HomeCybersecurity NewsNews roundup September 9, 2024
September 9, 2024

News roundup September 9, 2024

SAN MATEO, CA, September 9, 2024 — Cybersecurity news weekly roundup. Stories, news, politics, and events that impacted the network security industry last week. Sponsored by NetworkTigers.

Cybersecurity budgets shrink even as threats rise

A report from IANS Research and Artico Search has revealed that company cybersecurity budgets are flattening or even falling, with “uncertainty in the wider economy” cited as the main factor. According to the report, which surveyed 750 CISOs, some were not “able to increase their budgets, despite growing cyber-threats. A quarter of CISOs had flat budgets, and 12% saw funding cut back.” The report also indicates that organizations are taking a more targeted approach to security spending, shifting their focus to sophisticated, AI-driven threats. The budget restrictions have also affected recruitment, as hiring has slowed, with “one in three CISOs saying they are keeping their headcounts flat.” Chris Dimitriadis, chief global strategy officer at ISACA, says, “Cost continues to be a significant barrier for many companies looking to strengthen their cybersecurity efforts, where the return on these investments isn’t immediately clear.” Read more.

Avis discloses customer data breach

Car rental company Avis has disclosed that a cyberattack has compromised customer data in a breach notification letter sent to those impacted. According to the letter, “the company took action to stop the unauthorized access, launched an investigation with the help of external cybersecurity experts, and reported the incident to relevant authorities after learning of the breach on August 5.” The threat actor responsible stole some customers’ personal data, including their names and other information that Avis has not disclosed. The company has said that it has been working with outside experts to bolster its security. No significant details regarding the nature of the attack have been revealed, and no threat group has yet to claim responsibility. Affected customers have been offered a year of credit monitoring. Read more.

RansomHub claims attack on Planned Parenthood

Planned Parenthood has been hit with a cyberattack that required the organization to take down parts of its infrastructure. According to DEO and President Martha Fuller, the attack occurred in late August 2024. RansomHub has taken credit for the attack, threatening to release 93GB of stolen data if a ransom is not paid in six days. The group has “published various confidential documents on their extortion portal on the dark web as proof of their claims.” The news of the attack comes after US agencies issued a joint advisory about RansomHub’s propensity for targeting healthcare organizations. Due to the nature of services offered by Planned Parenthood, the breach could be a major privacy concern for patients. The nature of the information that may have been stolen has not been made public, as the investigation is ongoing. Read more.

Russians indicted for US election disinformation campaign

The US Department of Justice (DoJ) has indicted two Russian state media group employees, Kostiantyn Kalashnikov and Elena Afanasyeva, alleging that they used a Tennessee-based company to post disinformation content that received millions of views. The DoJ has said that the couple paid millions of dollars to a right-wing site called Tenet Media to post “Russian propaganda” across social media platforms to aid Donald Trump in his second presidential run and provide commentary on divisive issues. The Russians are said to have operated under fake names and provided funds to Tenet Media via shell companies. The US also seized 32 internet domains used for Russian propaganda. “Today’s actions show that as long as foreign adversaries like Russia keep engaging in hostile influence campaigns, they are going to keep running into the FBI. We will continue to do everything we can to expose the hidden hand of foreign adversaries like Russia and disrupt their efforts to meddle in our free and open society,” said FBI Director Christopher Wray. Read more.

Bitcoin ATM scams $110 million in 2023

The FTC has reported that Bitcoin ATM scams accounted for $110 million in losses last year, almost ten times the amount tracked in 2020. Bitcoin ATMs can be found in convenience stores and other locations with traditional ATMs. They allow people to buy and sell their crypto. Criminals have been impersonating law enforcement or government officials and tricking victims into depositing cash into the machines to safeguard their currency. However, the deposited cash goes directly into crypto wallets administered by the criminals. The FTC says these scams usually “start with a call or message about supposed suspicious activity or unauthorized charges on an account. Others get your attention with a fake security warning on your computer, often impersonating a company like Microsoft or Apple.” The agency is telling crypto investors never to move money in response to messages or calls that push a sense of urgency and reminding people that the government will never request that anyone do so. Read more.

$33.7 million for creating illegal facial recognition database

Clearview AI faces a $33.7 million fine from the Dutch Data Protection Authority (DPA) for violating the General Data Protection Regulation in the European Union by building an “illegal database with billions of photos of faces.” Referring to the technology as “highly intrusive,” Dutch DPA chairman Aleid Wolfsen said, “If there is a photo of you on the Internet-–and doesn’t that apply to all of us?-–then you can end up in the database of Clearview and be tracked. This is not a doom scenario from a scary film. Nor is it something that could only be done in China.” The database built by Clearview creates images that are then assigned a unique biometric code that is packaged and sold to law enforcement for the rapid identification of suspects, persons of interest, and victims. Wolfsen also said that the DPA is “now going to investigate if we can hold the management of the company personally liable and fine them for directing those violations.” Clearview has stated that it does not fall under the EU data protection laws and described the fine as “unlawful.” Read more.

Data stolen in Halliburton cyberattack

A cyberattack against Energy giant Halliburton saw threat actors access and exfiltrate information. Halliburton is currently “evaluating the nature and scope of the [stolen] information” after taking some of its systems offline following the attack’s detection. The company has not yet detailed the information stolen nor how much. It has confirmed that it is undergoing an “ongoing investigation and response” to assess the scope and nature of the attack. It has not yet made any statement regarding whether or not that incident resulted from a ransomware attack. However, considering current trends and the fact that TechCrunch has reportedly seen a purported ransom note associated with Halliburton from RansomHub, many believe that further information will reveal that it was one. Read more.

Aggressive social engineering attacks targets crypto firms

A warning from the FBI says that North Korean threat actor groups are targeting cryptocurrency companies and those that work for them with sophisticated social engineering schemes that infect victims with currency-stealing malware. The FBI’s warning describes the social engineering scams as challenging to detect, even among those well-versed in cybersecurity. The technique sees attackers homing in on crypto firm employees using the lure of new job opportunities or investments. “The actors usually communicate with victims in fluent or nearly fluent English and are well versed in the technical aspects of the cryptocurrency field.” The agency has also provided “a list of potential indicators of North Korean social engineering activity and the best practices that companies in the cryptocurrency industry and their employees should follow to lower the risk of compromise in such attacks.” Read more.

US agencies warn of RansomHub’s growth

CISA, in partnership with the Federal Bureau of Investigation (FBI), Multi-State Information Sharing and Analysis Center (MS-ISAC), and Department of Health and Human Services (HHS), has reported that threat actors associated with the RansomHub ransomware group “encrypted and exfiltrated data from at least 210 victims since its inception in February 2024.” The victims encompass many sectors, including “water and wastewater, information technology, government services and facilities, healthcare and public health, emergency services, food and agriculture, financial services, commercial facilities, critical manufacturing, transportation, and communications critical infrastructure.” The advisory describes how RansomHub operates, evades detection, and details mitigation information to help protect from a successful attack. Read more.

Fraud and account takeovers on the rise

According to data in the annual LexisNexis Risk Solutions Cybercrime Report, as many as one in four password recovery attempts are fraudulent. The findings indicate that attacks involving locking users out of their accounts by changing their passwords, called “detail change” attacks, rose by 232% in 2023. Media streaming, e-commerce, and mobile services are the most frequently targeted accounts. The drive is believed to result from increased bot usage by threat actors who quickly adopt new, sophisticated technology to expedite and enhance their tactics. It was found that desktop computers are more at risk of password reset attacks because desktop apps don’t have the same security protections that come built-in to mobile devices. Read more.

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles