Cybersecurity Roundup for April And May 2024
Peterson Technology Partners
25+ years of expert consulting and recruiting success. We guarantee innovative solutions and exceptional results.
It’s the end of May, 2024, and across America, doctors and nurses are using handwritten notes to chart patient issues. They’re sending faxes, and delivering orders by hand for tests and prescriptions.?
In 19 states, facilities associated with Ascension, one of the largest private healthcare systems in the US, have patients stuck in emergency rooms, waiting for lab results and reading machine results without the assistance of electronic uploads. They’ve diverted ambulances, as thousands of medical professionals revert to old methods because of a ransomware attack.?
It's an attack eerily reminiscent of the Change Healthcare event that paralyzed a healthcare billing system that handles a third of all American patient records, and is detailed here.?
It’s also an experience becoming all too-common in American healthcare, and we’ll look at the group behind this, and other cybersecurity highlights from the last two months, in our bi-monthly, Q2 cybersecurity roundup 2024.?
[Check out our prior cybersecurity roundup, for Q1 cybersecurity trends.]?
With so much going on, it’s our goal to help keep you informed, so you can be as proactive as possible with your data security, and overall cyber defense!
Headline Events for April and May?
We start with the biggest cybersecurity news, across the varying forms of cyberattack:
Security firm Rapid7 revealed a unique form of social engineering used by Black Basta, wherein they flood a target’s inbox with spam emails, and then follow up with a fake IT call. They claim they can resolve the issue if given remote access to a user’s machine temporarily, which they then use to seed their ransomware.
The Breachesnbsp;
Among specific cyber threats, data breaches—both as part of ransomware double extortion and independently—continue at pace, and here are some of the largest from this period:
Data Breaches April 2024:?
Data Breaches May 2024:?
On National Security?
As cybercrime is increasingly used as a weapon against rival nations, we shift to national-level security vulnerabilities and key regulatory developments:
领英推荐
The results were far and away led by Russia (1), followed by Ukraine (2), China (3), the United States (4), and Nigeria (5), with the top five well ahead the rest of the world in the risk posed.?
Conclusion?
This is just a sampling of the latest cybersecurity events making news in April and May, but also an ongoing reminder of the necessity of being proactive in defense, both personally, and as part of organizations that are under near-constant attack.??
[For help with your own cybersecurity, contact PTP to hire onsite or remote consultants.]
At Ascension, there’s been no timetable given for when the services will be back online. They’re working with federal law enforcement, and the pressure is spread across hospitals, as patients are rerouted by necessity and mortality rates increase in the fallout from this insidious crime.
Look for the next edition of our roundup around the final week of July, and until then, stay safe!
References?
The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind, Wired
#StopRansomware: Black Basta, CISA
Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators, Rapid7
U.S. Charges Russian Man as Boss of LockBit Ransomware Group, KrebsonSecurity
Thousands of servers hacked in ongoing attack targeting Ray AI framework, Ars Technica
AT&T Resets Millions of Passcodes After Customer Records Are Leaked, New York Times
Roku says 576,000 accounts breached in cyberattack, CNN
The not-so-silent type Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers, Munk School at the University of Toronto
Dell Confirms Database Hacked—Hacker Says 49 Million Customers Hit, Forbes
A (Strange) Interview With the Russian-Military-Linked Hackers Targeting US Water Utilities, Wired
Cyber Official Speaks Out, Reveals Mobile Network Attacks in U.S., 404 Media
The World Cybercrime Index: What is it and why is it important?, Tripwire
- Doug McCord
(Staff Writer)
Check out other articles from PTP on CyberSecurity and? AI?
Get the latest updates on recruiting trends, job market, and IT, and expert advice on hiring and job seeking at the PTP Report?