CenturyAvocado, to random
@CenturyAvocado@fosstodon.org avatar

Excellent work ... email they generate (via some system) doesn't pass or !

thenewoil, to Cybersecurity
0x58, to Cybersecurity

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #37/2023 is out! It includes the following and much more:

➝ ☁️ 🔑 How #Google Authenticator made one company’s network #breach much, much worse
➝ 🇬🇧 🔓 30k primary pupils’ data may be at risk after #Capita cyber attack
➝ 🇬🇧 🔓 #Manchester Police officers' data exposed in #ransomware attack
➝ 🇺🇸 🎰 #Caesars Entertainment says customer data stolen in #cyberattack
➝ 🇺🇸 🎰 #MGM Resorts shuts down IT systems after cyberattack
➝ 🔓 #Rollbar discloses data breach after hackers stole access tokens
➝ 🇫🇷 🔓 #Airbus Launches Investigation After Hacker Leaks Data
➝ 🇮🇷 Microsoft: Iranian espionage campaign targeted satellite and defense sectors
➝ 💸 Hackers steal $53 million worth of #cryptocurrency from #CoinEx
➝ 🧨 After #Microsoft and X, Hackers Launch DDoS Attack on #Telegram
➝ 🇺🇸 ❌ #California passes first-in-the-nation data broker deletion tool
➝ 🇨🇴 💸 Several Colombian #government ministries hampered by ransomware attack
➝ 🇮🇪 💰 #TikTok slapped with $368 million fine over child privacy violations
➝ 📱 📡 #Apple and Google Are Introducing New Ways to Defeat Cell Site Simulators, But Is it Enough?
➝ 🇺🇸 🔐 Washington summit grapples with securing #opensource software
➝ 🇷🇺 👀 Hacking #Meduza: Pegasus #spyware used to target #Putin’s critic
➝ ⚖️ 💻 The International Criminal Court will now prosecute #cyberwar crimes
➝ 🇵🇱 👀 Polish Senate says use of government spyware is illegal in the country
➝ 🦠 #Rust-Written 3AM Ransomware: A Sneak Peek into a New #Malware Family
➝ 🇺🇸 🥸 US Agencies Publish Cybersecurity Report on #Deepfake Threats
➝ 🐧 🦠 Password-stealing Linux malware served for 3 years and no one noticed
➝ 🍏 🦠 #MetaStealer Malware Targets Apple #macOS in Recent Attacks
➝ 🇮🇷 🦠 Iranian hackers #backdoor 34 orgs with new Sponsor malware
➝ 🩹 ☁️ Researchers Detail 8 Vulnerabilities in #Azure HDInsight Analytics Service
➝ 🍏 🔓 Mullvad #VPN Warns of Critical Firewall Flaw in Apple's MacOS #Sonoma
➝ ☁️ 🔓 New #Kubernetes #Vulnerabilities Enable Remote Attacks on Windows Endpoints
➝ 🇺🇸 💦 CISA offers free security scans for public water utilities
➝ 🩹 #Mozilla Rushes to Patch WebP Critical Zero-Day Exploit in Firefox and Thunderbird
➝ 🩹 Google Patches #Chrome Zero-Day Reported by Apple, Spyware Hunters
➝ 🩹 Microsoft September 2023 Patch Tuesday fixes 2 zero-days, 59 flaws

📚 This week's recommended reading is: "Extreme Privacy: What It Takes to Disappear" by Michael Bazzell

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-372023

Freedom_Press, to random
@Freedom_Press@kolektiva.social avatar

DWP awards Capita 5 years of contracts despite deaths
The government has awarded to Capita, on the same day that the company was linked to the death of a young disabled mum.
https://freedomnews.org.uk/2023/06/03/dwp-awards-capita-5-years-of-contracts-despite-deaths/

pauldyson, to random
@pauldyson@mastodon.social avatar

As a member of the Universities Pension Scheme my wife has been caught up in the data breach. Many sensitive personal and financial data points relating to her have been exposed to criminals.

As part of the ‘remediation’ she has been given a one year subscription to to see if her details are used to fraudulently sign up for loans, etc. In order to access this ‘service’ she has to provide even more personal information, some of it relating to me.

WTAF?

