Security ills of health care sector draw senator’s attention

A vocal senator on U.S. cybersecurity matters wrote on Monday to four government agencies, seeking more information about how they are working to mitigate cyber risk in the health care sector. Sen. Mark Warner, D-Va., asked the agencies how they were working to resolve apparent security vulnerabilities and urged them to provide strategic recommendations on how to fend off attacks in the medical sector. Warner’s office wrote to the Food and Drug Administration, the Department of Health and Human Services, the Centers for Medicare and Medicaid Services and National Institute of Standards and Technology. The letter comes amid ongoing scrutiny over an apparent lack of security at many health care organizations. Hackers have haunted the industry for years, leveraging medical devices to steal valuable personal information or launch highly publicized ransomware attacks. The senator last week asked a number of health care organizations how the federal government can more effectively help rectify […]

The post Security ills of health care sector draw senator’s attention appeared first on CyberScoop.

Continue reading Security ills of health care sector draw senator’s attention

Russian hacker accused of creating NeverQuest malware pleads guilty

Stanislav Lisov, a Russian hacker accused of creating banking malware used to steal $885,000, pleaded guilty to one count of conspiracy to commit computer hacking in the U.S. Southern District Court of New York Friday. Lisov created the NeverQuest banking malware that was used against hundreds of financial institutions. It once was the third-most popular malware online, according to Russian security vendor Kaspersky Lab. Lisov was facing 35 years in prison when he was extradited to the U.S. from Spain after being apprehended in Barcelona in 2017. Lisov faces a maximum of five years in prison under the terms of his plea deal, according to his lawyer. “My client spent over a year in jail in Barcelona, Spain while in extradition,” lawyer Arkady Bukh said in a statement. “[It] then took over a year here in the United States to negotiate this plea.” Lisov was one of a number of […]

The post Russian hacker accused of creating NeverQuest malware pleads guilty appeared first on CyberScoop.

Continue reading Russian hacker accused of creating NeverQuest malware pleads guilty

U. of Washington Medicine learned it exposed info on 974k people after a patient found their data on Google

Medical data about nearly 1 million patients of the University of Washington Medicine was exposed online for at least three weeks in December, the school said in a statement this week. Data about approximately 974,000 individuals was included, the school announced Wednesday. UW Medicine is sending letters to the affected patients and has notified the Office for Civil Rights at the U.S. Department of Health and Human Services. A misconfigured database made visible patient names, medical record numbers, with whom the school shared patients’ medical information, and a description of what was shared, such as office vs. lab visits or patient demographic information. In some cases, exposed files included the name or a lab test that was performed, though not the result, or the name of a research study including the name of a health condition. The information in question became accessible on Dec. 4, 2018 “due to an internal […]

The post U. of Washington Medicine learned it exposed info on 974k people after a patient found their data on Google appeared first on CyberScoop.

Continue reading U. of Washington Medicine learned it exposed info on 974k people after a patient found their data on Google

Blind Eagle, a new APT group, poses as Colombia’s Cyber Police to steal business secrets

Cyberwar is intensifying in South America. A new hacking group researchers have dubbed Blind Eagle is carrying out targeted attacks against Colombian government agencies, financial companies and corporations with a presence in Colombia. Blind Eagle has been active since April 2018, posing as Colombian institutions like the National Cyber Police and the Office of the Attorney General to steal intellectual property, according to research published this week by the 360 Enterprise Security Group, which is affiliated with the Chinese security giant Qihoo 360. Researchers from 360 did not specifically identify the suspects who might be behind the group, which is also referred to as APT-C-36. But they suggested the attacks originated in South America, based on the timing the attacks were sent and the use of the Spanish language in the malware, among other factors. “[This] APT attack could probably be carried out by neighboring countries,” researchers said. “The background […]

The post Blind Eagle, a new APT group, poses as Colombia’s Cyber Police to steal business secrets appeared first on CyberScoop.

Continue reading Blind Eagle, a new APT group, poses as Colombia’s Cyber Police to steal business secrets

These scammers claim to have videos of your most private moments

Cybercriminals have scammed people out of $332,000 since July 2018 by threatening to publish footage of the individuals engaging in some kind of sexual act, according to research published Thursday. The threat intelligence company Digital Shadows examined 790,000 “sextortion” attempts sent to 89,000 email recipients to find that digital con artists typically build their bogus stories on existing information about real hacks. They often review a database of username and password credentials leaked in previous data breaches to find possible extortion victims. Upon contacting a user, scammers claim to have video of the victim watching internet pornography, providing the stolen password to boost their legitimacy. Others claim they exploited a known vulnerability in Cisco routers to monitor their web activity. The tactic was enough to convince more than 3,100 people worldwide to send bitcoin to 92 addresses, according to Digital Shadows. Attacks ranged from sloppy thieves who demonstrated little knowledge of how to organize such […]

The post These scammers claim to have videos of your most private moments appeared first on CyberScoop.

