Posts

Showing posts with the label Australia

2022 Week 10 - 12 News Roundup

Summary Sorry for the delay.  Work, life, and school got in the way.   As expected, most of the news can be wrapped around the growing war between Russia and Ukraine.  There is growing fear of either intentional or unintentional escalation in the cyber world outside those two countries. News SLTT Several state and local governments were targeted by a Chinese government-backed hacking gang.  The breaches occurred in at least 6 different states in The United States.  It appears that the group used the Log4J (i.e. LogJam) vulnerability.     https://www.cnn.com/2022/03/08/politics/china-hacking-state-governments-mandiant/index.html Western Australia announced it will invest $25.5 million AU to expand state cybersecurity.   https://www.zdnet.com/article/wa-government-allocates-au25-5m-to-expand-cybersecurity-services/?&web_view=true New Mexico in the United States (U.S.) appointed its first senior advisor for cybersecurity and critic...

2021 Weeks 32-40 Security Roundup

  Summary Let me apologize for the long delay right upfront.  First, we had a round of Covid in the household in a person who is immune-compromised.  Next, I started a new semester in college and the workload was far greater than I expected.  Lastly, this is the start of the budget year for us and I had several projects that have demanded almost every second of my work time.  I hope to get back to weekly updates by November. Lots of news that covers:  health care, education, infrastructure, and SLTT governments around the world.  Since I am hitting the length limitations of Blogger, I will simply invite you to read and try and get caught up yourself.  News UC San Diego Health sued over breach In what is becoming a growing trend UC San Diego Health is being sued for failure to have proper data protection protocols.  The suit is citing breach of contract, negligence, and violating California consumer and medical privacy laws.  Specifically...

2021 Week 24 Security Roundup

  Summary Cybersecurity is getting a lot of attention because of the rash of high-profile attacks.  This week saw more information about some of those attacks as well as new attacks against schools.  We also are starting to get word of past attacks that have had their investigations completed or that were declassified.    News Colonial Pipeline Hack Evidence is mounting that the United States government was the group behind the dismantling of servers operated by the DarkSide hacking group.  The Federal Bureau of Investigations (FBI) announced that they had worked with Colonial Pipeline to recover about $2.3 million worth of bitcoin.  This marks the first such seizure by the newly created Department of Justice digital extortion taskforce (what?  No acronym?  Our federal partners are falling down on the game...).  This is part of the reason, in my opinion, that several of the global hacking organizations are making a change to avoid critic...

2021 Week 12 Security Roundup

  Summary This blog is geared towards cybersecurity events that are of interest to State, Local, Tribal, and Territorial (SLTT) governments in the United States of America.  It is hoped that this focus will help SLTT information technology workers and policymakers to get the information relevant to their mission.  If you are in other sectors hopefully there is information you can find useful as well.   Updates on Solar Wind and the Microsoft ProxyLogon issues dominated news again this week.  Breaking news is that as of Thursday night, Defender and System Center Endpoint Protection have added automatic patching for the linchpin of the attack playbook.  This was so successful they evidently broke one of their honey-pot farms.   In other news, we had updates from the US and other Federal governments.  There are even more signs of escalation by nation-state actors, primarily China, in what many are seeing as a global cyberwar.  We also ...