CyberSec Roundup
A synopsis of the Latest Cybersecurity News
Planned Parenthood Ransomed
Planned Parenthood of Los Angeles revealed that they were the victim of a ransomware attack in October. Patient information from approximately 400,000 of their clients was stolen during the attack, but the identity of the threat actors remains unknown. Planned Parenthood LA notified the affected patients of the breach and is investigating the incident with the help of a cybersecurity firm.
Cuba Ransomware on the Rise
In a recent Flash Alert, the FBI warned organizations to be aware that Cuba ransomware threat actors have compromised at least 50 entities in various sectors such as financial, government and healthcare. The hackers normally use phishing emails, Microsoft Exchange vulnerabilities and poorly secured remote access tools to deliver the malware onto target networks. They have managed to collect $43.9 million of $74 million in ransom demands so far.
Patch Zoho ManageEngine
There is a critical patch available for Zoho’s ManageEngine Desktop Central. The company hasn’t noticed the vulnerability being exploited as yet, but it could allow a threat actor to bypass authentication and execute arbitrary code in the Desktop Central MSP server. Customers are encouraged to patch the vulnerability tracked as CVE-2021-44515.
By: David Pinder
IT & Security Consultant
Certified Ethical Hacker (Master)