows seven. And those are still out there. I just saw recently somebody I know where the Windows version of Windows seven still running. So they’re still out there. They’re still out there and that’s a problem because you’re vulnerable. So check out that article on bleeping computer.com, the 10 most exploited vulnerabilities in the last four years. And if you if you’re guilty of any of those, get them taken care of. All right. The last thing we’re going to talk about in our hot news for today is the contract contact tracing applications that are developed or worked been worked on. I have three separate articles that show a concern for privacy in reality so the first one was reported on threat post leaked NHS docs revealed roadmap concerns around contact tracing app. So NHS is UK National Health Service. They were storing to haven’t developed an app yet they were storing information in Google Docs. That information was leaked. So a COVID-19 contact tracing app to be rolled out by the UK National Health Service has been thrust into the spotlight thanks to sensitive documents being leaked via public Google Drive link. contact tracing has emerged as a top idea for dealing with the Coronavirus pandemic and is considered by many to be an important step towards reopening economies worldwide. However, with several initiatives underway to use mobile phone apps to carry out privacy concerns have come to the forefront. The NHS app is no exception with details tractors concerned about how the information it collects could be used to leaked NHS NHS documents reported by wired showed that the officials behind initiatives are also concerned specifically around about how unverified information could be used. So this particular post raises a couple of concerns. One is how is the information going to be used, right? So if I decide to opt in, and in the US anyway, it’s going to be you can opt in, you don’t have to, you’re not being forced to do it. But you can opt into doing it. So if you do have symptoms, you put the information into the app. In the US, this is how they’re planning to do it. You put your information into the app, it’s supposed to be anonymous. And if you are, if it is determined that you had COVID-19 then that is updated. And now that anybody now anybody who’s opted in to this will be notified that they have come into close contact with you And then there’s there’s some guidelines around what’s considered close contact. Right. So the concern, one is, is my privacy secure is my privacy? Is there a potential for privacy issues within the application? And in the US, Android, Google, and Apple are planning to do this at the operating system level, meaning they will, they won’t be a third party app eventually. Right now, there are companies working on third party apps, and we’re going to talk about that shortly. One of them in Utah. But what are the potential repercussions to my privacy and health information being put into an application that by the way works with Bluetooth which has several vulnerabilities. So that’s number one. Number two, what happens if I want to be funny and I upload the wrong informations Um, I am sick and I put that I’m not sick or I’m not sick and I put that I am sick to cause fear. So that’s another concern that I don’t know how they can address that. Because it’s supposed to be anonymous, so I can, if it is anonymous, I could put whatever information I wanted, and nobody will know it’s me, theoretically. So already in UK, somebody got a hold of publicly, a link that was public on Google Drive that had some information in regards to the application being developed in the UK. But let’s take it a step further now. Now we have a woman in New Zealand who was being stalked after going to subway subway restaurant, and she put her information on the I guess they’re in there they have to write down contact details, including name email. Address, physical address and I think phone number. And she did this and then started getting essentially stalked by an employee a subway. So now that’s part two of the problems. So this here’s another another example of Privacy Information. private information being leaked to someone who probably should not have had it. So why this is, I compare this to I used to see my doctor used to keep a clipboard in the waiting area, you would come in, you would put your name, the reason you were there and who you were, who you were there to see in a clipboard sat at the front desk for the whole world to see. And so this is the same thing essentially, right? I’m writing down my name, email addresses, phone number and physical address and anybody else can see it, including employees, but also other customers can see it potentially. So if you’re If this is just like a mailing list you’re putting your name on, which is what it kind of sounds like then now you have other people seeing your name, address, phone number and physical address, name, address, email address in physical, you know, get a right name, address, and email address and phone number. And potentially the whole world sees it. That it you know, that could be cause for concern. Absolutely right. And this was a woman. And she even goes on to state that if she did live alone, she doesn’t that she she lives with several roommates it sounds like, but if she did live alone, then she could feel even more uneasy about what happened. And then this also opens up things like spear phishing, using social engineering, different forms of social engineering. There’s a lot of different little cyber activity cyber crime items that can be committed, because this information is now somewhat publicly available. And then we have another article, this one on threat posts about a company called healthy together an application called healthy together being developed out of Salt Lake City or out of Utah. They’re saying no to Apple and Google COVID-19 tracing, I get that, but they’re going to go with a third party app, which, in my opinion, is probably less secure than using Google or Apple. So healthy together app uses a raft of location data, including GPS cell tower triangulation, and Bluetooth. Again, Bluetooth being having several vulnerabilities to pinpoint users and Id Coronavirus hotspots. I just give you an example of Bluetooth and how it works. I one of my children’s activities. They’re one of their teachers. Try To connect her phone to Bluetooth speakers, and every time she tries, it attempts to connect to my phone. And I deny it because I’m not a bad person. But if I had accepted it, I now conceivably have access to everything on her phone. Who knows what’s on that phone, right? That’s how Bluetooth works. And if you’re in close, close proximity to something like that, it’s not hard to grab Bluetooth information off of another device. And we’ve seen it already with Tesla, their cars. We’ve seen it already with their entertainment systems. We’ve seen it with other phones. We’ve seen it with Bluetooth devices when you rent a car. If you don’t remove your phone’s information from the Bluetooth connection then you I mean, even if you do you might you might be at risk. And I’ve rented cars where I’ve seen five or six other phone information still there. After being rented after being Return. Now. We have Utah wanted to use this application from. It’s called healthy together. It’s called. And it’s from a startup company called 20 holdings. And they had already developed a social application that lets users see who’s around see who’s down and hang out in so I guess that’s their their tagline. In other words, the company specializes in Nebula enabling physical in person connections. It’s perhaps no surprise that 20 is Coronavirus app for Utah uses a raft of location data including GPS cell tower triangulation, and Bluetooth to pinpoint users. Now, that quote, that to me is cause for concern privacy concerns like what why do you? Why would you want that information out there? I get the reasoning behind it. So don’t get me wrong. I understand. We want to slowed the progress of COVID-19 down. And from the information I’ve seen in the last few days, it sounds like we’re already on that. But so just to give you an idea of how it works, so Jeff and Sarah are two individuals. This is as an example, this is not real people, Jeff and Sarah, two individuals in this example who don’t know each other, but they both have the app on their phones, old outlet. And so both phones are emitting Bluetooth and GPS signals all good said. So all good being the Chief Strategy Officer at 20. Through that data, we can identify whether or not two people have spent some time together from their contact, tracers can swing into action making calls and contacted ineffective and exposed persons, other contexts. So do you can see where I hope you can see where that could be a concern. A big privacy concern Again, I get the idea behind it. I don’t know that it’s worth the privacy concerns. Let’s educate the population. Let’s tell everybody, hey, this is what, what the symptoms are, this is what you need to be Look out, this is how you need to protect yourself, this is what you need to do. And then let’s let it go from there. I think what what you’re going to see is this technology somehow will get abused, whether it’s the company creating an application, and even say, where some people within the organization will have access to that data. Or somebody finding a vulnerability and utilizing it or somebody using false information. So there’s too much potential damage that can occur from an application like that. They’re probably going to move forward with it, to be honest with you. So Google and Apple and maybe some other companies and other countries are already doing In this so my concern is privacy. All right, so we’re gonna continue with our HIPAA education we started a few weeks ago around cybersecurity practices for small healthcare organizations. This is according to the 405 D. project to improve cybersecurity and healthcare organizations. And this week, we’re going to talk about asset asset management, management, asset management. So, what are we doing to secure our assets our servers, our computers, our healthcare equipment, and so forth. Organizations manage it assets using processes, referred to collectively as it asset managers. ITM is critical to ensuring that the appropriate cyber hygiene controls are maintained across all assets in your organization. ITSM processes should be implemented for all endpoints, all endpoints, there’s always that one breach where all we didn’t think that was needed. servers and networking equipment. ITSM processes enable organizations to understand their devices, and the best options to secure them. The practices described in this section may be used to support many of the practices described in other sections of this volume. So let’s talk what we have here. First of all, you need to do an inventory. And again, this is all based on the NIST cybersecurity framework framework, NIST cybersecurity framework. It completely inaccurate inventory of IT assets in your organization facilitates the implementation of optimal security controls as inventory can be conducted and maintained using a well designed spreadsheet the following question should be captured for each device. So you should capture AI asset ID primary key hostname purchase order operating system, Media Access Control address that’s the MAC address that MAC address is assigned to any piece of hardware that connects to a network IP address deployed to who is deployed to user last logged on which you know that’s that’s kind of ongoing but purchase date cost and physical location now the user logged on can be last logged on can be monitored. So you can you can continually track that. Most important probably asset IDs, operating system MAC addresses IP addresses, and who was deployed to especially with the current work from home environment, procurement. And with that, once you have established your ITM spreadsheet it is important to record each new it asset as it is acquired. This requires establishing standard operating procedures for procurement. Generally, it is advisable to assign the responsibility of collecting information on new assets to the purchaser within your organization. And then decommissioning which is probably the most important piece, right? It assets that are no longer functional or required, well, maybe not the most important but it’s close to inventory. Required should be decommissioned in accordance with your organization’s procedures. small organizations often contact contract with an outside service provider specializing in secure destruction processes. Such providers can ensure that all data especially sensitive data, are properly removed from a device before it is turned over to other parties. Additionally, your standard operating procedures should ensure that your record decommissioning of each device if you use a service provider to decommission or destroy devices, record the certificate certification of destruction so there was never a question about what happened to it. What is mitigated by this These activities so you have ransomware attacks, loss of, or theft of equipment or data insider accidental or intentional data loss and attacks against connected medical devices that may affect patient safety. Asset Management is important because things walk away and we see it time and time again. They walk away, and they didn’t the healthcare provider realizes, hey, that wasn’t encrypted. And now you have a problem because now you have potentially thousands or even in some cases, millions of healthcare records. Now, just out there, no idea what is going to come of it. You know, we saw a HIPAA breach a few weeks ago, I think, where some hard drives went just went missing. The hard drives were not encrypted. Now. There was From the healthcare provider was that you need a specialized software to be able to see the information on those hard drives. But let me tell you a software is not hard to come by that so that response is not to me is not a good response. The hard drives non encrypted is a problem the hard drives being able to walk away as easily as they did. They were in a locked room, but the person who took them out of the locker room didn’t realize the room was supposed to be locked thought it was just because it was time of the day they walked out, never to be seen again. It doesn’t take much to get required software to view healthcare records. And if so, if that’s the intention of the Deaf, maybe it’s not the intention. Maybe the intention is Hey, I just found some hard drives I could use. But if that is the intention, then it’s not going to be hard to get that information if it’s not encrypted. So Asset Management know where they are. tracked them use barcodes or use a barcode reader you can get you could put a bar reader on a smartphone and print labels off with a barcode without any printer. Really, there’s printers out there that can do that. So put a barcode on the device, scan it, you’re done with it. Well, if you can believe this, we only have one. HIPAA breach to report this week. Fortune 500 company Magellan health has announced that it experienced a ransomware attack in April that resulted in encryption of files and theft of some employee information. The ransomware attack was detected by Magellan health on April 11. When files were encrypted on a systems the investigation into the attack revealed the attacker had gained access to its systems following a response to a spear phishing email sent on April 6, the attacker had fooled the employee by impersonating a client of Magellan health, Magellan health engaged in cyber security from mandiant to assist with the investigation into the breach, which revealed the attacker had gained access to a corporate server that contained employee information and exfiltrated, a subset of that data. Prior to the encryption of files. The attacker also downloaded malware that was used to steal logon credentials. The data stolen by the hacker related to current employees, and including names addresses, employee ID numbers, and W two and 1099 information which included taxpayer IDs, and social security numbers. a limited number of usernames and passwords were also stolen in the attack. Magellan health is unaware of any attempts to use that data but has advised affected individuals to be alert to the possibility of identity theft and misuse of their data. affected individuals have been offered a complimentary three year membership to experience identity works identity theft, detection and resolution service Magellan health is working closely with law enforcement is and is aggressively investigating the breach and steps have already been taken to improve security to prevent similar breaches in the future. Of course, it is currently unclear how many of the individuals have been affected by the breach the ransomware attack comes just a few months after the company discover some of its subsidiaries suffered phishing attacks. Magellan RX management Magellan healthcare and national imaging associates were all affected. announcements about the breaches were made in September and November of 2019. With the phishing attacks following I’m sorry, with the phishing attacks, allowing unauthorized individuals to gain access to employee email accounts in July of 2019. The emails into compromised accounts contain the protected health information of 55,637 members. So this goes back to last July. It’s conceivable that the two are tied together, right. So they got some information from that attack back in July of last year and then used it to fish Someone else this year, because it says spear phishing email. Spear Phishing means that was somebody that was targeted in the organization. So it’s conceivable that the information from last year’s attack was used in this year’s attack. And that’s why you have to be careful with that information. And that’s why you have to teach your employees how to recognize phishing attacks. And that’s why you have to set up multi factor authentication. So it sounds like Magellan which is a fortune 500 company is not not taking that information seriously. And then, of course, you always have these information where these responses where they say, you know, they’re aggressively investigating and they’re taking steps to improve security to prevent a similar incident, but hey, just happened 10 months ago, so alright, that is going to do it for the product by T podcast. Until next week, stay healthy, stay safe and stay secure. Transcribed by https://otter.ai The post ProactiveIT Ep 29 – Privacy vs. Health [https://nwajtech.com/proactiveit-ep-29-privacy-vs-health/] appeared first on Nwaj Tech - Information Tech & Cloud Support [https://nwajtech.com].

