Posts

Showing posts with the label power

2023 Week 47

  Summary Slowly trying to bring this back since I have found no other place that collects this exact information.  My also add a podcast feature around the first of the year. News CISA is exploring becoming a managed service provider of cybersecurity services to critical infrastructure entities.  This is part of the ongoing efforts by the U.S. to take an expansive approach to cybersecurity.  https://securityboulevard.com/2023/11/cisa-to-provide-cybersecurity-services-to-critical-infrastructure-entities/ https://therecord.media/cisa-launches-pilot-program-offering-services-to-critical-infrastructure?&web_view=true SLTT The City of Long Beach, California is deciding whether to declare a state of emergency in regards to their cyber incident that struck systems on the 14th.  The attack affected public-facing services as well as some business operations but appears to have spared the public safety systems. https://www.govtech.com/security/long-beach-calif-mulls-...

2022 Week 10 - 12 News Roundup

Summary Sorry for the delay.  Work, life, and school got in the way.   As expected, most of the news can be wrapped around the growing war between Russia and Ukraine.  There is growing fear of either intentional or unintentional escalation in the cyber world outside those two countries. News SLTT Several state and local governments were targeted by a Chinese government-backed hacking gang.  The breaches occurred in at least 6 different states in The United States.  It appears that the group used the Log4J (i.e. LogJam) vulnerability.     https://www.cnn.com/2022/03/08/politics/china-hacking-state-governments-mandiant/index.html Western Australia announced it will invest $25.5 million AU to expand state cybersecurity.   https://www.zdnet.com/article/wa-government-allocates-au25-5m-to-expand-cybersecurity-services/?&web_view=true New Mexico in the United States (U.S.) appointed its first senior advisor for cybersecurity and critic...

2022 Week 6 Security Summary

Summary This week we saw a wide array of news about cyber security.   News SLTT Pellissippi State Community College was the victim of a ransomware attack that apparently was trying to encrypt data.  They report they did not pay the ransom and are working to figure out the extent of data that was accessed. https://www.securityweek.com/tennessee-community-college-suffers-ransomware-attack?&web_view=true https://www.infosecurity-magazine.com/news/tennessee-college-hit-ransomware/ Infosec Institute is offering scholarships to 15 people from underrepresented groups in the infosec/cybersecurity industry.  It expands on their Accelerate Scholarship Program.   https://www.infosecurity-magazine.com/news/infosec-announces-new/ https://www.infosecinstitute.com/scholarship-opportunities-for-aspiring-cybersecurity-professionals/?utm_source=newswire&utm_medium=pr&utm_campaign=accelerate&utm_content=women#women Clario researchers discovered an unsecured Mi...

2022 Week 5 Summary

 Summary News came this week of several new cyber security operation centers.  This is a great idea.  The harder we make it for the bad guys the more likely they are to try and figure out something else to do.  We also have some advisories about issues in Industrial Control Systems(ICS). News SLTT Several Puerto Rico government entities were struck by a cyberattack including the territories Senate.  Still not a lot of information at this time. https://www.securityweek.com/official-says-puerto-ricos-senate-targeted-cyberattack?&web_view=true The Port of Los Angeles has opened its own Cyber Resilience Center (CRC).  This CRC will ensure that the port is protected from cyber threats that might impact cargo shipments that come into one of the world's most active seaports.   https://www.infosecurity-magazine.com/news/la-launches-cyber-resilience-center/ Power The U.S. Federal Energy Regulatory Commission (FERC) is looking at implementing a new regu...

2021 Security for Week 26 Roundup

  Summary: This week we have an update on the Tulsa Oklahoma Ransomware attack and data breach as well as an update on the Ireland health system breach by the same group.  NBC and others have recaps of water security.  Several groups are doing cybersecurity exercises and this included a grid attack simulation.   News Tulsa Oklahoma Ransomware Attack  As previously noted ( https://yasb2018.blogspot.com/2021/05/2021-week-19-security-roundup.html ) Tulsa was the victim of a Ransomware Attack.  Now it appears that some of the breached data (18,000 + files) has been released.  This again points to the danger of paying the ransom as it appears there is little honor among the hackers.  It should be noted that Conti (the suspected group behind the attack) has a long history of this. https://edition.cnn.com/2021/06/23/us/tulsa-cyberattack-personal-information-dark-web/index.html?&web_view=true https://kfor.com/news/local/ransomware-attackers-relea...

2021 Security for Week 25 Roundup

  Summary This week there was quite a bit of activity, including some that hit close to home.  These include ICS security news, more PulseConnect victims, a deep dive at a school system response, and a local hospital that was the victim of ransomware.  Lastly, there is quite a bit of legislative activity with the NATO and G7 summits dominating the news. News SolarWinds hack I have had some who follow my writings here and on social media claim that attributing the SolarWinds attack to Russia is somehow partisan or rash.  The argument seems to be that there is no real proof and instead, the hack was due to some perceived (but unattributed) lack in the operations of the current state of the nation's cyber defense strategy.  If you are one of those, I really implore you to get in to that discussion here.  What can we, the front-line workers in the cyber war front, do to be better at defense, response, and recovery? This week, FireEye, who first identified the h...

2021 Week 24 Security Roundup

  Summary Cybersecurity is getting a lot of attention because of the rash of high-profile attacks.  This week saw more information about some of those attacks as well as new attacks against schools.  We also are starting to get word of past attacks that have had their investigations completed or that were declassified.    News Colonial Pipeline Hack Evidence is mounting that the United States government was the group behind the dismantling of servers operated by the DarkSide hacking group.  The Federal Bureau of Investigations (FBI) announced that they had worked with Colonial Pipeline to recover about $2.3 million worth of bitcoin.  This marks the first such seizure by the newly created Department of Justice digital extortion taskforce (what?  No acronym?  Our federal partners are falling down on the game...).  This is part of the reason, in my opinion, that several of the global hacking organizations are making a change to avoid critic...

2021 Week 19 Security Roundup

  Summary The Colonial pipeline hack dominated the news cycle this week.  This is probably the largest infrastructure hack in the history of the world. It is probable that this event will be in the news for weeks to come.   News Colonial Pipeline Ransomware Hack This may end up being the largest infrastructure attack in U.S. history.  From the various reports, it looks like the threat actor that launched the attack is Darkside.  Darkside is a group thought to be Russian as they avoid Russian companies and others in Russian speaking former Eastern Block countries.  They released a statement Monday saying that it was an affiliated group and they were vowing to reign in their partners in the future to avoid causing social and political strife.  In the past, the  Darkside group has held themselves as social justice warriors taking down corrupt corporations and has been known to donate 10% of their ransoms to charities.   While none have indi...

2021 Week 17-18 Security Roundup

  Summary Spent a week driving around the western US then had to get caught up with work and school, so didn't have the time nor ability to post an update.  Here is what has happened over that time frame. For such a long time period there really is not too much actual news.  In my scanning of sites, it appears that the focus has returned to financial sectors and work from home attacks.  One of the things I have noted over the years is that these things tend to be cyclic, which could indicate that there is some dark web coordination that security practitioners are not yet privy to (though nation-state experts might be).   News Washington D.C. police server hacked by Russian group A Russian hacking group named Babuk posted screenshots that seek to prove that they have accessed several databases by the Washington D.C. police department.  The group left a text document on their network outlining how to pay the ransom to get locked files back and to bribe t...