Continue reading These scammers claim to have videos of your most private moments

Complex court battle for Methbot, 3ve cybercrime suspects only is getting started

Alleged perpetrators of the Methbot and 3ve cybercrime rings have started to arrive in the U.S. to face accusations that they orchestrated a broad conspiracy to defraud advertisers for millions of dollars. Yevgeniy Timchenko, a 30-year-old citizen of Kazakhstan, appeared Wednesday in federal district court in Brooklyn alongside Aleksandr Zhukov, a Russian national, in a short status hearing. Both men had bald heads with facial hair and stood before the judge in beige jumpsuits. Lawyers asked for more time to review discovery materials in a case where the evidence is “extremely voluminous” and comes in multiple languages, including Russian and Bulgarian. The Department of Justice has linked Timchenko to 3ve and Zhukov to Methbot, two distinct ad-fraud operations outlined in the same indictment unsealed in November. Both groups used botnet-based schemes to boost web traffic numbers in plots to collect money from legitimate advertising companies lured into investing in seemingly trustworthy businesses. Members of Methbot and 3ve (pronounced “eve”), while working in different […]

The post Complex court battle for Methbot, 3ve cybercrime suspects only is getting started appeared first on CyberScoop.

Continue reading Complex court battle for Methbot, 3ve cybercrime suspects only is getting started

Kaspersky sales in North America fell by 25 percent in 2018, despite global revenue growth

Global revenue for Moscow-based cybersecurity vendor Kaspersky Lab increased by 4 percent last year despite sales in North America falling by 25 percent, the company said. The privately-owned Kaspersky reported an unaudited revenue of $726 million in 2018, thanks mostly to 27 percent growth in the Middle East, Turkey and Africa. Kaspersky also reported 55 percent growth in non-endpoint products and services. But the company also acknowledged that “the challenging geopolitical situation resulted in an overall slowdown in the North American market,” where sales fell by a quarter. Kaspersky’s sales announcement, published Tuesday, offers a glimpse at how scrutiny from the U.S. government has affected the company. President Trump in 2017 signed legislation prohibiting the use of Kaspersky software on computers and devices on military and civilian networks. The FBI also pushed private sector companies away from using Kaspersky products. U.S. officials have alleged Kaspersky is vulnerable to Russian influence, […]

The post Kaspersky sales in North America fell by 25 percent in 2018, despite global revenue growth appeared first on CyberScoop.

Continue reading Kaspersky sales in North America fell by 25 percent in 2018, despite global revenue growth

Hacking tools used by North Korea’s Lazarus Group aimed at Russian targets

One of the United States’ biggest cyber adversaries has been targeting another, according to new research. Security vendor Check Point Technologies on Tuesday published findings in which its researchers “were observing what seemed to be a coordinated North Korean attack against Russian entities.” The company cautions that it’s “problematic” to definitively pinpoint who’s responsible for such an attack, though “analysis reveals intrinsic connections to the tactics, techniques and tools used by the North Korean APT group[.]” Lazarus has been blamed for highly publicized attacks on Sony Pictures, the Bangladesh Bank heist, and could be a key part of North Korean efforts to evade international sanctions by pursuing international espionage. The suspicious activity in this attack occurred “over the past few weeks,” the company said. Check Point said its researchers were tracking malicious Microsoft Office documents that appeared to be designed specifically targeted at Russian victims. A closer inspection of the […]

The post Hacking tools used by North Korea’s Lazarus Group aimed at Russian targets appeared first on CyberScoop.

Continue reading Hacking tools used by North Korea’s Lazarus Group aimed at Russian targets

Splunk to exit Russian market amid growing government scrutiny

Security analytics provider Splunk no longer will do business in Russia, the company announced Monday in a blog post that may have created more questions than it answered. “Splunk is continually evaluating where we are investing and focusing our company resources,” the San Francisco-based firm said. “As part of this ongoing evaluation, we have decided Splunk will no longer be selling software and services to organizations in Russia — either directly or through partners.” The shift also includes ending opportunities with technical partners, resellers, distributors, and vendors, according to the announcement. Splunk intends to fulfill customer support obligations under existing contracts but will not expand or renew orders, it said. Splunk did not include specific details about what led to its decision. The company did not immediately respond to a request for more information from CyberScoop. The timing of the announcement comes amid growing Russian government scrutiny of foreign companies, […]

The post Splunk to exit Russian market amid growing government scrutiny appeared first on CyberScoop.

Continue reading Splunk to exit Russian market amid growing government scrutiny

Update from No More Ransom helps victims of GandCrab attacks

International authorities and the security company Bitdefender have released a new decryption tool meant to help people sidestep infections of the GandCrab ransomware, Europol announced Tuesday. The No More Ransom software initiative, which first began in 2016, is now enabling GandCrab victims to unlock their files for free without meeting extortionists’ demands. The updated No More Ransom software released Tuesday remedies GandCrab versions 5.0.4 through 5.1, which have infected victims since November 2018. “GandCrab has surpassed all other strains of ransomware in 2018, having infected over half a million victims since it was first detected in January last year,” Europol said in a statement. This particular No More Ransom tool was developed by Bitdefender in collaboration with Romanian police, Europol, and law enforcement from throughout Europe, the U.S. and Canada. Previous versions of the software have been downloaded more than 400,000 times, decrypting information for nearly 10,000 victims to the tune of […]

The post Update from No More Ransom helps victims of GandCrab attacks appeared first on CyberScoop.

Continue reading Update from No More Ransom helps victims of GandCrab attacks