On Tuesday, January 17, 2023, the University of Texas at Austin announced that it has blocked TikTok access across the university’s networks. According to the announcement to its users, “You are no longer able to access TikTok on any device if you are connected to the university via its wired or WIFI networks.” The measure
Cybersecurity
LastPass Updates Disclosure of Security Incident
There are pros and cons to using a password manager [view related posts]. The biggest pro is that it helps keep all of our passwords organized and safe. The biggest con is that if the password manager is compromised, and the master password gets into the wrong hands, all of our passwords are compromised.
Password management company LastPass has been tackling several security incidents over the past few months. On August 25, 2022, LastPass informed its customers that it discovered unusual activity within its environment and determined that “an unauthorized party gained access to portions of the LastPass development environment…and took portions of source code and some proprietary LastPass technical information.” At that time, LastPass assured customers that their Master Password had not been compromised and didn’t recommend any action.…
Continue Reading LastPass Updates Disclosure of Security Incident
Nineteen States Have Banned TikTok on Government-Issued Devices
Governors of numerous states have issued Executive Orders in the past several weeks banning TikTok from government-issued devices and many have already implemented a ban, with others considering similar measures. There is also bi-partisan support of a ban in the Senate, which unanimously approved a bill last week that would ban the app from devices…
Chinese-Based Hackers Alleged to Have Stolen $20M in COVID-19 Relief Fraud Schemes
According to NBC News and Reuters, the United States Secret Service confirmed that hackers from APT41, a criminal cyber-hacking group linked to the Chinese Communist Party, stole “at least $20 million in U.S. Covid Relief benefits, including Small Business Administration loans and unemployment insurance funds in over a dozen states.”
According to the report…
South Dakota Governor Bans State Workers from Using TikTok
It is estimated that some 80 million Americans and more than one billion people use TikTok. It is well known that TikTok has a direct connection to the Chinese Communist Party, which is a foreign adversary of the U.S. This week, South Dakota Governor Kristi Noem signed an executive order banning all state workers or…
Health Care Organizations Warned of Venus Ransomware
The Health Care Sector Cybersecurity Coordination Center (IC3) recently released an Analyst’s Note to health care organizations providing information on a new variant of ransomware called Venus (also known as GOODGAME).
According to IC3, the threat actors “are known to target publicly exposed Remote Desktop Services to encrypt Windows devices.” The ransomware then “will attempt…
Joint Advisory Outlines Attacks by Daixin Team
The Cybersecurity & Infrastructure Security Agency, the FBI and the U.S. Department of Health & Human Services released a Joint Advisory last week warning organizations, particularly those in the health care and public health (HPH) sectors, of the ransomware and data extortion operations by the Daixin Team.
The Advisory is designed to provide information to…
CISA Lists Top CVEs Exploited by Chinese State-Sponsored Cyber Actors
The Cybersecurity & Infrastructure Security Agency (CISA) recently issued an Alert outlining the top Common Vulnerabilities and Exposures (CVEs) that have been used by the People’s Republic of China (PRC) state-sponsored cyber actors since 2020.
According to the Alert, these threat actors “continue to exploit known vulnerabilities to actively target U.S. and allied networks as…
CISA Recommends Following Microsoft’s Mitigation for Zero Day Exploits
Microsoft recently issued mitigation steps for vulnerabilities that are being actively exploited by threat actors. Microsoft stated that it is aware that two vulnerabilities are being actively exploited to access users’ systems.
The Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory following Microsoft’s release of the mitigation steps, encouraging “users and administrators to review…
Killnet Takes Credit for Disabling State Websites
Killnet, a Russian-speaking hacking group that emerged shortly after Russia invaded Ukraine, took responsibility last week for deploying a denial-of-service attack that temporarily took several U.S. states’ websites offline.
Although reported as unsophisticated, the attacks managed to affect the websites of Colorado, Connecticut, Kentucky, and Mississippi. The group’s goal is reportedly to disrupt U.S. state…