Project Hyphae

Information Security News 11-20-2023

Share This Post

PJ&A Says Cyberattack Exposed Data of Nearly 9 Million Patients

Article Link:

  • Recently the medical transcription company Perry Johnson & Associates (PJ&A) began notifying impacted individuals of a cyberattack that occurred between March 27 and May 2, 2023.
  • According to the notifications sent to victims, a significant amount of information was accessed including full names, date of birth, Social Security numbers, medical record and hospital account numbers, insurance information, and more depending on what type of information victims had provided to their healthcare services.
  • In addition to other hospitals, Cook County Health, the largest healthcare provider in the Chicago area, and Northwell Health, New York’s largest healthcare provider, were among those with exposed patient data. Additionally, as a result Cook County Health has since announced that they are terminating its relationship with PJ&A.

Google Workspace Weaknesses Allow Plaintext Password Theft

Article Link:

  • Researchers at Bitdefender recently released a report that discussed how the local compromise of a Windows device could allow attackers to bypass MFA for the Google Cloud Platform and eventually steal passwords in plaintext format.
  • Specifically, the attack requires the attacker to leverage the organization’s Google Credential Provider for Windows (GCPW) to create a local Google Accounts and ID Administration (GAIA) account with elevated privileges. From there, attackers can steal or generate refresh tokens for the account and then leverage POST requests to gain access to any service within the issued token’s scope, including Google Drive, Gmail, and RSA keys used for passwords.
  • Bitdefender informed Google, who stated that they wouldn’t address the perceived issue as it falls out of the scope of what Google considers a “Google-specific bug” as it requires local access to occur.
  • Link to Bitdefender’s Report:

New York Proposes Cybersecurity Regulations for State’s Hospitals

Article Link:

  • The governor of New York has recently proposed a new set of cybersecurity regulations for the state’s hospitals. The New York Public Health and Health Planning Council is currently reviewing the rules.
  • The rules would require hospitals to develop security programs, hire a CISO, and more.
  •  If the rules are adopted, they would likely be published on December 6th with a 60-day comment period. After that, then the rules would be finalized, and organizations would have a year to comply with the rules.

New Report Examines Pressing K-12 Cybersecurity Concerns

Article Link:

  • A new report from MS-ISAC looked at the top threats and the state of cybersecurity at K-12 schools.
  • The top five concerns according to a survey of MS-ISAC members in K-12 schools include a lack of sufficient funding, increasing sophistication of threats, a lack of documented processes, a lack of a cybersecurity strategy, and an inadequate availability of cybersecurity professionals, in that order.
  • As the report highlights, K-12 organizations have generally shown maturity in maintaining and repairing industrial control and information systems, maintaining strong identity management and access control processes, and conducting cybersecurity awareness and training. However, they tend to struggle in supply chain risk management, audit log collection, data classification, and defending against malware threats.
  • Link to CIS MS-ISAC’s Report:

Nuclear and Oil & Gas are Major Targets of Ransomware Groups in 2024

Article Link:

Telemetry Gaps Leave Networks Vulnerable as Attackers Move Faster

Article Link:

  • Sophos recently released a report that reviewed 232 IR cases between January 1, 2022, and June 30, 2023, with 83% of impacted organizations having less than 1,000 employees. A key finding was that telemetry logs were missing in 42% of attacks studied and of those 42%, attackers disabled or wiped the logs in 82% of the cases.
  • The report highlighted the importance of logs in responding to incidents. Of the incidents reviewed, 38% had a dwell time of less than or equal to 5 days, emphasizing the importance of a quick response.
  • Link to Sophos’ Report:

CompTIA Advises Retailers to Check their Cybersecurity Preparedness Ahead of the Holiday Shopping Season

Article Link:

  • CompTIA and other organizations are highlighting the importance of retail organizations preparing for the possibility of malicious hackers launching attacks as the holiday season starts to ramp up.
  • In the short-term, it is recommended to verify that the latest security patches and software updates are applied, system inventories are reconciled, and a plan is in place for responding to potential incidents. Long-term, organizations should also focus on awareness training for employees.

Steps CISOs Should Take Before, During & After a Cyberattack

Article Link:

  • While each cyberattack is unique and requires its own response processes, there are several considerations vital for CISOs in preparing for incidents.
  • Much of the incident response legwork should occur prior to an incident occurring. Before a cyberattack, CISOs should forge strong relationships with leadership, build a comprehensive response framework with outlined roles and responsibilities, begin testing plans and playbooks in preparation for potential incidents, and educate stakeholders.
  • The article discusses the steps that should be taken during and after incidents as well. Specifically, during an incident CISOs should prioritize effective and empathetic communication with those responding. Following an incident, it is vital that there is reflection of the incident without any blame.

Defense Firms Can Take Steps Now to Comply With Enhanced Cyber Standards, Industry Officials Say

Article Link:

  • As the article notes, the DoD’s Cybersecurity Maturity Model Certification (CMMC) first went into effect in 2020 and the updated CMMC version 2.0 ruling is set to be released in the near future. While CMMC 2.0 has yet to be released, organizations can still work towards meeting the coming rules.
  • The article highlights that CMMC 2.0 will likely be long and complex. Likewise, the requirements are said to likely be difficult for some smaller firms as the DoD aims to set the initial bar high.
  • Although CMMC compliance will likely be challenging for many organizations, there are a variety of resources available for organizations to begin taking steps to meet the DoD’s requirements.

Reach out to our incident response team for help

More To Explore

CVE-2024-3596 | Attackers Blasting RADIUS

CVE-2024-3596 | CVSS:9.0 A new and emerging attacked named “Blast-RADIUS”, allows a man-in-the-middle attack between the RADIUS client and server to forge a valid protocol

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.