15 mei 20201 h 1 min
aflevering ProactiveIT Ep 28 – The Hidden Costs of Ransomware artwork

ProactiveIT Ep 28 – The Hidden Costs of Ransomware

THIS IS THE PROACTIVEIT PODCAST.  THIS WEEK: THE LATEST IN IT AND CYBER SECURITY NEWS PLUS CRITICAL VULNERABILITIES BEING PATCHED, BREACHES & CYBERSECURITY STATS ARE GLOOMY, AND THE COST OF RANSOMWARE THIS IS EPISODE 28 INTRO Hi Everyone and welcome to the Proactive IT Podcast.  Each week we talk about the latest in tech and cyber news, compliance, and more.  We also bring you real-world examples to learn from so that you can better protect your business and identity. This podcast is brought to you by Nwaj Tech – a client-focused & security-minded IT Consultant located in Central Connecticut.  You can find us at nwajtech.com. Thanks for listening to this podcast.  Show us some love on Apple or Google Podcasts.  Subscribe and leave us some positive feedback.  What are you waiting for? Also, go join the Get HIPAA Compliance Facebook Group.  Search for Get HIPAA Compliance PATCH TUESDAY UPDATE: Unpatched Oracle WebLogic Servers Vulnerable to CVE-2020-2883 [https://www.us-cert.gov/ncas/current-activity/2020/05/01/unpatched-oracle-weblogic-servers-vulnerable-cve-2020-2883] SaltStack Patches Critical Vulnerabilities in Salt [https://www.us-cert.gov/ncas/current-activity/2020/05/01/saltstack-patches-critical-vulnerabilities-salt] Firefox 76 released with integrated data breach alerts [https://www.bleepingcomputer.com/news/software/firefox-76-released-with-integrated-data-breach-alerts/] Microsoft releases May Office updates with fixes for auth issues [https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-may-office-updates-with-fixes-for-auth-issues/] Instacart Patches Security Bug That Would Have Let Attackers Spoof SMS Messages [https://www.darkreading.com/risk/instacart-patches-security-bug-that-would-have-let-attackers-spoof-sms-messages/d/d-id/1337734?&web_view=true] Google Releases Security Updates for Chrome [https://www.us-cert.gov/ncas/current-activity/2020/05/06/google-releases-security-updates-chrome] Cisco Releases Security Updates for Multiple Products [https://www.us-cert.gov/ncas/current-activity/2020/05/07/cisco-releases-security-updates-multiple-products] CYBER SECURITY NEWS Trump Declares National Emergency As Foreign Hackers Threaten U.S. Power Grid [https://www.forbes.com/sites/daveywinder/2020/05/02/trump-declares-national-emergency-as-foreign-hackers-threaten-us-power-grid/?fbclid=IwAR23zJbQadTSo5AF7graEubyD6jvULdt0VBI4XTlK6dzlHszC-pUo-zlmho#150f89593497] GoDaddy notifies users of breached hosting accounts [https://www.bleepingcomputer.com/news/security/godaddy-notifies-users-of-breached-hosting-accounts/] Ciitizen HIPAA Right of Access Study Shows Significant Improvement in Compliance [https://www.hipaajournal.com/ciitizen-hipaa-right-of-access-study-shows-significant-improvement-in-compliance/] Nearly 2,000 malicious COVID-19-themed domains created every day [https://www.techrepublic.com/article/nearly-2000-malicious-covid-19-themed-domains-created-every-day/?&web_view=true] US financial industry regulator warns of widespread phishing campaign [https://www.zdnet.com/article/us-financial-industry-regulator-warns-of-widespread-phishing-campaign/?&web_view=true] SAP announces security issues in cloud-based products [https://www.bleepingcomputer.com/news/security/sap-announces-security-issues-in-cloud-based-products/] Cyberattack on NTPC Further Exposes the Cybersecurity Risks of Energy Sector [https://cyware.com/news/cyberattack-on-ntpc-further-exposes-the-cybersecurity-risks-of-energy-sector-6896de5e] An Update on Cognizant [https://www.msspalert.com/cybersecurity-breaches-and-attacks/ransomware/cognizant-status-update/] Critical WordPress plugin bug lets hackers take over 1M sites [https://www.bleepingcomputer.com/news/security/critical-wordpress-plugin-bug-lets-hackers-take-over-1m-sites/] HOT TOPICS Topic 1: Consumers will opt for competitors after a single ransomware-related service disruption [https://www.helpnetsecurity.com/2020/05/04/ransomware-related-service-disruption/?web_view=true] Topic 2: Patients Notified Medical Records Exposed at Tornado Hit Secure Medical Record Facility [https://www.hipaajournal.com/patients-notified-medical-records-exposed-at-tornado-hit-secure-medical-record-facility/] Topic 3: Half of Companies Have Suffered a Cybersecurity Issue Amid COVID-19 Crisis [https://www.darkreading.com/vulnerabilities---threats/half-of-companies-have-suffered-a-cybersecurity-issue-amid-covid-19-crisis-/d/d-id/1337753?&web_view=true] HIPAA CORNER: https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf [https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf] BREACHES https://www.hipaajournal.com/category/hipaa-breach-news/ [https://www.hipaajournal.com/category/hipaa-breach-news/] Ep 28 Critical Vulnerabilities Being Patched, Breaches & Cybersecurity Stats are Gloomy, and the Cost of Ransomware IGS [https://nwajtech.com/wp-content/uploads/2020/05/Ep-28-Critical-Vulnerabilities-Being-Patched-Breaches-Cybersecurity-Stats-are-Gloomy-and-the-Cost-of-Ransomware-IGS-683x1024.jpg] Transcription (Unedited) This is the proactive it podcast this week the latest in it in cybersecurity news. Plus critical vulnerabilities being patched. breaches in cybersecurity stats are gloomy, and the cost of ransomware. This is Episode 28. Hi everyone and welcome to the productive it podcast each week we talk about the latest in tech and cyber news compliance and more. We also bring your real world examples to learn from so that you can better protect your business and your identity. This podcast is brought to you by wash tech a client focused and security minded consultant located in Central Connecticut, you can find us at and wash tech comm that’s NW Aj tech.com. Well, it’s been another fun week in isolation. I don’t know what to call it really, because it’s not real isolation, we can go out, but you’re trying to avoid it for the most part and I’m now entering week eight It is day 56 as I record this I don’t know. Good. Seems like there may be some some light at the end of the tunnel. But we’ll see. First of all, wherever you’re listening to this, if you could like share, review or comment, you know, whatever, we’ll get people to, you know, new people to listen to, if that would be awesome. You know, especially on Apple and Google, but also stitcher and anywhere else you listen to it. And if you’re in a HIPAA compliant business, if you can go over to Facebook, type in get HIPAA compliance, and join that group. You’ll be awarded with Lots of HIPAA information. And if you want to go to that now, are we you know, just you go do that, and I’ll wait right here. All right. Did you do you? Um, I did not. You know, I’ll be honest with you. I got asked a lot of questions this week, and I did not pick one to completely forgot about it, to be honest. So we’re not going to do a question of the week. We’re going to jump right into the updates for the week. And so it is the first week of May. We do not have Patch Tuesday updates from Microsoft, but we do have quite a few updates to talk about. So we’re gonna jump right into that, with the first one being unpatched Oracle WebLogic servers that are vulnerable to CVE 2020 2083 Oracle has released a blog post warning users that have previously disclosed Oracle WebLogic Server remote code execution vulnerability is being exploited in the wild Oracle disclose the vulnerability and provided software patches in April 20. 20 critical patch update over malicious cyber actors are now known to be targeting unpatched servers so if you’re using Oracle WebLogic Server get patched because it’s already been exploited saltstack which you may have heard about because it’s being it’s impacted some pretty big systems including ghost blogging platform saltstack does did patch a critical vulnerability in salt. So you should be if you’re, you shouldn’t be on anything prior to 2019 point 2.4 or three first salt. I’m sorry, should not be on anything prior to 2019 point 2.4 or two to 3,000.2. So get that updated ASAP because it is being actively exploited. Firefox 76 was released to integrate data breach alerts I I’m obviously I’m on Firefox 76 already, I have not checked out the data breach alert to see if it works at all. So we’ll be it’ll be interesting to see how that develops. There were some security vulnerabilities addressed with that release as well. Microsoft released May office updates with fixes for auth issues. There are no security updates as part of this rollout. But there is an issue with auth issues basically. Blank authentication prompts were being displayed. And I believe there was something that was crashing as well. I don’t I don’t remember what it wasn’t this point, but it’s a it’s a bug in feature update. So applied at will Microsoft Office 2016. PowerPoint 2016 outlook 2016 Project 2016 word 2016. And Skype for Business 2015 instacart did patch a security bug that would have led to tech spoof SMS messages. I’m only reporting this because sort of as an update, it’s not anything you need to take care of. But they did patch an issue with their system. Basically, it was sending a text message saying, if you’ve saw that they have an application on our website, you can happen, have them text you the link to the application. And link could have been compromised and sent a different link redirecting you to a malicious website. With that being said, if you ever want to download an app for anything, do it from the Google Play Store or from the Apple Store, don’t click on links and don’t download it from anywhere else. And we have a Google released a security update for Chrome you should be on at 1.0 point 404 4.138. That’s across the board. And finally Cisco released security updates for a bunch of products. That was just reported. Yesterday. So if you’re using Cisco products, check out their Cisco Cisco security advisories page and see if you need to update any of them. All right, we got lots of news to share this week. First up earlier this week on Forbes Trump declared national emergency as foreign hackers threaten us power grid. Combine that with another article that I saw a few days later that I don’t think I’m sharing today where a, an energy company in Canada was hit with a ransomware attack. So President Trump has signed an executive order that declares foreign cybersecurity threats to the US electricity system, a national emergency. We’ve known for a little while now that electric grid is a target. So President Trump signed an executive order may 1 to further secure the US bulk power system from foreign adversaries that he wrote are increasingly creating exploiting opportunities. The Executive Order declaring a national emergency over the hacking threat bans the acquisition, importation transfer or installation of bulk power system electricity equipment from companies under foreign adversary control. Executive Order also confirmed that the task force has been established with members including the Secretary of Defense Secretary of Homeland Security and the director of national intelligence to work to protect against national security threats to energy infrastructure, with the sort of did not do is go as far as naming any specific foreign adversaries and other companies. They may control so they left it a little vague on purpose, I’m sure. However, President Trump did state the acquisition or use of bulk power system or choosing equipment designed, developed, manufactured or supplied, subject to the jurisdiction of these unnamed foreign adversaries as to their ability to create an exploit vulnerabilities with potentially catastrophic effects. Acknowledging that an open investment, climate needs to be maintained for the growth of the economy, President Trump note wrote that this openness has to be balanced with the requirement to protect against a critical national security threat. Then Director of National Intelligence Dan arcos, published a ward worldwide threat assessment in January 2019. That warned of cyber attack capabilities both China and Russia when it came to the US electricity grid. That report stated that Russia has the ability to execute a cyber attack in the United States that generates localized temporary disruptive effects on critical infrastructure. The FBI and the Department of Homeland Security released an alert in 2018 warning of Russian government actions targeting among others the energy infrastructure sector in the US. US Secretary of Energy Dan relay, who will lead the newly established Task Force said it is imperative the bulk power system be secured against exploitation and tax by foreign threats. this executive order will greatly diminish the ability of foreign adversaries to target our critical electric infrastructure. The Department of Energy established the Office of cyber security, energy, security and emergency response in February of 2018 to approve energy, infrastructure security, including Preparedness and Response against cyberattacks. So there you have it. bleeping computer report GoDaddy notifies users are breached hosting accounts to secured an October 19 of 2018 and was discovered on April 23. I did see somewhere a number of accounts and don’t don’t believe it’s in this article. But it wasn’t attend. Oh, here it is approximate 28,000 accounts. They identified an SS de identified SSH usernames and passwords that were compromised through an altered SSH file in the hosting environment. This apparently only impacted hosting and nothing else. So if you are hosting on GoDaddy you should have received he received a notification at this point, an email or a letter saying that your account may have been compromised and enforced password changes. Citizen HIPAA right of access study shows significant improvement in compliance. So this was good news I wanted to share it. There has been a significant improvement in compliance with the HIPAA right of access. According to the latest patient records scorecard report from citizen to propel the report citizen conducted a study of 820 healthcare providers to assess how well each responded to patient requests for copies of their healthcare date. Data and wide range of healthcare providers were assessed for the study from single physician practices to large integrated healthcare delivery services or systems. So this is a so the HIPAA right of access rule is this you asked for your medical records to bring them to another doctor or just because you want Whatever it may be, they’re supposed to give them to you within a reasonable amount of time, which is 30 days or less. And you’re supposed to give it to for no less demand supposed to charge more than the cost of actually creating that record, which is usually a few dollars. They have a rating system for this, they’ve been doing this for a little while, I guess. They have a rating system of one to five stars, one being the worst and five being, you know, your name goes up in lights. The good news is that there was an increase of so there’s the latest study saw the percentage of one stars fall to 27% from 51%. That’s those that were not compliant. percentage of providers awarded four stars rose from 40 to 67%. And those with five stars rose from 20 to 28%. So that is good news, because we did see a few and they actually believed that this was because of the enforcement initiative on right of access, by the way by the OCR. And we did see a couple of penalties last year and we saw a few breach notifications for it as well. So maybe people are taking a little bit more seriously, let’s hope. On tech Republic, nearly 2000 malicious COVID-19 themed domains created every day. More than 86,600 new domains related to pandemic are considered risky or malicious according to a new report. And there was 1.2 million newly registered domain names containing words related to the COVID-19 pandemic from March 9 through April 26. And they believe that almost 87,000 of those are malicious in nature. And I’m just looking for the actual numbers here. Man, I’m not looking I’m not seeing what I’m looking for. So anyway, there’s 2000 rough almost 2000 domains registered every day related to COVID-19 that they believe will be malicious in nature, meaning it could be phishing sites or carry malware. And believe they believe that most of them will be crypto mining sites, but some of them will be fishing for sure. You know, they’ll say, Hey, we have a, we have masks, we have we have peepee, or we have a vaccine or we have a cure or whatever it might be, none of those things will be true. They will steal information and run with it and probably use it in another attack later on. And so that is the goal and there was some registered around zoom done. This article doesn’t cover the zoom ones. But that did occur when zoom was having all their problems. And it’s they’re still being used. And this is why you need to have DNS filtering in your environment because DNS good DNS filtering will take care of any newly registered domains. So they will not cause an issue with your business. Zd net us Financial Industry Regulatory warns of widespread phishing campaign. This is FINRA making a warning or issuing a warning I should say the US Financial Industry Regulatory Authority, also known as FINRA, probably more commonly known as FEMA. FINRA has issued a rare cybersecurity alert today warning member organizations have a widespread ongoing phishing campaign. FINRA said the malicious emails were aimed at stealing Microsoft Office and SharePoint account passwords. From its member organizations, FINRA, which is private industry group that works as a self regulatory body for brokerage firms and exchange Marcus said the campaign is still ongoing. According to the security alert, phishing emails were sent using a domain of app broker finra.org so you could see where someone might fall for that and made to look like they were sent by Bill woman or Josh drove Nick to FINRA as vice president presidents. FINRA said the phishing emails included the ads PDF, I’m sorry and attach a PDF file that contains a leak link redirecting users to a website prompting members to enter the respective Microsoft Office or SharePoint passwords. So this goes to a point where I’ve said before, don’t open attach attachments that you didn’t expect. Don’t click on links you didn’t expect, if in doubt with links and type them in manually and if and if in doubt about an attachment make a phone call and see if it really came from where it came from. bleeping computer SAP analysis security issues in cloud based products German software maker SAP announced on Monday that has started to fix security issues identified in several of its cloud based products. The company discovered the problems following an internal review and has already started working on eliminating the vulnerabilities. details about the security flaws have been have not been disclosed in an advisory This week the company says that fixing a post will largely be completed in the second quarter of 2020. The list of affected products includes sa p success, faster success factors. Sa p concur sa p callate. Is cloud Commission’s sa p Caldas cloud si p q as well as sa PC for si Sales Cloud sa p cloud platform in SAP analytics cloud. Some of these platforms along with their infrastructure were acquired over the years and company paid billions of US dollars for them. With this SAP inherited all the potential gaps and had to align them to the company’s present contractually agreed or statutory. IT security I’m sorry that should be contractually agreed on statutory IT security standards. It is estimated that around 9% of SAP is 440,000 customers are impacted by the vulnerabilities. They will be notified of the risk and will receive assistance to remedy the problems. Sa Pease investigation is not complete but the company does not believe that customer data has been compromised as a result of these issues. And then effort to ensure that the effective products meet relevant terms and conditions. And in addition to technical, cold remediation, SAP has decided to update its security related terms and conditions. These remain in line with the market peers. The security updates are not expected to have an impact on the company’s financial outlook for 2020. So I guess that’s good news for SAP. So roughly 440 thousand companies are impacted by this. So they will reach out to you and help you resolve it. So that’s that’s a step in the right direction, in my opinion, and here it is, I mentioned it earlier. cyber attack on NTPC further exposes the cybersecurity risks of energy sector so Northwest Territory is Power Corporation. A generator and distributor of electricity in Canada was hit with a ransomware attack. The ransomware attack hit NTPC shutting down its IT systems and impacting the power generation, transmission and distribution systems are company, my NTPC the online payment portal used by NTPC was not working properly and leading the customers to a message saying that the files were encrypted by networker, although not confirm for this case, but the spread of networker ransomware aka mail two is usually associated with the COVID-19 themed phishing phishing emails as observed during its previous attacks. And so here’s some of the previous attacks or the here’s, here’s actually information about an earlier data breach with NTPC. In January 2016 NTPC informed its customers that it had wrongly sent some personal details of its customers to third party, resulting in breach of personal data file containing a list of customer names, meter addresses, and balance account balances was sent out to some customers while responding to some customer inquiries. Other attacks on energy sectors and April 2020, the Portuguese multinational energy giant energy SMD portrait Goal UDP, was hit with Ragnar locker ransomware, where no hackers stole 10 terabytes of sensitive company files and asked for 1500 and 80 Bitcoin which is roughly $10.9 million. In March 2020, the European electricity association was targeted by cyber intrusion incident, although no further details about the incident were disclosed. In February 2020 of the reading municipal light department, our mld was targeted by cyber criminals in an attempt to extort money by encrypting data in an ancient in the station’s computer system. In January 2020, a hacking campaign by Iranian hackers was observed targeting the European energy sector, in which the attackers tried to steal sensitive information using the pupae rat malware. Other attackers by networker in other attacks by networker sorry, in March 2020 network or ransomware was observed using Coronavirus themed phishing emails to target its victims in the same month. Just ransomware was also used to target The Champaign Urbana Public Health District and in February 2020, the Australian toll group admitted that they were targeted by network a ransomware. The toll group by the way, Australian toll group was hit with another attack within the last couple of days. So not not a good year for them. Cognizant we have an update on Cognizant you may remember Cognizant is an MS MSP. So similar type businesses me as my business, except that they make quite a bit more money than I do. And we’ll get to that in a moment. They are. I believe they’re the largest the world’s largest MSP, but I could be wrong, but Cognizant believes it has contained in Mays ransomware attack that hit the MSP in IT consulting firm in late April 2020. According to the first quarter earnings statement, released May 7 still yesterday. In their statement, Congress has said the company believes it has contained the attack and that the actor is no longer operating in the company’s environs. Since becoming aware of the attack, the company has taken decisive actions to remediate the threat while keeping clients regularly informed. The company believes these measures enabled it to continue its operations in a timely, secure manner. In addition, the company has and will continue to take any necessary steps to protect the integrity of its systems. Cognitive provably previously disclosed at the attack may impact company revenues. More details about the attack and remediation are expected to surface on cognisance earnings call for quarter 120 20. Cognizant says revenue was 4.2 billion up 2.8% from a year ago quarter, including a negative 50 basis points impact from the exit of certain content services businesses and a net income was 367 million compared to 441 million a year ago. Now that being said, mes doesn’t just hit you with a ransomware attack. There’s still data. They have not said if that has happened here in Mesa has not released any data. So that tells me one of two things Mays is not done yet. Or Cognizant may have paid some money. But I’m sure we’ll learn more as the day’s progress here. So when there’s another update on Cognizant, I will share and last bit of news before we move on to our hot topics. Critical WordPress plugin bug lets hackers take over 1 million sites. That doesn’t mean they have it means it’s possible. So Elementor Pro and ultimate add ons for Elementor. WordPress plugins have critical vulnerabilities that Elementor Pro has released release patches for so if you are using those in your on your WordPress website, you should be updating Elementor Pro to version 2.9. point four immediately. There’s vulnerabilities that are being attacked as we speak. ways you can check to make sure that your site hasn’t already have been compromised check for any unknown subscriber level users on your site this may indicate that your site has been compromised as part of this Active Campaign. If so, remove those accounts. Check for files named WP dash XML or PC dot php these can be considered an indication of compromised, so check your site for evidence of this file and delete any unknown files or folders found in WP content slash uploads slash element or slash custom dash icon slash directory files located here after a rogue subscriber level account has been created our clear indication of compromise. So again, that is almost 1 million. I think it’s actually a little more than 1 million sites that are using Elementor Pro and another hundred and 10,000 sites using ultimate add ons for Elementor. So if you’re using those, get them updated immediately. Let’s talk some numbers because this if you know, not gonna lie, I try to scare you guys. I try to scare business owners, because they need to be scared. I don’t do it because I want you to purchase on fear I do it because you need to be educated you need to understand the risks that are out there. So if you’re not willing to consider the risk of, you know, you being breached your client information being stolen or whatever else, maybe you’d be concerned about this risk. consumers will opt for competitors after a single ransomware related service disruption. While most consumers are taking necessary security precautions to protect their online accounts. I don’t believe that but if but some of them are. Businesses may not be doing enough to protect their information inadvertently driving sales to competitors that can that can an ark serve research reveals and I found this on help. NET security calm by the way 7% will switch to a competitor. If your systems and applications are back online within 24 hours. 41% will walk away if they still can’t access systems and applications within two to three days. They serve a survey of nearly 2000 consumers across North America, the United Kingdom, France and Germany found that 70% believe businesses are not doing enough to adequately secure their personal information and assume it has been compromised without them knowing it. And as consumers become more educated and cyberattacks become well known, perceived trust becomes more influential and a purchasing decisions, with the study also finding that nearly nine out of 10 consumers consider the trustworthiness of a business prior to purchasing a product or service and 59% of consumers would likely avoid doing business with an organization that had experienced a cyberattack in the past year. These findings suggest businesses must manage Uncharted challenges within the use of cyber criminals, or I’m sorry within the rise of cyber criminals. Now making breaches public regardless ransom pay. So again, we’re talking about me’s and the apple painter. I think Raju and a few others are clop are now publishing the data that they steal if you don’t pay up ransomware related service disruption consumer tolerance thresholds, cyberattacks, have arguably become the largest business threat. However, the quantifiable impact on consumer behavior has not been widely understood. The study found that one in four consumers will abandon a product or service in favor of a competitor after a single ransomware related service disruption, failed transaction or instance of an inaccessible information. It also found that tolerance for these events quickly deteriorates with over 66% of respondents setting that they would turn to a competitor. If an organization couldn’t restore systems and applications within three days following a cyber attack. And over a third of those would be willing to switch after a mere 24 hours of waiting to access their information or make a transaction Moreover, the potential damage doesn’t stop during a shortly during or shortly thereafter a cyber attack. More than eight and 10. respondents admit to sharing their negative ransomware related experiences with family friends or colleagues posting about their experiences online or medium and lying about the incidents. Note these attacks are usually very well publicized. So you have to think about that perspective as well. certain industries fared better than others. While the report concludes their debt consumers are generally intolerant of cyberattacks. There are a few industries where businesses are under even more pressure to keep data secure and operations running. The survey found that nearly half of consumers would walk away from their banking or security provider immediately upon experiencing ransomware related event which would which prohibited them from transacting or accessing information and 43% would immediately seek out a competitive communication product or service and I can’t say I blame them. While there are many negative ramifications caused by cyber attacks, businesses that take protective or I’m sorry, proactive steps in many To get ransomware quickly will benefit in the long run. Over half of the respondents would be willing to pay more for products and services they believe to be more reliable and secure in the banking and securities industry in over 40% would pay more if they believe products and services were more secure from companies in the healthcare insurance and retail categories. So all of you, businesses, these are all almost all of them. compliant type businesses that say you can’t afford cybersecurity because it’s too much money. Well think about that over half of the respondents would be willing to pay more for products and services they believe to be more reliable and secure in the banking and securities industry, and over 40% would pay more if they believe products and services were more secure from companies in the health care insurance and retail categories. Consumers are clearly already hesitant about working with companies hit by cyberattacks, and it just won’t tolerate disruption as businesses figure out recovery and remediation plans after the fact. The findings represent a stark warning for organizations given that one in four of their customers will be gone immediately upon disruption with many more losing patients within 48 hours, and the numbers are there, the ransomware attacks take in many cases take more than 48 hours to recover from. businesses must do more to ensure they’re protecting your data from cyber criminals and mitigating the chance. They’ll experience extended downtime, we recommend a two pronged approach where cyber security backup and disaster recovery are deeply intertwined. So if the thought of your clients data being stolen, or the thought of your business coming to its knees, or you know, I don’t know why business owners wouldn’t already be concerned and we’re going to go over another article in a moment that shows that some businesses are not concerned that maybe this is another one you get hit, you’re going to lose reputation immediately and I’m going to look up the hit that target took after they were their credit card information was stolen a few years ago. Just to give you an idea, but before we do that, patients notified medical records expose that tornado hit secure medical record facility. So I’m going to go through this first and then I’m going to explain why I’m bringing this up. Several healthcare providers have been affected by an unusual data breach at wapa. Wisconsin base stat information informatics solutions LLC. stat provides secure medical records services to several health care providers, which includes scanning paper files so they can be added to hospital medical record systems. On March 3, a staff facility in Lebanon, Tennessee was hit by a tornado, which caused extensive damage to the building and some of the records stored in a facility that notified all affected clients the same day, and representatives of those health care providers visited the site to assist with locating and securing medical records in the facility. to limit the potential for unauthorized access. A tall fence was erected At around the building while the medical records were located and secured to security guards were also posted on the site 24 seven to prevent unauthorized individuals from accessing the building. The majority of the medical records were found in the remnants of the building, but the records were determined to be unsalvageable, and have now been securely destroyed. While it is possible that to an authorized individuals, that unauthorized individuals may have viewed some paperwork relating to patients, no evidence has been uncovered to suggest that this was the case and patients are not believed to be at risk of financial harm. Out of the abundance of caution patients whose records were stored in a building are being notified by mail and will be offered complimentary credit monitoring services. The medical records at the facility contain the following types of information, full names, social security numbers, addresses, dates of birth, medical record numbers, account numbers, medical images, diagnosis, nursing and physician documentation, test results, medications and other types of information typically found in medical records. And so here’s the of the health care providers who were impacted by this Bayfront health in Port Charlotte, Florida, Bayfront health and Buta gorda, Florida. Commonwealth health Wilkes Barre General Hospital, Pennsylvania, Commonwealth health, Moses Taylor Hospital in Pennsylvania and Poplar Bluff Regional Medical Center in Missouri. Now, why did I bring this up? This illustrates a very important point. Your security risk analysis is supposed to go through every risk that is believed to be in existence for your practice for your metal for your covered entity or business associate, associate, whatever it might be. Tennessee is in an area where they do get tornadoes. So tornado is a very real risk. I’d be willing to bet that this business stat did not do a security risk analysis that included tornado potential for tornadoes. So in other words, if you live in an area where you’re you’re constantly under hurricane threats so Florida, South Florida, then you should include that in your security risk in house. If you live in the northeast where blizzards are very real threat, you should include that in your security risk analysis. If you live in an a coastal area where water is an issue, you should you should include really you should include flooding, whenever you have a covered entity or business associate, but that needs to be in your security risk analysis. The security risk analysis should take every possible risk, analyze it and prepare your healthcare practice or business associate for that risk. It’s not meant to be a checklist. It’s not meant to say okay, well, we are we have anti malware software in our computers. So we’re secure. That’s not what it’s meant to be. And that is part of it. You know, that’s, that’s part of your security risk analysis. And every every healthcare practice should have that. You should, you should make sure that your systems are secure from breach and from malware and from ransomware, and all that stuff, you know, and that includes data backups and all that. But this I’m sure that could have done more to prevent something like this from happening, it is tragic. And I’m sure that the numbers will show that the chances of that building getting hit by a tornado were pretty small, but it’s still a possibility and it’s still something that needs to be looked at when you run your security risk analysis at least once a year. So that’s the point of me sharing it is it’s a rare HIPAA breach, but it’s still a HIPAA breach and it still could happen. You know, we’ve we’ve, with Florida you get hurricanes all the time. And they do say that 20 is going to be an act of hurricane season in a way this year is going to wouldn’t shock me the least bit. So, that’s something to think about if you have a healthcare practice and that could be anything, it could be a dentist, the chiropractor, a physician, an optometrist, any hip any business that that falls under the HIPAA umbrella needs to run a security risk analysis and say, okay, we could get hit with a hurricane. Are we prepared for that? And what do we need to do to prepare for that better? So that is, that was the whole point of me sharing that. And plus, it’s one less HIPAA breach I need to report later on in this podcast. And we’re going to go back to the we’re not going back to the article, but we’re going to go back to that topic. So I found this some dark reading. It’s a real short read. Dark reading.com half of companies have suffered a cyber security issue a mid COVID-19 crisis. survey shows 49% expect to experience a data breach or cybersecurity incident in the next month. But it gets scarier than that. Social Justice, social justice sensing and working from home may be helping to stem the tide of the COVID-19 pandemic but they aren’t doing much good for enterprise cybersecurity. According to the results of new study, nearly half, which is 46% of global businesses have encountered at least one. cybersecurity scare since shifting to remote working model, and 49% of the survey respondents anticipate suffering and data breach or security incident in the next month as a result of moving employees to work from home. The study conducted by Barracuda found that an increase in perceived risk has not been accompanied by an increase in security spending. So that’s where it gets scary. So you saw that you getting hit with a ransomware attack which will directly impact your bottom line and your reputation. And then you see this where it says some 40% of companies surveyed said their response to COVID-19 as included cutting their cybersecurity budget in 50% said they would consider cutting staff. If cybersecurity could be maintained. Cutting, they cut it. They didn’t. They didn’t just they didn’t just say, Alright, we need to make sure we’re still doing the same thing. They cut it. And the problem with that is, you now have this population of employees that are working from home. And they are not cybersecurity aware. And that is opening up a whole new wormhole for your business. I’ve worked with a number of employers, businesses over the last now eight weeks to help secure it and I got to tell you some of the things I’ve seen from municipalities from small businesses from healthcare practices from law firms, it’s unreal, and you know that a lot of them are BYOD. So you’re working from home now you need to use your own device. to remote back into the office, they’ll set up Remote Desktop with no security at all use very simple password. They will make sure that you can still access your email but they’re not securing that you don’t turn on multi factor authentication. They’re not educating their people in phishing. They’re not doing anything to secure the business and secure in many cases secure client files and not spending on it is not the answer. That is the opposite of the answer. So I thought it was scary that you know 40% said they are they are cutting spending on cybersecurity during COVID-19. Hopefully that is not a trend going forward. But COVID-19 might be here for a little while. So who knows? All right, we’re gonna continue on our hip education. With a review of the technical Volume One cybersecurity practice for small healthcare organizations that was part of the 405 D project. And as the I never remember what h ICP stands for, but it’s it’s h ICP, also known as hiccup. That is part of the part of the it’s a plan to make sure that healthcare practices are more cyber secure. So we’re going to talk about today cybersecurity practice number four data protection and loss prevention. Let’s start with and again this is all this is all based off of the NIST cybersecurity framework. So that means if you’re familiar with the NIST cybersecurity framework, none of this should come as a surprise to you. But and apparently it does, because I see him care practices across the board USING IT support or other business associates what’s supposed to be business associates support, that are not familiar with this and are not using best practices. So let’s jump in here set the expectation for how your workforce is expected to manage the sensitive data at their fingertips. Most healthcare employees work with sensitive data on a daily basis very true. So it is easy to forget how important it is to remain vigilant about data protection. organizational policies should address all user interactions with sensitive data and reinforce the consequences of lost or compromised data. And so we just talked or we will talk about sorry about employees getting fired for viewing data that they shouldn’t be viewing towards it. A couple of those this week. Establish a data classification policy that categories data as for Israel, sample, sensitive internal use or public use identify the types of records relevant to each category. For example, this sensitive data category should include pH I social security numbers. And if you don’t know what pH is, its protected health information. credit card numbers and other information that must comply with regulations may be used to commit fraud, or may damage the organization’s reputation. And credit card numbers also fall into PCI By the way, so you need you need to look at both of those. So we have classification highly sensitive data that can be easily used