Security Newsletter

Issue #272 · 18 October 2024

Nearly 400 US healthcare institutions hit with ransomware in the last year. New proposal for moving passkeys around. Also hacked robot vacuum cleaners turning racist.

Supported by 1Password.

News

Hi friends,

Busy newsweek this week. Not so much pants-on-fire news, just a lot of interesting articles. I hope I digested them down to an interesting yet quick read for you :-) Enjoy and have a good one!

Cheers,

  • Microsoft warns it lost some customer's security logs for a month: link.
  • 23andMe will retain your genetic information, even if you delete the account: link.
  • British intelligence services to protect all UK schools from ransomware attacks: link.
  • US disables Anonymous Sudan infrastructure linked to DDoS attack spree: link.
  • Google: 70% of exploited flaws disclosed in 2023 were zero-days: link.

Breaches and leaks

  • US healthcare org admits up to 400k people's data stolen: link.
  • BianLian ransomware claims attack on Boston Children's Health Physicians: link.
  • Insurance giant Globe Life facing extortion attempts after data theft from subsidiary: link.
  • Pokemon dev Game Freak confirms breach after stolen data leaks online: link.
  • Cisco investigates breach after stolen data for sale on hacking forum: link.
  • Japan's ruling political party hit by cyberattack from alleged pro-Russian hackers: link.

Issues and fixes

  • Critical Kubernetes Image Builder flaw gives SSH root access to VMs: link.
  • CISA adds SolarWinds flaw to exploited vulnerabilities catalog: link.
  • GitHub patches critical vulnerability in its Enterprise Servers: link.
  • Recently-patched Firefox bug exploited against Tor browser users: link.
  • Jetpack fixes critical information disclosure flaw existing since 2016: link.