Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

October 2019

NNT Engineers Workshop: How to Implement a CIS Hardened Build Standard

Commercial and open source system configurations generally lack all the necessary security measures needed before deploying into production. These configurations will often times have features and functionalities enabled by default, making them less secure and a prime target for today’s cyber criminals.

Country of Georgia Hit by Widespread Cyber Attack

The small country of Georgia was hit by a cyberattack on Monday, knocking the national TV station and 2,000 websites offline in the nation's largest-ever cyberattack. A local web-hosting provider, Pro-Service, took the blame, claiming one of its servers that powers websites for media organizations, state agencies, and the private sector, was the target of the attack. The attack resulted in roughly 15,000 subscribers of website servers on the Pro-Service server crashing.

Italian Bank UniCredit Suffers Data Breach

Unicredit has reported a breach of its IT systems resulting in the leak of information belonging to over 3 million customers. The bank confirmed on Monday that a file created in 2015 containing three million records involving Italian clients is the source of the security incident. The victims' names, telephone numbers, email addresses, and cities where clients were registered are among the information compromised.

Senators Urge Investigation into AWS Following Capital One Breach

Two U.S. senators have demanded an investigation into Amazon Web Services to determine whether the cloud provider broke the law by failing to secure infrastructure that was compromised in the recent Capital One breach. Paige Thompson, a former AWS software engineer, has been accused of the attack on Capital One and 30 other organizations.

Ransomware Attack Takes Down German Automation Giant

One of the leading producers of automation tools is still experiencing outages after being hit by a ransomware attack over a week ago. German giant Pilz notified the prosecutor's office and the Federal Office for Security in Information Technology after experiencing a coordinated cyberattack on Sunday, October 13. The company has set up an incident response team to identify the source of the attack and mitigate the issue but has warned that these outages will persist for several more days.

Global Shipping Giant Pitney Bowes Hit by Ransomware Attack

Pitney Bowes, the US-based global shipping and eCommerce giant, informed customers on Monday that select services are unavailable due to a piece of ransomware that infected its systems. The company announced on Monday that a piece of ransomware encrypted files on some of its systems, rendering them inaccessible to users.

Microsoft and NIST Partner to Create Enterprise Patching Guide

Microsoft has partnered up with the U.S. National Institute of Standards and Technology (NIST) to create a guide designed to make enterprise patch management simpler. Microsoft originally worked with partners from the Center for Internet Security (CIS), the Department of Homeland Security (DHS), and the Cybersecurity and Infrastructure Security Agency (CISA), as well as customers.

Thousands of Online Shops Hit by Magecart Attack

Magecart attackers have been collecting sensitive information from thousands of online stores after compromising top eCommerce platform and payment service provider Volusion. Since September 7, hackers have activated online credit card skimmers on 3,126 online shops hosted by Volusion. That's according to Trend Micro security researchers' latest report.

CafePress Faces Class-Action Lawsuit Following Data Breach

CafePress is being served with a class-action lawsuit in the United States after allegedly failing to update its security software and informing customers of a data breach months after learning of the incident. The online gift shop retailer was criticized earlier this year for its weak cybersecurity and incident response after discovering 23 million customers had their personal information compromised in a data breach thought to have happened in February 2019.

Health Data Belonging to 1 Million New Zealanders at High Risk of Compromise

The health data belonging to nearly one million New Zealanders has been accessed illegally after a cyber attack on Tū Ora Compass Health's website. The website was hacked in August 2019, but investigations into the incident have found previous attacks dating as far back as 2016 to March 2019. Neither the firm nor New Zealand's Ministry of Health has been able to determine whether these attacks resulted in any medical information being accessed.

Cyber Attacks on UK Businesses Soar 243%

New research has found that cyber attacks on UK businesses increased by 243% over the summer, compared to the same time period in 2018. Hastings-based business ISP, Beaming, found that UK firms experienced 157,528 cyber-attacks each on average between July and September, up from just 45,970 during that same time last year. The company detected over 500,000 unique IP addresses used during the cyber attacks and found that the number originating from China more than doubled since last year.

FDA Issues Warning over Vulnerabilities in Medical Devices

The U.S. Food and Drug Administration (FDA) issued a formal warning on Tuesday on vulnerabilities detected in decades-old software used in many of today's medical devices and hospital networks. The warning claims that 11 vulnerabilities exist in IPnet, a third-party software component that supports network communications across computers.

Hearing Aid Giant Demant Warns of Extreme Losses Due to Ransomware Attack

Danish hearing aid manufacturer Demant has revealed that a suspected ransomware attack on its systems in September could cost the company over $95 million. The company experienced a 'critical incident' on September 3, but refuses to elaborate on the nature of the attack. Some researchers have speculated there are many indicators that it could be a ransomware attack that hit the firm causing a critical crash in the IT Infrastructure.