CISA warns ‘most serious’ Log4j vulnerability likely to affect hundreds of millions of devices

Cybersecurity and Infrastructure Security Agency Director Jen Easterly told industry leaders in a phone briefing Monday that a vulnerability in a widely-used logging library “is one of the most serious I’ve seen in my entire career, if not the most serious.” “We expect the vulnerability to be widely exploited by sophisticated actors and we have limited time to take necessary steps in order to reduce the likelihood of damage,” she said of the Apache Log4j flaw. The issue is an unauthenticated remote execution vulnerability that could allow an intruder to take over an affected device.  Hundreds of millions of devices are likely to be affected, said Jay Gazlay of CISA’s vulnerability management office in the call with critical infrastructure owners and operators.   CISA, a component of the Department of Homeland Security, is setting up a dedicated website as soon as Tuesday to provide information and counter “active disinformation,” said Eric […]

The post CISA warns ‘most serious’ Log4j vulnerability likely to affect hundreds of millions of devices appeared first on CyberScoop.

Continue reading CISA warns ‘most serious’ Log4j vulnerability likely to affect hundreds of millions of devices

Canadian Citizen Charged for Ransomware Attacks in Alaska

By Deeba Ahmed
The accused became a suspect when the FBI contacted Canadian intelligence after observing a surge in ransomware attacks in Alaska in 2018.
This is a post from HackRead.com Read the original post: Canadian Citizen Charged for Ransomware A… Continue reading Canadian Citizen Charged for Ransomware Attacks in Alaska

Canadian hospitals recovering from breach that forced thousands of appointment cancellations

Intruders accessed patient and employee data after infiltrating health-releated IT systems in a breach that’s only now coming into focus. A security incident affecting the province of Newfoundland and Labrador, first detected Oct. 30, took down multiple health networks, leading to the cancellation of thousands of appointments, including for chemotherapy treatments. The regional Eastern Health authority, which employees 13,000 people, on Tuesday announced that its email system was again functioning, more than a week after the initial compromise became known. “As part of the on-going investigation into a cyberattack that impacted health care IT systems in Newfoundland and Labrador, it has been determined that some personal information and personal health information was accessed from the systems,” the provincial government said in a Nov. 9 news release. “A review is ongoing to determine if any other information is affected in the incident and further updates will be provided as appropriate.” Hackers […]

The post Canadian hospitals recovering from breach that forced thousands of appointment cancellations appeared first on CyberScoop.

Continue reading Canadian hospitals recovering from breach that forced thousands of appointment cancellations

White House set to lead 30 nations in ransomware discussions, sans Russia

The White House on Wednesday and Thursday will convene meetings with representatives from more than 30 countries to discuss how to counter ransomware, leaving out the country the president most frequently criticizes for hosting gangs of hackers: Russia. “Participants will cover everything from efforts to improve national resilience, to experiences addressing the misuse of virtual currency to launder ransom payments, our respective efforts to disrupt and prosecute ransomware criminals and diplomacy as a tool to counter ransomware,” a senior administration official told reporters on Tuesday. The official didn’t specify why Russia didn’t get an invitation beyond unnamed “constraints.” The lack of an invitation this time “doesn’t preclude future opportunities for them to participate.” The U.S. also has other avenues for discussing ransomware with the Kremlin, the official said. The lack of an invitation for Russia exemplifies the tensions over when the U.S. might involve more adversarial nations in discussions over […]

The post White House set to lead 30 nations in ransomware discussions, sans Russia appeared first on CyberScoop.

Continue reading White House set to lead 30 nations in ransomware discussions, sans Russia

Canadian IP Firm VoIP.ms hit by non-stop extortion based DDoS attacks

By Waqas
Although unconfirmed; the notorious REvil ransomware gang could be behind the DDoS attacks on VoIP.ms. Here’s what we know so far.
This is a post from HackRead.com Read the original post: Canadian IP Firm VoIP.ms hit by non-stop extortion base… Continue reading Canadian IP Firm VoIP.ms hit by non-stop extortion based DDoS attacks

Nuula raises $120M to build out a financial services ‘superapp’ aimed at SMBs

A Canadian startup called Nuula that is aiming to build a superapp to provide a range of financial services to small and medium businesses has closed $120 million of funding, money that it will use to fuel the launch of its app and first product, a line of credit for its users. The money is […] Continue reading Nuula raises $120M to build out a financial services ‘superapp’ aimed at SMBs