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

One of the amusing elements of the Capita saga yet to play out is the Civil Service Pension Scheme — which both the ICO and GCHQ use — has a Classic part managed by with Hartshead… which is part of the breached data.

keefeglise, to random

So the trusted with my sensitive data and they got hacked. Excellent work.

drstevenhale, to random

"Capita have identified from their investigations that personal data was “exfiltrated” (i.e., accessed and/or copied) by the hackers. The information accessed includes your title, initial(s), and name, your date of birth, your National Insurance number, your USS member number and your retirement date."

Oh, brilliant.

focaccio,

@drstevenhale It's ironic that a compromised company is hiring another previously-compromised company to monitor our data.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

TechCrunch published a story earlier today about Capita having an insecure S3 bucket. Capita claim the bucket is "industry standard practice" data, so I've published the file names. https://doublepulsar.com/capitas-standard-industry-practice-633gb-open-cloud-storage-5d87e7e96a70

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Council contacts 7,000 after data hack. This was the S3 bucket that they tried informing media contained “industry standard data”. https://www.bbc.co.uk/news/articles/c97992yg5weo

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Derby City Council have published an update on the open bucket issue. It turns out the bucket contained council tax data of residents, including personal data. For some reason tried telling TechCrunch and other reporters it didn’t at the time.

https://www.derby.gov.uk/news/2023/august/capita-data-breach-investigation-update/

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

The Guardian (who are themselves working out of a pub still due to a ransomware attack in December 2022) are reporting #Capita (a major IT supplier) have a "IT incident", staff have been told to not use VPN, and they are working with pen and paper since this morning. Thread follows. https://www.theguardian.com/business/2023/mar/31/capita-it-systems-fail-cyber-attack-nhs-fears?CMP=share_btn_tw

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The BBC report nearly a hundred companies have contacted the ICO so far about . https://www.bbc.co.uk/news/technology-65746518

misterprickles,
@misterprickles@mastodon.world avatar

@GossiTheDog

This isn’t the case. handle BPSS clearances, but SC and DV are handled by UKSV, part of the Cabinet Office.

You might want to update your Medium post.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

What Security Watchdog (owned by - they're currently mid sale to another company) do. I may have added the final line.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

have sold Security Watchdog to .

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

NHS England say they had data breach via of medical records of two active patients and two deceased patients https://www.england.nhs.uk/2023/06/nhs-england-statement-on-capita-cyber-incident/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Several months later, have told teachers in Sheffield they may have had a “potential” data breach. https://www.thestar.co.uk/taxonomy/term/2438/taxonomy/term/164/warning-as-sheffield-schools-hit-by-data-leak-after-hackers-target-capita-4177037

Long time readers of this very thread may remember I pointed out the Sheffield teacher breach over 2 months ago. https://doublepulsar.com/black-basta-ransomware-group-extorts-capita-with-stolen-customer-data-capita-fumble-response-9c3ca6c3b283

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Remember the Black Basta ransomware incident from March? It’s still playing out months later - one of the orgs say “We remain concerned at the level of information provided to USS by Capita”

https://www.ucu.org.uk/article/13020/Update-on-USS-Capita-data-breach

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The Times reports staff saying Capita “played down” the ransomware/extortion during internal meetings and reported that executives said that “attacks happened to all organisations” and “it is just a small breach”. https://www.thetimes.co.uk/article/capita-admits-hackers-also-stole-staffs-personal-details-jjkw3r7rs

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The Times ran the headline “Capita boss heads for exit with turnaround finished” attached to a puff piece, so I just checked on how are doing. Good that the turnaround is finished. A story in 4 pictures.

image/jpeg
image/jpeg
image/jpeg

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

In ’s financial results they say “minimal impact from cyber incident”, in a call with investors they described it as a non-event.

Good luck to Capita’s clients. 🫡

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Just over 2000 people are taking legal action against , including some of its own employees.

Note this report contains factual inaccuracies as it relies on Capita’s version of events.

https://www.theregister.com/2023/09/13/capita_class_action_2000_claimants/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

It’s been almost a year since the ransomware incident began. Here’s how the new CEO describes it in their yearly update.

There’s now some careful rewording around data exfiltration and “recovery activities” of said data.

The exact amount they book for incident response and recovery is £25.3m, and they do not mention if insurance will cover. Overall the business has booked a £106.6m loss for the year.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

cut the pension business out of their operational KPIs, citing the impact of the ransomware incident.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Investors react.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

’s new CEO has refused to say if they paid Black Basta ransomware group last year (they did). https://www.thetimes.co.uk/article/capita-in-the-red-as-more-cuts-announced-mrs9gkx97

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines