2022 Week 27 and 28 Security News Roundup

 

Summary

I am experimenting with releases on Mondays.  We will see how this works.

Continues to be pretty slow news on the SLTT and Infrastructure fronts.  The biggest newsmaker was MI5 and the FBI giving a joint warning about China's efforts to steal intellectual property from the West.


News

In a first-of-its-kind announcement, Great Britain's MI5 and the United States' FBI have released a joint warning on China's threat to industry and academia.  They pointed out that Communist China leaders have made establishing China as a world economic powerhouse by acquiring intellectual property from the rest of the world a primary goal.  The FBI in particular has been warning of this in recent years as they have made several high-profile arrests that I have covered in previous posts.  


SLTT

Education

College of the Desert in Palm Desert, California has suffered a cyberattack that disrupted the school's online services and on-campus phone system.  The school announced that outside experts were working to restore the services.  This is the second time the college has been hit, which is a trend I have noted in the past where threat actors will go back to previously attacked entities.  


Healthcare

North Korean State-Sponsored threat actors are using Maui ransomware to target healthcare and public health entities in the United States (and probably other places).  The FBI has indicated they have responded to several instances of Maui being used in the past few months to bring down healthcare entities.  

Aerospace

3TB of airport data was publically accessible due to a misconfigured Amazon S3 bucket.  The information included PII of employees of at least 4 airports in Colombia and Peru.  This is a good example of why cloud security is so important.



Legislative actions 

A U.S. Congressman has issued an amendment to the defense authorization bill that will tie the definition of the term infrastructure to key national critical functions that would affect security, economic security, public health, or safety.  



Comments

Popular posts from this blog

2021 Week 11 Security Roundup

2021 Weeks 32-40 Security Roundup

2021 Week 29 Security Review