to commit financial fraud or to cause significant damage to the organization’s reputation. Examples of such data for patients include social security numbers, credit card numbers, mental health information, substance abuse information and sexually transmitted infection information. access to these data should be restricted to users who require it and who demonstrate proper identification at login. Such data must be managed in compliance with applicable regulatory requirements. Sensitive All other pH I, especially data associated with the designated records, clinical research data, insurance information, human employee data, and organizational board materials. internal data that should be protected yet are not considered sensitive. Examples include organization policies and procedures, contracts, business plans, corporate strategy, and business development plans, internal business communications and in public all data that can be sanitized and approved for distribution to the public, with no restriction on use, prohibit the use of unencrypted storage such as thumb drives, mobile phones or computers require encryption of these mobile storage mediums before everything should be encrypted, not just mobile. Because there have been a few cases in the last few months of servers walking away and desktops walking away all these things walking away. The document references The different NIST framework as well when it comes to the different practices in this document, and we have use of classifications to establish data usage procedures identify, identify authorized users of sensitive data and the circumstances under which such data may be disclosed. So in other words, identify who’s allowed to access it and make sure they’re the only ones accessing it. Train your workforce to comply with organizational procedures and OMC guidance. When transmitting pH I through email, encrypt all pH I sent via email or text, however, patients can request and receive access to their HIV unencrypted electronic communication following a brief warning to the patient that unencrypted communication could be accessed by a third party in transit. And the patient confirms that they will still want to receive an unencrypted communication. So in other words, if you’re going to send an email, and that person is asking you to send it to their free gmail account or free Pop your email account there for let’s say Comcast since we’re talking about them earlier, you need to warn them of the risks because Comcast does not encrypt their email. When emailing pH I use a secure messaging application such as direct secure messaging, which is nationally adopted secure email protocol and network for transmitting pH I DSM can be obtained from EHR vendors and other health information exchange systems. It was developed and adopted through Meaningful Use program and many medical organizations nationwide. Now use DSM networks when you texting pH, I use a secure texting system. And there are quite a few secure test texting systems. But I would, to the point here use the one that your EHR provides if you’re going to use anything, not just a texting system, implement data loss prevention technologies to mitigate the risk of unauthorized access to pH I check with your IT provider to determine if this is feasible for your organization, or reference cybersecurity, practice number four Data Protection and prevention. So data loss prevention is having a disaster recovery, business continuity, disaster recovery system set up. And so the way we do it is we set it up where you have a local backup and then you have an off site backup done through the cloud. And if something goes down, you’re able to get back up virtually within minutes. train staff never to back up. data on control uncontrolled storage devices on Personal Cloud or Personal Cloud services. For example, do not permit employees to configure any workplace mobile device to backup to a personal computer unless the computer has been configured to comply with your organization’s encryption and data security standards. I saw this once where they employee installed their personal Dropbox account on the work computer. I don’t know how they how they were allowed to do that. And why would that wasn’t preventable, but they did and a place picked up on a security scan and the employee they didn’t I don’t know if there were ever recommend, I don’t know what the HR outcome was, but obviously, the Dropbox account was removed. And when they did find stuff in the Dropbox account that shouldn’t have been there. Not only that, but the employee had information in the Dropbox account that he probably did not want anybody else to see. Remember to protect archived data such as records for previous patients to to to it is important to monitor access to the data which may be used infrequently so that cyber attack is detected immediately ensure the absolute absolute absolute data removed or destroyed properly so they cannot be accessed by cyber thieves. Just as paper medical and financial records must be fully destroyed by shredding or burning. digital data must be properly disposed of to ensure that it cannot be inappropriately discovered, recovered sorry. Discuss options for properly disposing of outdated or unneeded data with your IT support. Do not assume that deleting or erasing files means the data are destroyed. And if not, by the way, it’s easily recoverable. Retain and maintain only data that your organization requires to complete work comply with record storage requirements minimize your organization’s risk by regularly removing unnecessary data. And so what are the threats mitigated by this ransomware loss of depth or equipment or data and accidental or unintentional data loss? So, data protection and that is a big part of HIPAA. Not just HIPAA, but healthcare in general healthcare IT protecting your patients information, your clients, those are your clients to protect their information. Right, it’s time for the HIPAA breach report. We have quite a bit of breach news not necessarily breaches but news to share shareholder suicide Last quarter to recover losses caused by data breaches a lab Corp shareholders taking legal action against labcorp. And its executives and directors over the loss in share value that was caused by two cyber attacks experienced by the company in the past 12 months. So you may recall those breaches from last year where labcorp was breached 10,251,784 patients and in companies like quest were were part of that. And so a lot of you know, obviously it was a big breach. labcorp was one of the companies worst affected by data breach at the medical debt collection company, American Medical medical collection agency AMC, so that was also quest was also part of that. They use labcorp services to infiltrate MCA systems and at least 24 of the MCs clients were affected by the breach a second labcorp data breach was reported by TechCrunch In January of this year that involved around 10,000 labcorp documents, which the lawsuit alleges was not publicly disclosed by the company nor mentioned in any SEC filings. The breach was the result of a website mis configuration and allowed the documents to be accessed by anyone. The breach was also not reported to the HHS Office of Civil Rights. Even though TechCrunch researchers confirm that the documents contain patient data. Ramin Eugenio holds shares in labcorp, which lost value as a result of the data breaches and filed a lawsuit on April 23. To recover those and other losses. The lawsuit names labcorp as the defendant along with 12 of the company’s executives and directors, including labcorp CIO Landsberg, Varian, CFO, Glen Eisenberg and actor I’m sorry director Adam shuck Schecter. The lawsuit alleges that prior to the AMC a breach and subsequently labcorp failed to implement appropriate cybersecurity procedures and did not have sufficient oversight of cybersecurity which directly resulted in the two data breaches in an S sec filing labcorp explained the AMC a data breach it costs the company $11.5 million in 2019 in response and remediation costs, but the lawsuit points out that the figure is just a fraction of the total losses and does not cover the costs of litigation default. Several class action lawsuits have been filed by victims of the AMC a data breach that name labcorp. So the total losses are not known to its shareholders and it probably won’t be known for years. Also lawsuit also states that the second breach has not been acknowledged, publicly or in any SEC filings as such Eugenio alleges lab corpse failed in its responsibility to its shareholders and breached its duties of loyalty care and good faith. The lawsuit alleges labcorp failed to implement effective internal policies, procedures and controls to protect patient information. There was insufficient oversight of compliance with federal and state regulations and its internal policies and procedures. labcorp did not have a sufficient data breach response plan in place pH I was provided to MCA without ensuring the company had sufficient cyber security controls in place. labcorp did not ensure that the individuals and entities affected by the breach were noticed, notified in a timely manner, and that the company did not make adequate public disclosures about the data breaches. The lawsuit seeks reimbursement for damages sustained as a result of the breaches and public acknowledgement of the January 2020. data breach. The lawsuit also calls for a reform of corporate governance and internal procedures and requires a board level committee to be set up for an an executive office or position appointed to ensure adequate oversight of data security. So we’ve talked about the hidden costs of of HIPAA breaches before obviously, this was a very large data breach last year, large HIPAA breach last year, but these are the hidden costs. So, you know, OCR hasn’t even I don’t know where they are in the investigation of this breach, and I’m sure there will be something type of settlement when all of a sudden done but did lawsuits and everything else that’s going to come from this are going to be probably far worse than the actual HIPAA breach. settlement. bjc healthcare has announced the email counts of three of its employees had been accessed by an unauthorized individual after the employees responded to phishing emails suspicious activity was detected in the email accounts on March 6, and accounts were immediately secured. A leading computer forensics firm was engaged to conduct an investigation which revealed the three accounts and only been accessed for a limited period of time on March 6, it was not possible to tell if the patient data was viewed or obtained by the attacker. review of the accounts revealed did contain the data of patients at 19, bjc and affiliated hospitals protected health information in emails and attachments vary from patient to patient and may have included the following data elements, patient names, medical record numbers, patient account numbers, dates of birth, limited treatment and or clinical information. which included provider names visit dates, medications diagnosis, testing information, the health insurance information, social security numbers, driver’s license numbers of certain patients were also potentially compromised. All patients affected by the breach will be notified by mail when the email account review is completed. So they did notify and exactly 60 days so good for them. However, three email breaches means no MFA, no training is occurring on a routine basis at bjc. And there is a list of 19 facilities here. Alton Memorial Hospital Barnes Jewish hospital, Barnes Jewish St. Peter’s hospital Barnes Jewish West County Hospital bjc behavioral health PGC in corporate health services bjc homecare bjc Medical Group boom Medical Group Poon Hospital Center, Christian hospital Memorial Hospital Daleville Memorial Hospital East Missouri Baptist Medical Center Missouri Baptist physician services LLC Missouri Baptist Solomon hospital, Parkland health center Boone tear Parkland Health Center at Farmington progress West hospital and Louis Children’s Hospital. Patients notified medical records expose this tornado hit secure medical record facility. We already talked about that. But again, just to review if you when you run your your security risk analysis, you need to consider all potential loss not just things that are common, like theft, but anything that could occur. And and Robert H Lurie Children’s Hospital of Chicago has terminated employee for improperly accessing the medical records of patients without authorization over a period of 15 months. The privacy violations were identified by the hospital on March 5. Employees access to hospital systems was immediately terminated while the investigation was conducted. After reviewing access logs, the hospital found that the employee had access to medical records of 4824 patients without authorization between November 2018 and February 2022. types of information access by the employee including names addresses, dates of birth diagnosis, information, medications, appointments, medical procedures no health insurance information, financial information or social security numbers where access. No reason was given as to why the medical records were access but the hospital says it does not believe the employee obtain misused or disclosing information to anyone else. hospital setting the employee no longer works at the hospital. This is not the first incident of its type to occur at Lurie Children’s Hospital. A similar incident was discovered in November 2018 when the hospital learned that a former employee access to medical records of patients without authorization between September 2018 and September 2019. So it sounds like they have an issue with access controls which we talked about in last week’s podcast so you know, mercy health and we talked about that breach earlier. Last when did it occur in March so we did talk about it a couple months ago. Mercy health fires nurse for multiple privacy violations. This one’s interesting mercy health has also recently taken action against an employee for alleged violations of HIPAA Privacy Rule. A nurse at hackley Hospital in Muskegon, Michigan was terminated on April 3 determination came shortly after the nurse raise concerns in media interviews about the level of preparedness of the hospital for the COVID-19 pandemic, and how the alleged lack of preparedness but put safety at risk. The nurse contacted the Michigan Nurses Association, labor union, which claimed at Mercy Mercy health fire the nurse for speaking out the labor union also filed a charge with the National Labor Relations Board. House termination came on the evening of April 3 days after he had publicly raised concerns about lack of appropriate PCP and the need for improved screening measures to keep nurses and healthcare workers safe during the COVID-19 pandemic. So the labor union in April 21 press release 10 days after the nurse was fired in one day after the press release was issued by the labor union. Mercy health released a press release of its own stating the nurse was fired for multiple violations of HIPAA rules. Mercy health said it does not usually share details about employment matters related to its workers but what’s compelling To speak out due to the misinformation campaign led by the labor union. Mercy health claims the fire nurse Justin Howe was terminated for accessing the medical records of multiple patients over a period of several days. The records were not were were not for patients receiving treatment at campus where the nurse worked and there was no legitimate work reason for accessing those records. Mercy health claims that how was not the only nurse terminated for improper medical record access according to mercy health press release. We have mechanisms in place to monitor for inappropriate access of privileged information. As part of this review process, Mr. Howe, along with the others were terminated for the same just investigative effort is still in process. So kind of interesting case. We’ll wait to see what comes with that. And then we have three more breaches that were reported early this morning. St. Francis healthcare partners in Connecticut is notifying 38,529 patients that some of their protected health information has potentially been obtained by hackers as a result of so instigated cybersecurity incident that allowed an unauthorized individual to gain access to its email system. The attack occurred on December 30, but it took until March 20. Further forensic investigation to determine that patient’s protected health information was potentially compromised. The types of information stored in the email system that could have been accessed included names, medical histories, medical record numbers, clinical and treatment information, dates of service diagnosis, health insurance or health insurance. provider names and count numbers prescription information in all types of procedures performed, no financial information or social security numbers were compromised. The investigation uncovered no evidence to suggest patient information was accessed stolen or misused. steps have now been taken to improve data security practices and all affected patients were have been notified by mail. There’s a few failures here one, obviously with this took more than 60 days to notify. Make your breach notification to sophistication it’s not a thing. phishing attacks are not so sophisticated. If you set up multi factor authentication, and you train your employees, then it’s not a sophisticated attack it can’t happen. The the the statement here is that a sophisticated cyber security incident that allowed an unauthorized individual to gain access to its email system tells me that somebody was fished. Florida internal medicine practice suffers ransomware attack Daniel Ben. Ben data what’s Md ffensive pa is notifying 3314 patients that the protected health information has been exposed as a result of a ransomware attack. The attack occurred on March 25 2020, resulting in the encryption of its computer systems including patient records backup files were not affected so files could be recovered without paying the ransom. And these types of ransomware attacks. files are not typically accessed by the attackers prior to file encryption. However, data access cannot be ruled out. So notification letters have been sent effective paid to affect a patient’s doctor Then debits explained in a breach notification letters that names addresses dates of birth, social security numbers, health insurance, information and medical information were potentially compromised. Either the abundance of caution identity theft protection services have been offered to all affected patients. steps have also been taken to improve security to prevent further attacks in in the future. So here’s a here’s the here’s the thing with this one. They say that in these types of ransomware attacks, files are not typically accessed That is incorrect. And that is a very poor assessment. Very poor statement. Because as we’ve seen multiple times now in the last few months, they’re stealing the files before they encrypt you. They’re spending time to peruse your network, so to speak in encrypting your files. Houston Methodist Hospital is notifying 1987 heart patients that some of their protected health information was stored on portable storage devices that were stolen from vehicle a vendor representative in mid February. The individual was employed by the medical device manufacturer and operated to 3d imaging technology in the hospitals cardiac cath third is Catherine ization lab. The hard drives were left in a vehicle from where they were stolen. The hospital reports that the room where the hard drives were stored, was locked in removal of the devices was against hospital protocol and violated established technical safeguards and contractual obligations. The representative believed the room was only locked due to the lead hour of the day. The hard drives contain medical images that included a patient’s name, gender, date of birth and code number. The images could only be viewed with specialist software that clinic reported the theft to law enforcement and hired a private investigator, but the hard drives could not be located. So means the hard drives were not encrypted. An email an employee of Ascension Eastwood clinic in Southfield Michigan sent an email to patients on April 15th. I’m just explaining the practice was transitioning to telehealth services due to COVID-19 to help prevent the spread of The disease in error was made sending email patients email addresses were not added to the BCC field of the email and could therefore be viewed by other patients. As a result of the error email addresses and in some cases, patients names were disclosed to other patients. Apart from allowing a patient to be identified as a patient of the clinic, no other information was exposed. The HHS Office of Civil Rights breach portal shows 999 patients were affected and that is going to do it for the HIPAA breach roundup and that is going to do it for this podcast. So until next week, stay healthy, stay safe and stay secure. Transcribed by https://otter.ai The post ProactiveIT Ep 28 – The Hidden Costs of Ransomware [https://nwajtech.com/proactiveit-ep-28-the-hidden-costs-of-ransomware/] appeared first on Nwaj Tech - Information Tech & Cloud Support [https://nwajtech.com].

8 mei 20201 h 3 min
aflevering ProactiveIT Ep 27 – No One is Safe From Ransomware artwork

ProactiveIT Ep 27 – No One is Safe From Ransomware

THIS IS THE PROACTIVEIT PODCAST.  THIS WEEK: THE LATEST IN IT AND CYBER SECURITY NEWS PLUS A ROUGH WEEK FOR WORDPRESS, NO ONE IS SAFE FROM RANSOMWARE & ACCESS MANAGEMENT FOR HEALTHCARE This is Episode 27! INTRO Hi Everyone and welcome to the Proactive IT Podcast.  Each week we talk about the latest in tech and cyber news, compliance, and more.  We also bring you real-world examples to learn from so that you can better protect your business and identity. This podcast is brought to you by Nwaj Tech – a client-focused & security-minded IT Consultant located in Central Connecticut.  You can find us at nwajtech.com. Thanks for listening to this podcast.  Show us some love on Apple or Google Podcasts.  Subscribe and leave us some positive feedback.  What are you waiting for? Also, go join the Get HIPAA Compliance Facebook Group.  Search for Get HIPAA Compliance PATCH TUESDAY UPDATE: Chrome 81 Released With 32 Security Fixes and Web NFC API [https://www.bleepingcomputer.com/news/google/chrome-81-released-with-32-security-fixes-and-web-nfc-api/]Firefox 75 released with Windows 10 performance improvements [https://www.bleepingcomputer.com/news/software/firefox-75-released-with-windows-10-performance-improvements/]Juniper Networks Releases Security Updates [https://www.us-cert.gov/ncas/current-activity/2020/04/09/juniper-networks-releases-security-updates]Microsoft releases April 2020 Office updates with crash fixes [https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-april-2020-office-updates-with-crash-fixes/]Hackers Can Compromise VMware vCenter Server Via Newly Patched Flaw [https://www.securityweek.com/hackers-can-compromise-vmware-vcenter-server-newly-patched-flaw?&web_view=true]Oracle Tackles a Massive 405 Bugs for Its April Quarterly Patch Update [https://threatpost.com/oracle-tackles-405-bugs-for-april-quarterly-patch-update/154737/]Microsoft April 2020 Patch Tuesday fixes 3 zero-days, 15 critical flaws [https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2020-patch-tuesday-fixes-3-zero-days-15-critical-flaws/]Intel April Platform Update fixes high severity security issues [https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/]Apple Releases Security Update for Xcode [https://www.us-cert.gov/ncas/current-activity/2020/04/17/apple-releases-security-update-xcode]More Updates [https://www.us-cert.gov/ncas/current-activity]Apple Patches Two iOS Zero-Days Abused for Years [https://threatpost.com/apple-patches-two-ios-zero-days-abused-for-years/155042/] New This Week [https://threatpost.com/apple-patches-two-ios-zero-days-abused-for-years/155042/]Critical Security Patches Released for Magento, Adobe Illustrator and Bridge [https://thehackernews.com/2020/04/adobe-software-updates.html]A few updates are available.  Samba, Google Chrome and Juniper [https://www.us-cert.gov/ncas/current-activity]VMware Releases Security Updates for ESXi [https://www.us-cert.gov/ncas/current-activity/2020/04/29/vmware-releases-security-updates-esxi]High-Severity Cisco IOS XE Flaw Threatens SD-WAN Routers [https://threatpost.com/cisco-ios-xe-flaw-sd-wan-routers/155319/] CYBER SECURITY NEWS Hackers are exploiting a Sophos firewall zero-day [https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/?&web_view=true] Contact tracing apps unsafe if Bluetooth vulnerabilities not fixed [https://www.zdnet.com/article/contact-tracing-apps-unsafe-if-bluetooth-vulnerabilities-not-fixed/?&web_view=true] 5 common mistakes that lead to ransomware [https://nakedsecurity.sophos.com/2020/04/27/5-common-mistakes-that-lead-to-ransomware/] Microsoft Teams patched against image-based account takeover [https://www.bleepingcomputer.com/news/security/microsoft-teams-patched-against-image-based-account-takeover/] Biopharmaceutical Firm Suffers Ransomware Attack, Data Dump [https://www.darkreading.com/attacks-breaches/biopharmaceutical-firm-suffers-ransomware-attack-data-dump/d/d-id/1337673?&web_view=true] Millions of Brute-Force Attacks Hit Remote Desktop Accounts [https://threatpost.com/millions-brute-force-attacks-rdp/155324/] Smart Parking Meter Company Hit by Sodinokibi [https://hotforsecurity.bitdefender.com/blog/smart-parking-meter-company-hit-by-sodinokibi-23114.html?web_view=true] Unpacking The 7 Vulnerabilities Fixed in Today’s WordPress 5.4.1 Security Update [https://www.wordfence.com/blog/2020/04/unpacking-the-7-vulnerabilities-fixed-in-todays-wordpress-5-4-1-security-update/?utm_campaign=Wordfence%20Blog%20Emails&utm_source=hs_email&utm_medium=email&utm_content=87192878&_hsenc=p2ANqtz-_KoDu8ruELhyxBJ-PnCA8RKjfQhBcscr3vPCt3HYi7PfVLfp0z8OvOQyVAm1sEll-d4KKK2t6X5U4EiczXI6qwkHqMRw&_hsmi=87192878] Topic 1: Ransomware attacks against key sectors fall amidst coronavirus outbreak [https://www.techrepublic.com/article/ransomware-attacks-against-key-sectors-fall-amidst-coronavirus-outbreak/?&web_view=true] Topic 2: [https://threatpost.com/beyond-zoom-safe-slack-collaboration-apps/154446/]March 2020 Healthcare Data Breach Report [https://www.hipaajournal.com/march-2020-healthcare-data-breach-report/] Topic 3: Average Ransomware Payments Soared in the First Quarter [https://www.darkreading.com/attacks-breaches/average-ransomware-payments-soared-in-the-first-quarter/d/d-id/1337695?&web_view=true] HIPAA CORNER: https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf [https://www.phe.gov/Preparedness/planning/405d/Documents/tech-vol1-508.pdf] BREACHES https://www.hipaajournal.com/category/hipaa-breach-news/ [https://www.hipaajournal.com/category/hipaa-breach-news/] ProactiveIT Podcast Ep 27 No One is Safe from Ransomware & Access Management for Healthcare PIN [https://nwajtech.com/wp-content/uploads/2020/05/ProactiveIT-Podcast-Ep-27-No-One-is-Safe-from-Ransomware-Access-Management-for-Healthcare-PIN-683x1024.jpg] Transcription (Unedited) This is the prodactive IT podcast this week the latest in it in cybersecurity news plus a rough week for WordPress. No one is safe from ransomware and access management for health care. This is Episode 27 Hi everyone and welcome to the productive it podcast each week we talk about the latest in tech and cyber news compliance and more. We also bring your real world examples to learn from so that you can better protect your business and your identity. This podcast is brought to you by wash tech a client focused and security minded IT consultant Located in Central Connecticut, you can find a set and watch check calm, that’s NWA j tech.com. All right. First of all, thank you for listening to this podcast. Once again. Wherever you’re listening to this, if you could please like, share, comment, review. All of the above. Anything you could do would be greatly appreciated. And we would listen to virtual hugs about that. And if you’re in a HIPAA compliant business, please go to Facebook and in a search type in get HIPAA compliance and join that group where we share lots of HIPAA information that will help your healthcare practice or your business associate. Remain in the HIPAA green. How about that? We don’t have a question of the week. I was sent a few questions in but they’re mostly around zoom and Google Classroom, things like that. I think we’ve talked enough about zoom. So we’re not going to discuss that here. Here, I will say that Google has launched Google meets, which is supposed to be, it’s really just Google Hangouts rebranded, but they’re trying to compete with zoom, of course, and Facebook is launching, through Facebook Messenger, they’re launching a similar service. So be on the lookout for those. And, you know, use whatever you think is appropriate for your business. But just know that zoom has fixed most of the issues. I think all of the issues at this point. There were a few updates that we need to talk about. So we’re just going to add to the April update, I know today’s may 1. Happy May, happy May Day, but there were some updates to discuss. So first of all, critical security patches released from Magento, Adobe Magento, Adobe Illustrator and Adobe Bridge. You’ll need to take care of those. They are critical severities there was a bunch of work Press updates this week. We’re going to talk about some of them on this podcast today. But WordPress core WordPress core files were updated to 5.4 point one and they will adjust seven different vulnerabilities that we’re going to talk about later in this podcast. There were also updates from Cisco to address, iOS xe SD win solution software. There was updates from VMware for security updates for ESXi. Samba released some security updates, Google released another update to Google Chrome so should be on at 1.0 point 404 4.1 to nine. That is to address some security vulnerabilities. Juniper released updates, open SSL not echoes back last week. Okay, so Juniper released updates. We told you about VMware ESXi. Yes, x i. And we told you about Cisco, so Lots of updates again this week, that is a big list of updates for the month of April. And so I will include the entire list in the show notes. If you need to apply those updates, please take care of it, because you’re leaving yourself exposed. And if you were using WordPress, if you have any plugins that were probably five or six this week to add to have a lot of installs with critical vulnerabilities that had patches including a theme that is no longer supported. So get it updated. And if this theme is no longer supported, then remove it, replace it because you’re leaving your website exposed. Okay. All right. Let’s talk some news here. First up on Zd net hackers are exploiting a Sophos firewall zero day so Speaking of updates, so force releases emergency patch to fix SQL injection bug is bloated in the wild impacting its x GE firewall. product. cybersecurity from so forth has published an emergency security update on Saturday to patch zero day vulnerability. And it’s x g enterprise firewall product that was being abused in the wild by hackers. So first heard its first learned of the zero day I went late Wednesday, April 22. After received the report from one of its customers. The customer report is seeing a suspicious field value visible in the management interface after investigating reports so foes determined that this was an act of attack and not an error in its project. The attack used a previously unknown SQL injection vulnerability to gain access to expose the x g devices. So for certain a security advisory, hackers targeted so for 60 firewall devices that had their administrators HTTPS service or the user portal Control Panel exposed to the internet. So for Cid, to hackers, Use the SQL injection vulnerability to download a payload on the device display a little den store files from the firewall. Stolen data could include usernames and hash passwords for the firewall device admin. For the firewall portal admins and user accounts used for remote access to the device. It also included the firewalls license and serial number and user emails. So posted that so you can expect phishing attacks by the way. So posted that passwords for customers, other external authentication systems, such as ad or LDAP, were unaffected. So that’s good news. The company said that, during its investigation, it did not find any evidence that hackers used a stolen passwords to access extra firewall devices, or anything beyond the firewall on its customers internal networks. So false researchers named the malware asking iraq a detailed step by step analysis as a malware as features and modus operandi was published and it’s linked on the Sophos website and then there is the aim a infographic here of of what Sophos published the patch already pushed to customer devices UK company famed for its antivirus product said it prepared and already pushed an automated automatic update to patch all extra firewalls that have the auto update feature enabled this hotfix eliminated SQL injection vulnerability which prevented further exploitation stop the extra firewall from accessing any attacker infrastructure and cleaned up any remnants from the attack asset. So that has been taken care of by Sophos to good job there. For companies that had devices hacked. So forces recommending a series of steps which include password resets, I would reset your password either way, and device reboots, reset portal administrator and device administrator accounts reboot extra device reset password for all local user accounts and all those passwords were hash it is recommended passwords are reset for any accounts where the extra credentials might have been used reuse. So, in other words, even though it’s hashed, the hash may already have been cracked and is sitting on a dark web form somewhere. So change your password. Also on Zd net contact tracing apps on safe if Bluetooth vulnerabilities not fixed. So we’ve been talking about contract test tracing apps for COVID-19. Right. So essentially, it’s an app in Google and Google and Apple have both said that they will include an operating system update down the road few months down the road. Your issues with there’s concerns that Bluetooth is not stable enough to handle something like this. So with governments increasingly looking into looking to use contact tracing apps to help contain COVID-19 such initiatives are likely to spark renewed interest in Bluetooth attacks, which means there is a need for assurance that these apps are regularly tested and vulnerabilities patched. As more governments turn to contact tracing apps to aid in their efforts to continue to Corona virus outbreak, cybersecurity experts are warning this may spark renewed interest in Bluetooth attacks. They urge developers to ensure such apps are regularly tested for vulnerabilities and release patches swiftly to flow potential holes while governments should provide assurance that their databases are secure and the data collected will not be used for purposes other than as originally intended. So, I, you know, when I first read about this, the potential of this happening, I did of course, express my concerns. You know, there’s there’s a track record that anytime apps are developed to hold sensitive information, that sensitive information gets exposed. So there’s there is concern of course that using Bluetooth which has been compromised before refer to Blue snarfing and think it’s blue jacking was the other other thing but you you’ve heard of these things before, we’ve all heard of Bluetooth being and we all know that. Be careful of where we have Bluetooth turned on and what’s near us and what what’s shareable and so forth. Well, this is another thing that that scares people. Right? And I did see another document somewhere or another article that said only about half of of people polled would be for using this type of technology. And I can understand a concern to completely understand a concern. So something to think about naked security by Sophos five common mistakes that lead to ransomware ransomware is down so far this year. That’s the good news. The bad news is it probably will not. That is not a trend that will continue. I’m sure it will pick up again, a lot of the focus right now is on COVID-19. There’s there may have been ransomware attacks. There’s there’s a lot of reasons why ransomware could be down right now. One is, you know, some of them promised not to hit healthcare during this, this pandemic. Another one is a lot of businesses are shut down right now. So they may have ransomware sitting in their environment and not even know it. It’s a little bit harder to get into To an enterprise environment right now, if people are working from home, though not completely impossible. So there’s a lot of a lot of variables there. So but here’s what you can do to protect your business from ransomware. If the first one, this is again on naked security by Sophos protect your system portals, this is what happened with target. And now that a third party vendor was involved, but this is exactly what happened with target. Crooks often sneak in by looking for remote access portals such as RDP and SSH, that aren’t properly secured, perhaps because they were set up temporarily but then forgotten about, learn how to scan your own network from the outside and make sure that there are services that are open are in and listening for connections are supposed to be there and that they’re on regular security checklist. So in other words, if you have telnet, open close it because nobody uses telnet anymore, and I should should clarify my statement. So the target hack was a few years ago. 2015 if I’m not mistake And I could be wrong. But third party, a third party company was compromised. And then that leaked to a hack of a portal that they use for target. And then the hackers got into the target internal system. Now it’s not the third, not entirely the third party vendors fault. It’s probably more target’s fault than the third party vendor. But that’s how they got into a portal. Number two, pick proper passwords. We’ve talked about passwords, we’ve talked about passwords, strong passwords, means uppercase, lowercase numbers and special characters. And the longer the better. Use a password manager. Don’t reuse passwords. And I’m not sure if it’s here, but use multi factor authentication. It’s not here, but use multi factor authentication, wherever possible, wherever possible. I don’t care what it is. It is here I’m sorry, two factor authentication. Use it on your email, use it on your social media. Use it on Your portals, whatever they are, whatever, whether it’s a CRM or a payroll portal or whatever it is, use it. Number three, peruse your system logs. And this is one that’s overlooked a lot. many if not most, ransomware attacks don’t happen instantly or without warning to crooks usually take some time, often days and sometimes longer to get a picture of your entire network first. That’s how they make sure when they finally pull the trigger that initiates the attacks, they will get this destructive result they want for the ransom they planted demand. So there will often be numerous telltale signs in your logs such as appearance of gray hat hacking tools that you wouldn’t expect your own users to need or use sysadmin operations such as creating new accounts that happen unusual times, and network connections from outside that don’t follow your usual pattern. The Sophos managed threat response team can help you here of course, this is an ad, but you know you have some some logs out there where They collect logs from the network and you’d look for certain types of activity and then review it and act on it as you feel necessary. Pay attention to warnings and that’s number four. If you’re if you’ve set up alerting system to shout out, shout you all the time, you will almost certainly end up with alert fatigue. This is a very real thing if you get 100 alerts, and 98 of them are just a waste of time, you need to adjust your alerting to remove those 98. But be careful not to assume that otherwise interesting warnings can be ignored if they mentioned a potential threat was already blocked. Often threats that pop up on your network aren’t just chance events. They’re evidence that cooks are already poking around cautiously to see which action set off what alarms in the hope of pulling off a much bigger attack later on. And number five patch early and patch often don’t leave yourself exposed to potential holes for longer than necessary. So as a rule, we test patching As soon as it rolls out, especially for operating systems, soon as it rolls out and apply it when we think it’s safe, but usually by the end of the same week that the patches came out so it comes out on a Tuesday. By the weekend it’s patched and on all of client machines. Some things like browsers are updated immediately. In a malware, what we use is updated automatically. Things like that get taken care of as quickly as possible. bleeping computer reports Microsoft Teams patch against image here’s another update image based account takeover. After looking at how Microsoft Teams handles image resources, security, researchers found a way to take over accounts by sending recipients a regular gift. The method could have been used for desktop and web versions of teams to get access to multiple accounts at once and still conversations and threads controlling a subdomain under teams. microsoft.microsoft.com was the main condition for the attack and researchers To to choose from Microsoft received a report about the vulnerability and push mitigations to prevent the attack. So Microsoft had a vulnerability with teams that could have been compromised with a just by sending a gift. It’s been addressed no longer an issue on dark reading comm we’ve we’ve actually talked about this a few times this week. So executive farm, which is a pharmaceutical clinical research organization was hit with a ransomware attack. This article that I have here that we’ll link to, was the first of three that I’ve reviewed. The data that was compromised was personally identifiable information and potentially pH I for for executive farm and also for business partner. PAREXEL. It turns out it was the clop ransomware group and they stole data quite a bit of data actually. And have now posted it on the dark web. Because executive forum is has not paid the ransom, no clue what the ransom amount is. This is a HIPAA violation, HIPAA breach, by the way, and it is a data breach. So make make no mistakes here. They exfiltrated the data that makes it a data breach. So they have the data, they posted it on the dark web. exec form is not playing nice. They’re not, you know, no idea how much the ransom request is no idea how it happened or anything. So there will be more information to follow on this. But he up we’re seeing more and more of this and it was actually three We’ll talk about it later in the show but three healthcare breaches resulting from ransomware. Just yesterday they were reported. Threat Post reports millions of brute force attacks hit Remote Desktop accounts so remote, brute force attacks. have increased dramatically against Remote Desktop. Automated attacks on remote, remote desktop protocol accounts are aimed at taking over corporate desktops and infiltrating networks. So Remote Desktop if you’re not familiar with remote desktop protocol, is Microsoft’s way of being able to connect back to a nother Windows machine in another location. And if set up properly, it’s fairly secure. In other words, it should be done over VPN and strong passwords and multi factor authentication and so forth. But what happens is most people don’t do those things. And I just I personally personally witnessed a municipality here in Connecticut that’s not doing it a rather large municipality municipality at that. So there has been a rash of brute forcing attempts aimed at uses a Microsoft proprietary Remote Desktop protocol and striking millions per week. So That’s a lot. attacks are likely offshoot of cyber criminals looking to take advantage of the unprecedented numbers of employees working from home. So more people are working from home. More people are probably using remote desktop. And here’s what they do. They have lists of usernames and passwords. They drop them into a script, the script runs automatically in the attempt to brute force. How do they know where to go? They look for open port 3389 by using n map or something similar to scan. And if you’re if, if it’s 3389 is open. Now they’ve dropped they run the script. It’s really not that complicated. It’s really that easy script that you can get easily on the internet. On hop for security by bitdefender smart parking meter company, it was sold on eBay and I thought this was interesting and it’s part of the title for the podcast today. You know the part that says no one is safe from ransomware So here we are, we have parking meters that were hit with a ransomware attack company named civic smart from Milwaukee. That selling smart parking meters was hit by Soto Nokia ransomware. And Soto KB is one of those ones that will exfiltrate your data and then put it on the internet for the whole world to see if you don’t pay your ransom and the attackers managed to steal a large amount of data, which they don’t use for further leverage. These days, it seems that the most effective industries have something to do with the Coronavirus when it comes to cyber attacks, healthcare organizations are getting it left and right, even if they are working on possible vaccine against the virus. Unfortunately, bad actors don’t stop even in these troubling times and will use any weakness they find in a system to civic smart attack was perpetrated was soda leukemia ransomware and follow the extraction of 159 gigabytes of data. So there is a lot of a lot of data. Usually this kind of action comes from the attackers using maze which we know is not true anymore. There’s probably six or seven rants Somewhere operators that are using this method No, but it looks like it’s now being employed by other groups as well. According to scoop news report, the attack took place back in March, but the company remains silent and chose to pay the ransom and retrieve the files. So that makes it a data breach by the way. According to initial reports, the leaked data included employee records, bank statements, credit card numbers of customers and even contracts with cities and parking garage vendors. smart parking system is a great idea, and it’s used in many cities from around the world. But like any other service that deals with credit card payments and other sensitive data, security must never be in second place. to new strategy used by attackers. To steal data from affected systems seems to be used more widely in the past few months and it’s slowly becoming the new norm in cyber attacks. The other problem is that the company didn’t say anything about the attack and data leak even after it presumably paid to hackers just means that people’s financial personal data were compromised, but they have no idea about it, leaving them exposed to fraud and other hacks. So what should be happening is you should be getting credit monitoring services should have been notified. And this is why, you know, I know, regulation is, in a lot in a lot of ways sucks, but we need an national federal level data protection plan like the GDPR and the ccpa. Not all states. In fact, most states in the United States do not have something like ccpa, California, California and New York to and a couple other states do. Most states do not I don’t know if Milwaukee does or not, I don’t believe they do. But that’s, you know, that’s why we need it. And then finally, we talked a little bit about the word WordPress update to 5.4 point one. So if you’re using WordPress, which I believe roughly 40% of all websites are now WordPress, you should be on version 5.4 point one And here are some of the security issues password reset tokens fail to be properly invalidated if a password reset was requested for a user, but they then logged in and manually updated the password on the profile page, the email password reset link could still be used. Previously, the password reset link would only be valid invalidated if the user change their email address. There’s not many circumstances in which this type of issue could be problematic unless an attacker already had access to the victim’s email account, which would effectively be a worst case scenario. And that would be pretty bad if you did. Certain private hosts can be viewed by unauthenticated users just changed set had the following comment query ensure that only a single post can be returned on date time based queries. This indicates that it was possible for an attacker to view private post by using date and time based queries, though only for protected posts that were created or updated by the exact same time down to the second end, as an unprotected post. The two cross site scripting issues. In the customizer, these vulnerabilities appear to allow for corruption of post content by various users and could allow for the addition of malicious JavaScript by an automatic by an authenticated attacker with contributor capabilities. A user with the ability to write posts such as contributor or an author, without the unfiltered underscore HTML capability, and an administrator or editor could corrupt data from each other’s traps potentially adding malicious JavaScript to a preview or final version of a post cross site scripting issue in the search block this actually appears to refer to two separate vulnerabilities with the same mechanism in both the RSS block in the search block and attacker with the ability to customize the class of either of these blocks, such as a contributor could potentially set the block class in such a way that the malicious JavaScript would be executed when viewing or previewing the post. cross site scripting issue in WP object cache Object caches used to save trips to the database by caching content from the database and making the dash. I’m sorry, the cache contents available by using a key, which is used to name and later retrieve the cache contents. In a few edge cases, an attacker with the ability to change object cache keys might be able to set one of these cache keys to malicious JavaScript. By default, WordPress does not display the stats nor does it allow users to directly manipulate cache keys. It is impossible it is possible that an improperly program plugin or combination of plugins could allow an attacker to manipulate a cache key result a non escaped value being displayed to an administrator viewing the stats via a plugin or custom code designed to display them. cross site scripting issue and file uploads a particular vulnerability could allow a user with the upload underscore files capability authors and above and a default installation to upload a file with the file name set to malicious JavaScript which might be executed when viewing the file. The Media Gallery and authenticated cross site scripting issue in the block editor. This vulnerability existed in a few of the release candidates and does not appear to have been present in the official release. It was discovered by noggin or guy in the duck and WordPress 5.4. release candidate one and release candidate two and it was fixed in 5.4. release candidate five. So those are your seven vulnerabilities that were addressed. Six of them being cross site scripting issues. update to WordPress 5.4 point one. It is not easy to find websites that are not on the latest version. If you’re not you’re you’re putting yourself in your website at risk. right we’re gonna talk some numbers now for hot topics for the week. The first one I’ve kind of touched already touched on it a couple times in this podcast. ransomware attacks against key sectors fall and midst Coronavirus outbreak. This is on tech republic.com campaigns against government agencies educational establishments, and healthcare providers aren’t proving as successful as expected says security firm MC soft cyber criminals who deploy ransomware are always on the hunt for new victims. That’s true even during a time of crisis such as the Coronavirus pandemic. Those summaries more games have vowed to hold off on attacks against hospitals and healthcare providers as the world bad as battles COVID-19 others are still trying to make a profit out of the potential any potential victim. But as the virus has spread, the number of successful ransomware attacks against certain sectors has actually declined according to a blog post published Thursday by MC soft in 2018 966. Government agencies, educational establishments and healthcare providers in the US were hit by ransomware projections call for the same or worse numbers for 2020. But for the first quarter of the year, only 89 such organizations were affected by ransomware. So you’re looking at a 270, which is a significant drop off. If that play I’m sorry, not 270 would be 360. So that’s a little more than a third of what it was last year. However, as you’ll hear, that probably will not remain reducing the number to a level not seen in several years, drilling down on the results of ransomware attacks during the first quarter hit 38 government agencies 26 educational establishments, and 25 healthcare providers. So now here’s the thing. A lot of government agencies are that are considered not essential or shut down right now. All the schools are remote at this point. So there’s some in some of them are closed. And then healthcare providers, you know, some of the ransomware operators have promised not to hit them. I don’t believe that that’s going to be the case but That’s what they promise. This decline has continued into the start of the second quarter with three government agencies to educational facilities and to healthcare providers victimized by ransomware. Now we just learned about three more healthcare providers a couple days ago. So whether or not the overall number of ransomware attack campaigns has fallen. Why is the level of successful tax against the three mentioned sectors declined MC sauce points to a few factors. First, many government educational healthcare organizations have suspended non essential services during the Coronavirus outbreak leaving a smaller attack area for ransom. Second, while people working from home maybe new target they also represent different challenges for ransomware attackers. Just criminal groups are limited by available personnel and resources and can’t always modify their operations as quickly as desired. And third, many organizations are suffering financially as a result of COVID-19 outbreak. As such, they simply can’t afford to pay huge sums of money to attackers demanding a ransom note posted released recently on its website. ransomware groups said we’re living in the same economic reality as you are. That’s why we prefer to work under the arrangements and we are ready for compromise. Though the number of successful ransomware attacks in the public sector has fallen attacks against private sector have remained at around the same level during the Coronavirus outbreak further when even the client against government schools and health care providers is likely temporary, and MC soft believes the level of attacks will ramp up as the year progresses. The government should as noted in a 2019 report seek to bolster security in these sectors and should do as do so as a matter of urgency MC said in a blog post this is critical given that COVID-19 pandemic could amplify existing security risks around the upcoming election, especially as some states have reallocated elections security budgets to fund efforts related to COVID-19. So it is an interesting warning. And I think it’s a legitimate warning. I don’t think this is going to be the trend for the whole year. We’re going To see a jump when when a the ransomware groups figure out how to get around with the work from home and into the enterprise environments and into the healthcare environments and the government agencies and in the schools and so forth. And the schools are changing a lot right now. So that’s that’s likely to leave vulnerabilities. And the other piece of that pie is, we don’t know. There may be ransomware, sitting waiting anywhere. And so they’re changing their mode. And the interesting thing is the flip side of this is that malware has been reported as 30 up an increase of 30,000%. A lot of times that malware will lead to a ransomware attack. Phishing has seen an 85% increase since the beginning of the year. So phishing as we know 90% of phishing leads there to ransomware or 90% of ransom. Attacks begin with phishing. So it’s not that it’s not happening, it will happen. So don’t let your guards down don’t become the next victim simply because you think ransomware attackers have given up to have it. Now let’s talk about the bad side of the ransomware story for 2020. So far, this is on dark reading calm, average. ransomware. Payments soared in the first quarter. Criminals extorting large amounts of money from big enterprises pulled up the overall average significantly compare with the fourth quarter of 2019 Cove where says the ransomware economy continues to boom even as COVID-19 pandemic wreaks havoc on businesses around the world. new data from co were on ransomware attacks on the first quarter of this year showed that compared with the fourth quarter of 2019, medium ransomware payments held relatively steady at around 44,000. But average payments soared 33% to $111,605. Are you prepared to pay $111,000 to someone because You didn’t secure your system, you know, how much salary is that right there and then to, you know, then there’s other fallouts after the fact now it’s a data breach potentially, and lawsuits and whatever else exists out there. The increase in average amounts of insurance By the way, increasing average amounts reflected to significantly bigger ransom payments that large enterprises paid last quarter to get their data back. Compared with smaller medium sized businesses. This year’s first quarter marks the seventh straight quarter, the average payments have increased as recently as the first quarter of 2019. The average ransom payment cohort study was just $12,762 or less than a 10th of the current average. So you can see a big increase over the last year ransomware as an economics driven industry says bill Segal, CEO and co founder of CO where right now the economics are very favorable favorable to cyber criminals. coworkers, data shows that ransomware attacks increased across the board. Last quarter as threat actors took advantage of the pandemic and resulting economic disruption to go after businesses. The attacks resulted in downtime of around 15 days on average for victims down marginally from the previous quarter. But still disturbingly high. Kovar said many of the attacks involve data exfiltration as well and that’s where you get yourself into trouble. phishing emails are often perceived to be the most favored mechanism for attackers to drop ransomware but insecure Remote Desktop protocol. access points, which are available in dark markets for as little as $20 are even more popular and continued to represent the most common ransomware attack vector last quarter, combined with cheaper ransomware kits. The cost to carry out attacks on machines with open RDP or to economically route lucrative for criminals to resist cool were set. Now just we just told you that RDP There are over a million brute force attempts on RDP per week right now, as in previous quarter small professional services firms such as law firms managed service providers and accounting firms were the most heavily targeted and accounted for nearly 20% of all ransomware attacks that Coover account encountered in this year’s first quarter. public sector entities including schools and local governments and other top ransomware. Target and previous quarters attracted a lot of attention in the first quarter of 2020 as well but in break from pattern almost 50% of ransomware attacks on this cat category were directed at schools. According to co where ransomware have served purveyors typically have tended to tech schools and summer to increase the chances of getting victims to pay up before schools reopen uncharacteristic volume of attacks against school districts. In the first quarter suggests that threat actors were trying to take advantage of the hasty move to distance learning to schools had to implement in response to COVID-19. co where said even as some of the threat actors stop targeting healthcare as others continued going after them making healthcare the second most heavily targeted sector with after professional services firms. The payment payoff, security experts have strongly advocated against organizations paying a ransom to get back access to their encrypted data, and systems. Many believe that ransom payments only encouraged more attacks and more threat actors. In fact, the only reason an organization would even consider paying a ransom is if the business would fail, or falter. If it doesn’t says evil. It is the option of last resort only Siegel says only if your business is at risk of permanent damage because the data loss will be so severe should a ransom be considered. He says, Cove wears data suggests that when organizations do end up exceeding a seeding to ransom demand, their chances of good outcome remain fairly high. 99% of businesses that paid a ransom last quarter got a working decryption key for unlocking their data the average data recovery with these keys itself though dropped or dip modestly to 96% in the first quarter of 2020. Compared with 97% in the prior quarter, so in other words, you have a 96% chance of getting your data back if you pay the ransom, cool were found that enterprises stood a better chance of recovering your data when dealing with the operators of some of the top ransomware. Families such as Rioch, Soto leukemia and Phobos. The operators of these families, particularly ryokan Soto kV have attended have tended to target larger organizations. At the other end of the spectrum, some ransomware variants such as Miss Spinoza, and death hidden tier cause data loss when encrypting data and had decryption keys that were buggy as well. So, of course, these the larger ransomware families will give you the data back because if they don’t, then the next the next enterprise environment that they hit isn’t going to pay the ransom because why would they want you’re not going to give the data back don’t pay the ransom. But as it says in the article is strongly discouraged, because it does paint a bigger target. on you. It’s interesting. There’s some contradicting information here that says, you know, health care and schools were targeted heavily again in the first quarter, but then we just read in a previous article that that they were down significantly so not sure where the data comes from, but there you have it. We do have the march 2020 breach, HIPAA breach report. So the numbers for March, not great. March 2020. Saw 7.69% month over month decrease in a number of reported healthcare data breaches, and a 45.8% reduction in the number of breached records. But that’s from February, when February was one and a half million records breached. Now the number of data breaches of 500 or more, was 36 for the month of March, which is average for the year so far. We had 39 February 33 and January. A little bit lower than 2019 for the most Part. Only a couple of months were lower, lower than that. There was 128,921 Records breached and we have the top 10 breaches, nine of them were hacking or an IT incident. All were healthcare providers except for one one business, or I’m sorry, there was two business associates in the top 10, Stephen c Dean, and one digital health and benefits. The one digital health and benefits was a theft. I’m not sure. I don’t recall seeing that breach reported. So I’m not sure what the theft was, but I’d have to guess, a laptop or some unencrypted device. Remember, if your device is encrypted, it does not count as a HIPAA breach if it’s stolen or lost. But if it’s not encrypted, then it becomes a HIPAA breach, and you have to report it. So the number one breach was ambry genetics Corporation a health care provider 232,772 in individual records all the way down to number 10 Washington University School of Medicine which is also a healthcare provider 14,795 causes of March 2020 healthcare data breaches unauthorized access or disclosure was nine theft six lost to hacking it incident 19 and this should come as no surprise but again here we go location a breach of pH I other was one I’m not sure what that means. Other portable electronic device which could have been the stolen device is to electronic medical records to desktop computer could have also been stolen three email 18 network server nine paper films for and laptops three and again, that could have been the stolen device 18 for email again, I think it was almost 40% of all the breaches. The SCADA like I don’t just don’t understand why we’re not taking care of it. We’re not taking care of it though. It’s not happening. We continue to see phishing attacks succeed time and time again. The breaches by covered entity types so we have 26 healthcare providers, six business associates, which seems to be growing three health care plans in one healthcare clearing house. So business associates are outpacing healthcare plans and clearing houses combined. So six business associates health plan and healthcare Clearing House combined as for the OCR did say it would be increased enforcement against business associates. Now that was before the COVID-19 pandemic. So whenever things do settle down, you can expect to see some enforcement. Transcribed by https://otter.ai The post ProactiveIT Ep 27 – No One is Safe From Ransomware [https://nwajtech.com/proactiveit-ep-27-no-one-is-safe-from-ransomware/] appeared first on Nwaj Tech - Information Tech & Cloud Support [https://nwajtech.com].

1 mei 202057 min
aflevering ProactiveIT Ep 26 – Is Ransomware a Data Breach? artwork

ProactiveIT Ep 26 – Is Ransomware a Data Breach?

THIS IS THE PROACTIVEIT PODCAST.  THIS WEEK: THE LATEST IN IT AND CYBER SECURITY NEWS PLUS MORE UPDATES AND WARNINGS, GOOGLE & FITBIT BECOMING MORE INVOLVED WITH PHI, AND IS RANSOMWARE A DATA BREACH? This is Episode 26! INTRO Hi Everyone and welcome to the Proactive IT Podcast.  Each week we talk about the latest in tech and cyber news, compliance, and more.  We also bring you real-world examples to learn from so that you can better protect your business and identity. This podcast is brought to you by Nwaj Tech – a client-focused & security-minded IT Consultant located in Central Connecticut.  You can find us at nwajtech.com. Thanks for listening to this podcast.  Show us some love on Apple or Google Podcasts.  Subscribe and leave us some positive feedback.  What are you waiting for? Also, go join the Get HIPAA Compliance Facebook Group.  Search for Get HIPAA Compliance PATCH TUESDAY UPDATE: Chrome 81 Released With 32 Security Fixes and Web NFC API [https://www.bleepingcomputer.com/news/google/chrome-81-released-with-32-security-fixes-and-web-nfc-api/]Firefox 75 released with Windows 10 performance improvements [https://www.bleepingcomputer.com/news/software/firefox-75-released-with-windows-10-performance-improvements/]Juniper Networks Releases Security Updates [https://www.us-cert.gov/ncas/current-activity/2020/04/09/juniper-networks-releases-security-updates]Microsoft releases April 2020 Office updates with crash fixes [https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-april-2020-office-updates-with-crash-fixes/]Hackers Can Compromise VMware vCenter Server Via Newly Patched Flaw [https://www.securityweek.com/hackers-can-compromise-vmware-vcenter-server-newly-patched-flaw?&web_view=true]Oracle Tackles a Massive 405 Bugs for Its April Quarterly Patch Update [https://threatpost.com/oracle-tackles-405-bugs-for-april-quarterly-patch-update/154737/]Microsoft April 2020 Patch Tuesday fixes 3 zero-days, 15 critical flaws [https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2020-patch-tuesday-fixes-3-zero-days-15-critical-flaws/]Intel April Platform Update fixes high severity security issues [https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/] New Updates This Week Apple Releases Security Update for Xcode [https://www.us-cert.gov/ncas/current-activity/2020/04/17/apple-releases-security-update-xcode] More Updates [https://www.us-cert.gov/ncas/current-activity] Apple Patches Two iOS Zero-Days Abused for Years [https://threatpost.com/apple-patches-two-ios-zero-days-abused-for-years/155042/] CYBER SECURITY NEWS IT services giant Cognizant suffers Maze Ransomware cyber attack [https://www.bleepingcomputer.com/news/security/it-services-giant-cognizant-suffers-maze-ransomware-cyber-attack/] Hackers selling 267 million Facebook records on hacker forum [http://www.hackread.com/hacker-forum-sell-267-million-facebook-records/?web_view=true] Hacker returns $25 million after their IP address is exposed [https://www.hackread.com/hacker-returns-25m-after-ip-address-exposed/?web_view=true] DoppelPaymer Ransomware hits Los Angeles County city, leaks files [https://www.bleepingcomputer.com/news/security/doppelpaymer-ransomware-hits-los-angeles-county-city-leaks-files/] New Orleans Hit With Ransomware Again [https://www.wwltv.com/article/news/local/orleans/assessors-office-ransomware/289-2681faa3-5d40-4b86-9c74-4f8a4e7a76bc] Nearly 25,000 email addresses and passwords allegedly from NIH, WHO, Gates Foundation and others are dumped online [https://www.msn.com/en-us/news/us/nearly-25000-email-addresses-and-passwords-allegedly-from-nih-who-gates-foundation-and-others-are-dumped-online/ar-BB130we5?&web_view=true] US #COVID19 Relief Fund Leaks Data on Thousands of Firms [https://www.infosecurity-magazine.com/news/us-covid19-relief-fund-leaks-data/?&web_view=true] Topic 1: Scripps, Stanford working with Fibit to assess wearables’ COVID-19 tracking abilities [https://www.healthcareitnews.com/news/scripps-stanford-working-fibit-assess-wearables-covid-19-tracking-abilities?mkt_tok=eyJpIjoiWXpNek5UUXpZVGRsWVRoaSIsInQiOiJmTFwvWjNFRmxLVHo4VGhPRmVKMWtYelhNS1JcL3JtRG9qeGF1MUNya1BaWUcrTnQyaXZXZm1tUGhUXC9CdWVaWUxxb3Z5N1lNQkZiZXlVWVArbnpJZEpsZ1htM1dPbHcwUlwvdWxtTXdHcDhFQmo2bzJPSEh2SFdpY1RzY0ZRc1JWbVYifQ%3D%3D] Topic 2: [https://threatpost.com/beyond-zoom-safe-slack-collaboration-apps/154446/]Google wants to make it easier to analyse health data in the cloud [https://www.zdnet.com/article/google-wants-to-make-it-easier-to-analyse-health-data-in-the-cloud/] Topic 3:  Is it Time to Call Ransomware Attacks Data Breaches? HIPAA CORNER: https://www.phe.gov/Preparedness/planning/405d/Documents/resources-templates-508.pdf [https://www.phe.gov/Preparedness/planning/405d/Documents/resources-templates-508.pdf] BREACHES https://www.hipaajournal.com/category/hipaa-breach-news/ [https://www.hipaajournal.com/category/hipaa-breach-news/] Ep 26 Google & Fitbit Becoming More Involved with PHI, and Is Ransomware a Data Breach PIN [https://nwajtech.com/wp-content/uploads/2020/04/Ep-26-Google-Fitbit-Becoming-More-Involved-with-PHI-and-Is-Ransomware-a-Data-Breach-PIN-683x1024.jpg] Transcription (Unedited) This is the proactive IT podcast this week the latest 19 cybersecurity news plus more updates and warnings Google and Fitbit becoming more involved with PH I, and is ransomware. a data breach. This is Episode 26 Hi everyone and welcome to the productive IoT podcast each week we talk about the latest in tech and cyber news compliance and more. We also bring your real world examples to learn from so that you can better protect your business and your identity. This podcast is brought to you by wash tech, a client focused and Security minded IT consultant located in Central Connecticut. You can find us at and wash tech.com that’s NWA Aj tech.com Hi, welcome to another episode of the productivity podcast. As always, wherever you’re listening to this, if you could like, comment, share, or review the podcast and it is available on almost every major podcast platform, all that I know of anyway, that would be awesome. We would greatly appreciate it because it does help us to spread the word and get new audience and so forth and you know, hopefully help someone out there to prevent a catastrophic cyber attack or compliance issue. And if you want speaking of compliance, if you’re in a HIPAA compliant business, please go to Facebook and in a search type in get HIPAA compliance join that group because there we share all kinds of HIPAA information and anything related to healthcare it and it will help you to remain compliant and Do your job, protect your patients. Ultimately, that’s what HIPAA comes down to. Let’s jump into it. We don’t have a question of the week, let’s jump into the Patch Tuesday updates. And last week was Patch Tuesday. So we had a number of updates that needed to be addressed. So if you missed that, make sure you go back to Episode 25. And listen to that. But we do have a number of patches again this week. So we have first of all Apple releases security update for Xcode, Apple has released a security update to address vulnerabilities in Xcode that a remote attacker could use to exploit the vulnerability. So if you’re using Xcode, make sure you move up to Xcode 11 point 4.1. We have a Google Chrome update that also needs to be addressed that was you know, that’s I think it’s been updated three times this month, but the the most recent update is at 1.0 point 404 4.1 to two so you should end in one to two So make sure you take care of that immediately. Open SSL has released some security updates. So you should be on version 1.1. point one G. Microsoft released security updates for multiple products around the Autodesk FB x library. So any of their products that use Autodesk FBX library have vulnerabilities in them. Those products include office 2016 2019, office 365, Pro Plus, and paint 3d. And it can be used to to remotely attack your systems. So get that updated. What else do we have? I think that’s the updates. We have a couple of warnings as well that we’re going to talk about. We have one other update I’m sorry. So Apple did release or has updated to iOS zero days that have been abused for a while. They affect Apple Mail and on Apple, iOS Apple versions, I’m sorry, iOS version six in 13 point 4.1 you should be on 13 point 4.5 that is in beta right now. And it will eventually be updated to 13 point 4.5. And that will be a full release. So the vulnerability does allow for someone to take over mail and remove emails, delete emails, send emails and so forth. So you should address that ASAP. 13 point 4.5 for iOS. Right as I said, we have a couple of warnings one, the first one from the NSA in the Australian Signals Directorate, which is ASD. They jointly released a cybersecurity information sheet on mitigating web shell malware, malicious cyber attack, cyber actors are increasingly deploying web shell malware on victim web servers to execute arbitrary system commands by deploying web shell malware cyber attackers can gain persistent access, persistent meaning they’re going to On to compromise networks. The information sheet provides techniques to detect and recommendations to prevent malicious web shells. And this is on the system’s website. So there is a link from that posting to the to the information sheet. So if you’re using web shells in your environment, check that out. Also IC three which is an FBI agency, the internet crime complaint center, has released an alert warning of recent increase in extortion, email scams, cyber criminals threatened to release sexually explicit photos or videos of victims unless they agree to send payment. So I’ve I’ve I’ve shared that information, I don’t know probably four or five times on this podcast, or on a daily podcast. No. So I’m sharing it again because I continue to get questions around it. You know, from people that would never or at least I hope they wouldn’t go to porn sites. Things like that. So it’s a scam. And it usually winds up in your spam folder. So if you’re looking for it, and you find it in your spam folder, then it just tells you even more so that it’s a scam. If you’re getting into your inbox, and we need to talk because then you’re getting phishing emails and scams into your inbox, and that’s a problem. But those are the two warnings that came out this week. One from the NSA and one from the FBI. I see three. All right, let’s do a little news. Round up. We have some big news actually. This is on bleeping computer but it’s been reported all over the place and I’ve been trying to get some updates for you. I have not gotten much more in the way of updates but one of the world’s largest msps it may be the largest MSP out there. It service Giant Cognizant suffers Mays ransomware cyber attack and we’re gonna talk a little bit about me as ransomware when we get to the hot topics, more about more along the lines of data breaches, but Cognizant has been hit by what is suspected to be major ransomware. There is not a whole lot more information than not accept them that Cognizant has started to alert their clients and alert them as to how to determine if they have any ransomware. But specifically, mais ransomware on the network, on their networks. Now, because I’m going to talk more about this in a few minutes. I will just say this maze ransomware is one of those ransomware operators that does steal your data before encrypting your network and then telling you if you don’t pay up, we’re gonna release your data to on hacker form, and it will be available to the public. So this will this is this just happened this week over last weekend. So we will see how this plays out. I have not been able to uncover any more information as of yet. On hackery to have hackers selling 267 million Facebook records on accurate form. Currently the trove of 267 million Facebook records are being sold for around $600 on a hacker forum. Fake Facebook has more than 2.5 billion billion monthly active users and when its data is breached, that’s bad news for everyone today is one of those days where personal data of millions of unsuspected users has been put at risk. In December, hacker read reported that a misconfigured Elasticsearch server exposed the personal information of 267 million users. These records mostly belong to users in the United States and included Facebook profiles, full names a unique ID for each account and a timestamp. The good news is it does appear that passwords were not included in that breach. So there’s that but You can expect some spear phishing to come out of this. Also on hacker read a hacker, who got caught basically returned $25 million after his IP address was exposed. This This occurred in China. This was reported on April 21. So this happened on April 20. A Chinese lending platform named lend f.me, using a lending protocol by de force was hacked, resulting in a loss of $24.36 million worth of ether and Bitcoin and USD stable coins. Now in a shocking twist of events, the entire sum has been returned by the attacker. And the reason is because their system was set up to retrieve IP address information. Once he was exposed, the the website Lund f.me said hey, we have your information, you might want to think twice about what you’re doing. And so he returned the money in two different installments. So, you know, if you’re going to hack disguise where you’re hacking from on bleeping computer double pay Merlin’s. So we have two municipalities that got hit this week that we know of. One of those was Los Angeles County called Torrance, the city of Torrance of Los Angeles much upon area. California has allegedly been attacked by a double payment ransomware having encrypted unencrypted data stolen and devices encrypted. So again, the trend is still the data, encrypt everything and then demand money. So in this case, they’re demanding about $690,000 in in Bitcoin to get the decrypter. And of course, what will happen is if Torrance doesn’t pay up, which is as of right now it doesn’t look like to have then the top hammer gang will release the data that they have stolen, they have 20 gigs worth of files. They did release a little bit to show that they do have it. Basically they released the the hierarchy of the files system that was stolen. So they it looks like they stole the entire file system, whatever it was, and they’re sharing some of that on their forum and saying don’t pay us the $690,000. We’re going to release the rest. Not to be outdone New Orleans once again in the ransomware news department. I’m getting this there isn’t a lot of information on this for some reason, but I’m getting us on wwL tv.com. Orleans Parish assessor’s office hit by ransomware attack official said no personal info lost, which is probably why it’s not showing up on any of the ITC cites It is unclear when the ransomware was discovered and what kind of damage it did to the system. New Orleans, the Orleans Parish assessor’s office is latest government agency to be hit with a cyber attack the agency which handles property assessments and taxes in the city of New Orleans said in a statement Friday that it was working with the FBI to investigate the security breach. The Orleans Parish assessor’s office is working closely with Federal Bureau of Investigation after our server was breached by ransomware official said in a statement no personal or confidential information was stolen due to the multiple levels of authentication in the assessor system and all all the office functions will continue as the data critical to the operation of the office is still accessible. The office said it would continue to reevaluate homes for the 2021 tax year and the public facing sections of the assessor’s office website would not see any changes. It is unclear when the ransomware was discovered and what kind of damage it did to the system. The city of New Orleans was crippled at the end of 2019 by a severe ransomware attack that forced the city to reform are all government computers delaying all levels of city governance. The state of Louisiana suffered a similar attack which shut down OMB services for several weeks, there’s no indication of whether the latest attack was related to either of the previous ones. So New Orleans seems to be right in in the targets of the ransomware operators for summary On MSN, we reported this on our daily show. MSN reports nearly 25,000 email addresses and passwords allegedly from NIH, who gates Foundation’s are and others are dumped online. Unknown activists have posted nearly 25,000 email addresses and passwords allegedly belonging to the National Institutes of Health, World Health Organization, the Gates Foundation and other groups to combat the Coronavirus pandemic, according to the site intelligence group, which monitors online extremism and terrorist groups. Now when you hear who did this, where they suspected this I should say, you’re gonna be you’re gonna be a little surprised while site was unable to verify whether the email addresses and passwords were authentic, the group said that the information was really Sunday and Monday and almost immediately used to ferment attempts at hacking and harassment by far right extremists. In Australian cybersecurity expert Robert Parker Potter said he was able to verify that the who email addresses passwords were real little whose origins are unclear appear to have first been posted to 4chan a message board notorious for its hateful and extreme political commentary and later to paste into tech storage site to Twitter and too far right extremist channels on telegram in a messaging app so most of us probably know what telegram is. Think think Twitter would not really twitter twitter owns it’s encrypted trying to think of it what am I trying to think of think WhatsApp, but but not video calls and neo nazis and white supremacist capitalized on the lists so that’s the surprising part to me anyway, and publish them aggressively across their venue said read a cat sites executive director using a data far right extremist work calling for a harassment campaign while sharing conspiracy theories about the Coronavirus pandemic. The distribution of these alleged email credentials were just another part of months long initiative across the far right to weaponize the COVID-19 pandemic. The report by site based in Bethesda, Maryland said the largest group of allegedly emails and passwords was from the NIH with 9938. Found in this list posted online, the Centers for Disease Control and Prevention had the second highest number with 6857. The World Bank with 15 and 20 in the list of who addresses and passwords total 20 732. smaller numbers of entries were listed for the Gates Foundation, private philanthropic group whose co founder Microsoft co founder Bill Gates last week, announced 150 million dollars in new funding to combat the pandemic. Also targeted was the Wu Han Institute of biology, a Chinese Research Center in the city where the pandemic began, that has been accused of a role in triggering the outbreak. So here we go. With white supremacists getting involved in online extortion and hacking and data breaches and so forth. It’s kind of scary to be honest with That, you know, most people don’t think of these groups as being as having high levels of access to tools and ability to do these things. And it’s that’s actually not true. So it’s going to be interesting as we move forward, because there is a lot, a lot of conspiracy theories are out there around COVID-19. And there seems to be an increasing number of hostility on both sides of this thing. So hopefully, we can all calm down and come to cool level heads and stuff like this doesn’t continue. Also, speaking of COVID-19, the SBA was breached. And as we know, the SBA is giving out loans and in some cases on grants to help small, small businesses and you know, I’m not going to get political here on this but it didn’t really work the way they expected. I don’t think but anyway, US COVID-19 relief On the x data on thousands of firms This was reported on info security magazine calm but it’s been reported in a few different places. Thousands of us businesses may have had personal information PII leaked online after a government agency error led problems with applications for economic relief. The Small Business Administration admitted the error and your letter to affect a company’s widely reported in the us this week. It claimed that a problem was discovered with the online portal used by businesses to apply for economic injury disaster loans, which is idle for sure. Ideal. unspecified personal Identifiable Information link to 7900 businesses may have been disclosed to the other applicants of the program. So it wasn’t it wasn’t malicious attack. It was an error, but it may have exposed information to other businesses. They do say that the PPP portion of the of the stimulus stimulus package was not impacted. So that is good news. I suppose. But beyond the walk, you know, just watch your credit, watch your, your banking information and so forth. Make sure that your business does not become compromised from this Get, get some identity monitoring some breach monitoring going on if you need some breach monitoring, if you want me to check since and an email to support at and wash dot tech and wha tech, and we’ll be happy to check for you. And if you want monitoring, we could talk about that too. But we’ll check once for free. No problem. I have no problem doing that. So just reach out to us. Or you can just message us on Facebook. It’s m.me dot Hold on. I’m gonna mess that up. I was getting the Facebook address wrong. It’s m.me slash and wash tech m.me slash NW AJ tech. That’s our Facebook Messenger. You can also message us there We got a few hot topics two of them are these mega corporations trying to get involved or more involved I should say in healthcare. The first one being reported in healthcare IT news calm scripts Stanford working with Fitbit to assess wearables COVID-19 tracking abilities. We see an enormous opportunity to enhance disease tracking for improved population health during the COVID-19 pandemics at Scripps Research translational Institute’s Dr. Eric Topol, Scripps health and Stanford medicine have joined with Fitbit for a new study to gauge how well wearable devices can help track trace and isolate COVID-19 and other infectious diseases. The Scripps Research translation translational Institute recently launched an app based research program called detect that can analyze wearable health data, such as activity levels, heart rate and sleep and to more quickly detect viral illnesses caused by Coronavirus, influenza or other infectious diseases. The Stanford healthcare Innovation Lab, meanwhile, recently launched its own COVID-19 wearable study, which is exploring how data collected from wearables like heart rate, heart rate, skin temperature and blood oxygen saturation can be used to predict the onset of an infectious disease before symptoms start. So not just COVID-19. But other things like the flu. With Fitbit scripts in Stanford, other institutions are welcome to join in a consortium they say plan to assess how well such device driven approaches could be scaled up for public health response to outbreaks like COVID-19. Earlier this year, Scripps published evidence that wearables can help predict onset flu and similar diseases before symptoms start. The goal of the new consortium is to build on that research. With special focus on public health emergencies like this one, researchers will run many studies independently with a findings aggregated and shared across the consortium. Fitbit will help boost consumer awareness and help its customers participate in the effort so you will have to opt in. opt in. It will also donate wearable devices to scripts Stanford and others Fitbit users can learn how to participate in the studies through the company’s COVID-19 resource web. And there is an article on this page on this post, which will be a link to on the show notes. It’s looking like consumers devices will have a big role to play in any large scale track and trace effort to stem the tide of COVID-19. This past week, Apple and Google announced plans to develop API based API enabled interoperability between iOS and Android products and eventually build Bluetooth based contact tracing functionality into their respective operating systems to give public health officials better visibility into how Coronavirus might be spreading. Fitbit, meanwhile, also rolled out a new feature this week that can connect you To telemedicine services through its partnership with vendor plus care. From our previously published work, we know that data collected from consumer wearables can significantly improve the prediction of influenza like illnesses, said Dr. Eric Topol, director and founder of SRT AI. In a statement we see an enormous opportunity to enhance disease tracking for improved population health during the COVID-19 pandemic, and are pleased to join this new consortium to bring value to the research community. By bringing together these and other leaders in scientific research, we hope to rapidly advance science and innovation in the fight against COVID-19 by promoting consumer participation and critical release research efforts, supporting frontline health care workers and donated wearable devices and sharing learnings quickly and openly across research partners added James Park, co founder and CEO of Fitbit. So it’s interesting because you know, we’re you have to opt in so both the Fitbit thing and The Apple and Google thing you have to opt in even once the app on Google thing is OS based, you have to opt into it now, so not everybody’s gonna opt in. And I think a big part of that is do we trust Fitbit, Google and Apple to not release our PHR to people we don’t want it to get in, get in the hands of and then there’s the whole tracking piece so now we’re giving it not that it doesn’t already exist, because it absolutely does GPS is on all smartphones now. And you can be tracked, even if you turn GPS off, you could still be tracked, it’s not as accurate but you could still be tracked. But we’re essentially saying yes go ahead and track me track my movements track you know, so there’s there’s some gray area there that I’d like to see them address if they’re going to move forward with this because that those areas kind of scare me. You know, there’s even some talk online of, of using a chip implant. To track things and I know for a fact that is not going to sit well in America. So I would like to see more information as to how they plan to roll this out what safeguards are in place, there’s a lot of interoperability going on here. That tends to lead to potential breaches. And so obviously, there’d be a lot of concerns in that area. Speaking of Google, on Zd net, Google wants to make it easier to analyze health data in the cloud. google has opened up its cloud healthcare API to allow doctors to analyze data using cloud computing technologies. So you know, another API in place here. And if you know anything about API’s, you know that they are historically not secure. So this is another issue to consider with with these these large mega companies work together to you know, under the under the Healthcare umbrella. Trying to choose my words carefully here under the healthcare umbrella. There may be some opportunities here for the bad guys to sneak in. And I think that’s the concern that I have with a lot of this. But anyway, Google has expanded the availability of its cloud healthcare API in a bid to improve healthcare interoperability, and help providers drive insights from a myriad sources of medical data. Google’s cloud healthcare API allows healthcare organizations to collect and manage various types of medical data via the cloud, including digital imaging and communications in medicine. Also, daikon for short di c om, alpha level seven and East healthcare interoperability resource standards that’s Did I say East it’s fast healthcare interoperability resource. fH IR standards. This data can be fed through analytics and machine learning programs so that healthcare providers can identify patterns that could help improve patient care, which, you know, if that’s, that’s great, you know, let whatever we could do even if it’s to take a few minutes off of somebody’s healthcare that could save lives. As Google notes gathering a unified view of the multitude of data formats and inputs often possesses a Herculean Herculean effort, not least due to the highly fragmented nature of the healthcare systems, meaning the different systems use different formats and different EMRs EHR. So they’re not it’s going to take a lot of effort to have them all. All become the same format, all readable for everybody, which is something that HHS and OCR and other organizations have been trying to accomplish for years now. This is not new on C was trying to work on this as well. interoperability was always in place doesn’t always work well because you know the same reason that information isn’t always easily translated to whatever system the next doctor in the next healthcare system might use. It is hoped that running capture data through AI and machine learning while identify patterns that could help improve patient outcomes, which is an issue that has taken center stage as healthcare providers around the world scramble to react to the COVID-19 pandemic. We know that the pandemic is impacting every aspect of the healthcare industry differently and that needs organizations that the needs organizations are rapidly evolving Google said in a blog post. Our goal is to bring our technology expertise to bear in helping with experts, your experts so that healthcare organizations can focus on providing the best care to as many people as possible. Google launched its cloud healthcare API in early access release in March of 2018. The company has been working on partnership with Mayo Clinic since 2019. To demonstrate how cloud based AI technology could transform healthcare delivery. Mayo Clinic has since been using Google’s cloud API healthcare API to enable the storage and interoperability of its clinical data. Google said dr. john Halla, Maka allama halamka, President of mayo clinic platform said, we’re in a time where technology needs to work fast, securely and most importantly in a way that furthers our dedication to our patients. Google clouds healthcare API accelerates data liquidity among stakeholders and in return will use will help us better serve our patients. The issue of interoperability remains a tricky subject with healthcare battles over data formats and ownership stymies efforts to join up healthcare systems and make patient data available to healthcare professionals whenever the end whenever wherever they need it. So imagine, you know, two giant healthcare systems that use different data formats. They’re not going to want to budge and change those formats because of the massive costs that would be involved and the training That would be involved in the US. inroads have been made recently through the passing of rules by centers of Medicare and Medicaid Services, and National Coordinator for Health Information Technology OMC to make it easier for healthcare organizations to exchange patient data for patients to access their own information. So we’ve talked about that before but rights of access so Google said its cloud healthcare API was designed to scale and support interoperability and patient access. It added that the COVID-19 pandemic had made the need for increased data interoperability more important than ever. elsewhere. The Internet giant has been harnessing its mobile technology to aid effort to track the corona virus outbreak. We talked about that a couple times already. In a partnership with Apple and the COVID-19 tracking via smartphones, the operating systems through Bluetooth are not out yet. But that is something that is being worked on. So again, Google to go dipping your hands into healthcare. And you know, it might be prime time that it happens because of COVID-19. And because it’s not even just the outbreak right now it is the concern that fall in winter might be worse when combined with the flu. So we’ll see what comes with that. I’m sure there’ll be more talk around that as well. I’d love to hear your thoughts. If thoughts and concerns, you know, what do you think? What do you think about Google Cloud healthcare API, working with more healthcare providers to try to slow down this pandemic? What do you think about them? We’re going with Apple tech to come up with a way to trace people who may have COVID-19 what do you think about Fitbit? It’ll be interesting to see what people think and where it goes from here. And, you know, obviously, there are some, some concerns some risk factors involved too. So we’re going to try something a little different here. We’re going to talk about whether or not ransomware attacks should be coming. a data breach indices. This is not a new topic. It’s been around for a little while. It’s been kicked around for a little while. But this comes up this week because of the ransomware attack on Cognizant, know, Cognizant is a very large, it vendor, an MSP. They have, I believe 300,000 employees, and I think I saw $15 billion in revenue last year. They were hit with a ransomware attack and have lots of customers and they’ve warned their customers that this has happened. So now they’re dealing with the ramifications of that. What are the ramifications? So the attack was maze ransomware maze was the first one, I believe to say the maze ransomware operators were the first one to say if you don’t pay up, we’re going to release the data we have stolen to the public. So In some cases, not a big deal, because, you know, the company probably doesn’t have any sensitive information, but maybe they do. Who knows. But in some cases like Cognizant boot can just about guarantee they have health care providers and other, you know, law firms and financial firms that probably have some sensitive information and have some compliance issues. So now it becomes an issue. So now, maze ransomware. And now some others. So don’t mcareavey Doppel primer and a few others have said, we’re going to hit you a ransomware. But before we hit you with the ransomware, we’re going to steal your data. And if you don’t pay that ransom demand, we’re going to post that data on our hacker forums. And so now you’re releasing your sensitive information and potentially client sensitive information to the world. That is a data breach by definition that is a data breach. So if if in the case, let’s say Cognizant here, has, I don’t know, let’s say they have 500 gigs of data, client data sensitive data could be you know, credit card information, PII in some cases, it could be pH I if to have this information, and it gets shared to the world. That is a, I mean, it’s already been breached. So Mase already has it, that is the definition of a data breach. the theft of data from one company to one company is a data breach. So it means has gone in, taken the data, taking it off of cognizance network, brought it to wherever they’re going to store. That is a data breach. You know, a data breach could be as simple as a thumb drive that goes missing or a laptop that goes missing all the way to something like this where or a data breach could be, you know, you’re left to an Elasticsearch database or an s3 bucket open to the public. On the internet. That’s a data breach because Now it’s available to more people that shouldn’t be seeing it. And so we hear these things all the time. They’re all data breach, they all qualify as data breaches. And we don’t. We don’t have data breach laws everywhere yet, it will, it will eventually happen to us, we’ll have to catch up and have their own version of GDPR, which would which this would fall under GDPR. In Europe, this would fall under the ccpa, California Consumer Protection Act. New York has the New York shield law. So all of these things would fall under, under if Cognizant, and I’m not even sure Cognizant is based, I believe they’re based somewhere in Europe. But this would fall under data breach for those, those you know, whether it’s Europe or the states, individual states, um, it qualifies as a data breach and because of the size of the organization, you can bet there would be significant penalties in any of the cases. So Mays ransomware in the last few months. has hit South wire which is down south, I believe in Georgia and demanded a significant amount of money. I believe it was $6 million in Bitcoin. And there hasn’t been an update to that. But they did the same thing. They leaked the data on their forms, and said pay up. Oh, we’re gonna release more. They don’t release it all at the same time. Yeah, it was $6 million. They don’t release it all at the same time, but they do release some just to show that they have and then they keep releasing a little bit at a time to say we do have it. Eventually did publish 14 gigs worth of files, which is, you know, if it’s just documents, that’s a lot of files. chub was it just was in March earlier this year. Earlier this month, they were hit. Allied universal was breached. Chubb is an insurance carrier, by the way, they they’re a big cyber Insurance Agency. They sell a lot of cyber insurance. That’s their main focus, I believe, and they were hit with Mays ransomware. So that means their data was pulled off of Chubbs internal network. And Mays kept it and Mays again, there hasn’t been a lot of updates since since the last one at the end of March. I’m sorry, it was last month, not this month. So it’s been about a month since we’ve gotten an update on that. But chub was also hit and chub if you’re in the IT world, you know that they’re one of the one of the players in cyber insurance. Now they’ve been breached, do you trust someone who sells cyber insurance to provide cyber insurance to you if you’re in it or any business for that matter, when they have been breached? now it becomes a reputation issue as well, not just a data breach, but it is a data breach. They took the data off of their network, they now know who has potentially now know who has cyber insurance from Chubb. And what does that mean? That means now that that those companies, those individuals could become phishing attacks and nine we all know it’s 90% of ransomware attacks begin with a phishing attack. And if it’s made, it becomes a data breach if it’s if it’s Doppel paper or soda mcareavey, it becomes a data breach. Allied universal. I don’t have a lot of detail on that one. But they were also hit with a data breach, major ransomware attack, which was a data breach. They did leak the stolen data. And now we have cognitive so Cognos, it just happened a few days ago. And there are others. These are some of the bigger ones. Cognizant just happened. Or, Oh, I forgot one. In December we had one for city of Pensacola. Right. Do you remember that was $1 million ransom request. City of Pensacola in a few days later, there was a shooting on I believe a military base wasn’t related. So Mays was quick to point out they had nothing to do with that. But city Pensacola really, really took a big hit in that one week period and their data was breached their data was stolen and leaked. So then and what does this tell us? So we have a municipality. Well there’s one on Italy as well. There’s South wire which is a what it sounds like they make they make wires and things like that. There’s one here. Allied Where did it go? allied universal which I’m not sure what allied universal is. You have Chubb which is a cyber cyber insurance carrier provider. Allied universal is a security company it says facility like physical security. You we did have one on Hammersmith It was called which was a facility in the UK that was preparing to test COVID-19 vaccines and this As I said, we’re not going to attack healthcare facilities during this pandemic. And they had attacked right before the period before this was called a pandemic. They, so, that aspect of it, they said, we’re not going to do it. They did it before they said they weren’t going to do it. But they released the data on their forms after they said they would not attack any healthcare facilities. So what what is the point I’m trying to make here? And then of course, you have Cognizant, they don’t care what industry you’re in, they’re going they’re opportunists. They’re going to attack whatever they can get. And they’re going to try to make money off of whatever they can get. The question here is, is this such as should this be considered a data breach? And if you think about the basic, very basic definition of a data breach, is when someone breaks in, steals your data, and leaves what that data and then does whatever they do plan to do it that data right. The data is no longer in your control. That is is a data breach. Mais Sodano KB Doppel payment and a few others now are doing just that they break in, they don’t do a physical break in and do it through your, you know, a lot of times through phishing, or some other vulnerability that they’ve they’ve found on your, your systems. They steal the data. Then they encrypt everything. And they leave you a message saying pay this ransom, or we’re going to start releasing data. So in that now that the ransom amounts have gone up, because they’re saying, Transcribed by https://otter.ai The post ProactiveIT Ep 26 – Is Ransomware a Data Breach? [https://nwajtech.com/proactiveit-ep-26-is-ransomware-a-data-breach/] appeared first on Nwaj Tech - Information Tech & Cloud Support [https://nwajtech.com].

24 apr 20201 h 3 min