Posts

2021 Week 16 Security Roundup

  Summary While I initially thought this would be a slow news week, several articles of interest came out later in the week.  Probably the biggest thing of note is the Biden administration going all in to point the finger at nation-state actors and their attacks against U.S. and allied targets.   News National assessment Normally I try and skip a lot of reports put out by the national intelligence agencies as they are normally focused on the bigger picture and not on SLTT issues.  I have decided to link to the first worldwide threat assessment report in a couple of years because 1) it has been a while since the U.S. has publically acknowledged that we have a cyberwar going on and 2) they mention specifically the risks to utilities and governments at all levels in the United States (and its allies).   The main takeaways from the report are that even if the United States may have taken a break (which I suspect regardless of the guidance from the Executiv...

2021 Week 15 Security Summary

  Summary Not a lot of activity in the SLTT arena this week.  It appears that threat actors are currently targeting the financial sector. News 2 colleges in Ireland were hit with ransomware.  The attack actually occurred the previous week, but both universities made a joint announcement this week.  It was further reported that they did not believe that any personal data was removed. https://www.bleepingcomputer.com/news/security/ransomware-hits-tu-dublin-and-national-college-of-ireland/?&web_view=true Jobs The city of El Reno Oklahoma is hiring an IT director.  For more information check out the job posting on their website: https://www.cityofelreno.com/employment/

2021 Week 14 Security Summary

  Summary There was not a lot of activity of general interest this week.  Industrial control systems (ICS) security kind of had a spotlight on it.  ICS security is included in this blog as many local governments are responsible for power and water production and/or distribution.  Another hot topic was educational security, and I outline a couple of individual cases as well as general information. News Kansas water utility hack The DOJ announced they were inditing Wyatt Travnichek for hacking the Ellsworth Rural Water District No. 1 (AKA Post Rock Rural Water District) in Ellsworth County, Kansas In March 2019.  The DOJ is claiming that Travnichek tampered with the water purification and disinfecting systems via computers with the intent of causing harm.  If found guilty on all charges he faces 25 years in prison.  It appears that he was a former employee that had remote access privileges.  Apparently, when his employment ended in January 2019, his...

2021 Week 13 Security Roundup

  Summary This week there was not a lot of activity.  We did see quite a bit of news from the SCADA front.  A ransomware campaign has leaked some information in an attempt to get the victims to pay. News Power security The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security and Emergency Response (CESER) is pledging to help US energy system operators from the growing cyber and physical threat to their systems.  Some of the announced programs include testing of SCADA systems to assess their vulnerabilities against nation-state actors, research into electromagnetic and geomagnetic protective technologies, and a focus on researching cybersecurity with a goal of fostering well-trained university graduates.   https://www.energy.gov/articles/doe-announces-cybersecurity-programs-enhancing-safety-and-resilience-us-energy-sector https://www.infosecurity-magazine.com/news/new-cybersecurity-programs-to/?&web_view=true https://defensesystems.co...

2021 Week 12 Security Roundup

  Summary This blog is geared towards cybersecurity events that are of interest to State, Local, Tribal, and Territorial (SLTT) governments in the United States of America.  It is hoped that this focus will help SLTT information technology workers and policymakers to get the information relevant to their mission.  If you are in other sectors hopefully there is information you can find useful as well.   Updates on Solar Wind and the Microsoft ProxyLogon issues dominated news again this week.  Breaking news is that as of Thursday night, Defender and System Center Endpoint Protection have added automatic patching for the linchpin of the attack playbook.  This was so successful they evidently broke one of their honey-pot farms.   In other news, we had updates from the US and other Federal governments.  There are even more signs of escalation by nation-state actors, primarily China, in what many are seeing as a global cyberwar.  We also ...

2021 Week 11 Security Roundup

  Summary This blog is geared towards cybersecurity events that are of interest to State, Local, Tribal, and Territorial (SLTT) governments in the United States of America.  It is hoped that this focus will help SLTT information technology workers and policymakers to get the information relevant to their mission.  If you are in other sectors hopefully there is information you can find useful as well.   News Windows Outlook Vulnerability The 0-Day for Microsoft Exchange Server keeps making news.  Over the course of the week threat actors outside of the Haifum Chinese cyber espionage group started to take advantage of the exploit.  Many new breaches were identified over the weekend as organizations large and small rushed to update vulnerable servers.  From the briefings I have sat through over the last week or so, I can only add my echo to the chorus saying that you should immediately patch your on-premises version of Outlook.  Here are some of...

2019 Week 41 Security news summary

A couple of weeks ago 3 Alabama hospitals were struck with ransomware on the same day.  This caused patients to be diverted and surgeries to be postponed or moved to other facilities.  It was disclosed this week they have decided to pay for decryption. -           ThreatPost has this to say about the situation.  They do note that insurance plays a part in deciding to pay without specifically saying that it was an insurance company that made the choice in this case: https://threatpost.com/alabama-hospitals-pay-up-ransomware-attack/148937/ -             Cyware has an article on the hacking techniques that have been seen so far in 2019.  Some highlights: ( https://cyware.com/news/new-hacking-techniques-discovered-in-2019-so-far-3fac14b5 ) -           Ctrl-Alt-LED is a technique to use against air-gapped systems that us...