Posts

Showing posts with the label k-12

2022 Week 22 Security review

Summary Hopefully, these will be a bit more regular now that the semester is over.   We are seeing attacks against all infrastructure areas increasing.  This week's report has school breaches, SLTT breaches, SCADA news, and several healthcare attacks. News SLTT Texas Department of Transportation had a data breach that impacted over 7,000 records.  This included employee information with PII including Social Security Numbers (SSN).   https://www.databreaches.net/another-texas-state-agency-data-breach-this-time-its-the-department-of-transportation/?web_view=true The Texas Department of Insurance (TDI) announced that 1.9 million people in the state who filed claims for compensation had their information publically available from March 2019 to January 2022.  https://www.infosecurity-magazine.com/news/personal-information-two-million/?&web_view=true https://www.tdi.texas.gov/news/2022/tdi03242022.html https://www.tdi.texas.gov/data-security-event/additi...

2021 Weeks 32-40 Security Roundup

  Summary Let me apologize for the long delay right upfront.  First, we had a round of Covid in the household in a person who is immune-compromised.  Next, I started a new semester in college and the workload was far greater than I expected.  Lastly, this is the start of the budget year for us and I had several projects that have demanded almost every second of my work time.  I hope to get back to weekly updates by November. Lots of news that covers:  health care, education, infrastructure, and SLTT governments around the world.  Since I am hitting the length limitations of Blogger, I will simply invite you to read and try and get caught up yourself.  News UC San Diego Health sued over breach In what is becoming a growing trend UC San Diego Health is being sued for failure to have proper data protection protocols.  The suit is citing breach of contract, negligence, and violating California consumer and medical privacy laws.  Specifically...

2021 Security for Week 25 Roundup

  Summary This week there was quite a bit of activity, including some that hit close to home.  These include ICS security news, more PulseConnect victims, a deep dive at a school system response, and a local hospital that was the victim of ransomware.  Lastly, there is quite a bit of legislative activity with the NATO and G7 summits dominating the news. News SolarWinds hack I have had some who follow my writings here and on social media claim that attributing the SolarWinds attack to Russia is somehow partisan or rash.  The argument seems to be that there is no real proof and instead, the hack was due to some perceived (but unattributed) lack in the operations of the current state of the nation's cyber defense strategy.  If you are one of those, I really implore you to get in to that discussion here.  What can we, the front-line workers in the cyber war front, do to be better at defense, response, and recovery? This week, FireEye, who first identified the h...

2021 Week 24 Security Roundup

  Summary Cybersecurity is getting a lot of attention because of the rash of high-profile attacks.  This week saw more information about some of those attacks as well as new attacks against schools.  We also are starting to get word of past attacks that have had their investigations completed or that were declassified.    News Colonial Pipeline Hack Evidence is mounting that the United States government was the group behind the dismantling of servers operated by the DarkSide hacking group.  The Federal Bureau of Investigations (FBI) announced that they had worked with Colonial Pipeline to recover about $2.3 million worth of bitcoin.  This marks the first such seizure by the newly created Department of Justice digital extortion taskforce (what?  No acronym?  Our federal partners are falling down on the game...).  This is part of the reason, in my opinion, that several of the global hacking organizations are making a change to avoid critic...

2021 Week 14 Security Summary

  Summary There was not a lot of activity of general interest this week.  Industrial control systems (ICS) security kind of had a spotlight on it.  ICS security is included in this blog as many local governments are responsible for power and water production and/or distribution.  Another hot topic was educational security, and I outline a couple of individual cases as well as general information. News Kansas water utility hack The DOJ announced they were inditing Wyatt Travnichek for hacking the Ellsworth Rural Water District No. 1 (AKA Post Rock Rural Water District) in Ellsworth County, Kansas In March 2019.  The DOJ is claiming that Travnichek tampered with the water purification and disinfecting systems via computers with the intent of causing harm.  If found guilty on all charges he faces 25 years in prison.  It appears that he was a former employee that had remote access privileges.  Apparently, when his employment ended in January 2019, his...

2021 Week 12 Security Roundup

  Summary This blog is geared towards cybersecurity events that are of interest to State, Local, Tribal, and Territorial (SLTT) governments in the United States of America.  It is hoped that this focus will help SLTT information technology workers and policymakers to get the information relevant to their mission.  If you are in other sectors hopefully there is information you can find useful as well.   Updates on Solar Wind and the Microsoft ProxyLogon issues dominated news again this week.  Breaking news is that as of Thursday night, Defender and System Center Endpoint Protection have added automatic patching for the linchpin of the attack playbook.  This was so successful they evidently broke one of their honey-pot farms.   In other news, we had updates from the US and other Federal governments.  There are even more signs of escalation by nation-state actors, primarily China, in what many are seeing as a global cyberwar.  We also ...