jikodesu, to apps
@jikodesu@mastodon.social avatar

We don't need another app to install.

When Grab PH bought motorcycle taxi app Move It, I thought I would become a 1st-time customer of that service. I use Grab, so it already has my info. I wouldn't need to sign up and type all my details. How convenient.

But Move It wasn't integrated into the Grab app. Instead, I would have to download a new app.

Bummer. One fewer customer for the company.

gombang,
@gombang@social.nancengka.com avatar

@jikodesu huh, strange. In Indonesia Grab already offer motorcycle taxi. It's not like they don't have any experience with it...

gowin, (edited )
@gowin@social.tchncs.de avatar

@gombang

That's true, and its because the motorcycles are under the Grab brand, while in PHL, it's a different brand.

I only tried motorcycles taxis in Indonesia, because I was advised that's the best way to get around, though I think the Jakarta BRT is awesome if it happens to be close to your origin/destination

Also, because I don't want to register/install another app 😆, just like @jikodesu

thenewoil, to Cybersecurity
cazabon, to Health

Another day, another #breach #notification #letter in the #mail...

This time, it's (get this...) my employer's Canadian subsidiary's group health plan's provider's banking partner's provider of file transfer services, #MOVEit.

It's 6 #degrees of #separation, but not in a good way.

"The type of #data accessed could include any of..." <everything needed for #identity #theft>, and as an extra-special bonus, "#Health information relating to a claim"!

And then they trigger my pet #peeve

[...]

cazabon,

"We have been closely monitoring this situation and have found no of any involved in this being further disclosed or misused".

Stop. The first part sounded like almost-an-apology, but this kind of weasel-language just throws that in the toilet.

Just that 1) you don't have sufficient audit records to know what information was accessed or for which clients, 2) you done screwed up, and 3) that anyone might have it by now, and you'd have no way to know it.

Freemind, to Cybersecurity
@Freemind@mastodon.online avatar

The breach, as outlined in Delta Dental of California’s notification, involved unauthorized access by threat actors who exploited a zero-day SQL injection flaw in the MOVEit file transfer software (CVE-2023-34362).

https://cybersec84.wordpress.com/2023/12/15/massive-data-breach-delta-dental-reveals-sensitive-information-of-7-million-patients/

ai6yr, to Cybersecurity
@ai6yr@m.ai6yr.org avatar
MHowell,
@MHowell@kolektiva.social avatar

@ai6yr You can get some idea here: Have I Been Pawned? https://haveibeenpwned.com/

ai6yr,
@ai6yr@m.ai6yr.org avatar

@MHowell My oldest (publicly published, company) email below, LOL.... 25 breaches.

geekymalcolm, to random
@geekymalcolm@ioc.exchange avatar

N.S. privacy commissioner to probe data breach that affected at least 100,000

https://www.cbc.ca/news/canada/nova-scotia/privacy-commissioner-investigating-data-breach-1.7051788

PogoWasRight, to random

CBIZ KA notified nine Prime Healthcare hospitals that some of their patient data was caught up in the . As I report this morning on databreaches.net, here are the 9 hospitals:

Saint Michael’s Medical Center,
Roxborough Memorial Hospital,
Garden City Hospital,
Landmark Medical Center,
Lower Bucks Hospital,
Saint Clare's Hospital,
Lake Huron Medical Center,
St. Mary's General Hospital, and
Suburban Community Hospital

According to a spokesperson for Prime Healthcare, it was just these hospitals and not any of their other 36 hospitals or more than 300 outpatient locations in 14 states.

I don't have any numbers yet on this one.

ai6yr, to Cybersecurity
@ai6yr@m.ai6yr.org avatar

LOL just noticed a tool available to me at an employer. "secure data transfer" to hackers, ha ha.

mle, to infosec

In light of yet more breach disclosures, @censys researchers took another look at MOVEit exposure across the Internet. In early May, prior to Progress Software's disclosure of the initial vulnerability, we saw just under 3,000 MOVEit instances online. Over the next few months, we saw the number drop slightly, and as of August, we observe a fairly consistent presence of around 2,200 instances online.

We have no way to know whether these instances are all patched and remediated, but based on recent MOVEit breach disclosures from AutoZone, Welltok, and others, it's possible some unpatched instances (and undiscovered intrusions 😓) remain.

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 🇬🇧 University of Manchester Speaks Out on Summer Cyber-Attack
➝ 🔓 🇺🇸 Hacktivists breach U.S. nuclear research lab, steal employee data
➝ 🔓 👀 Sumo Logic Completes Investigation Into Recent Security
➝ 🔓 🇺🇸 Auto parts giant AutoZone warns of data breach
➝ 🔓 🇨🇦 Canadian government discloses data breach after contractor hacks
➝ 🇦🇫 New 'HrServ.dll' Web Shell Detected in Attack Targeting Afghan Government
➝ 🇬🇧 🇰🇷 UK and South Korea: Hackers use zero-day in supply-chain attack
➝ 🇵🇸 🇮🇱 -Linked Using Rust-Powered SysJoker Against
➝ 🇷🇺 😱 “They are tired of him, but they are afraid”: what is known about the leader of the hacker group Killnet
➝ 🇰🇵 N. Korean Hackers Distribute Trojanized Software in Supply Chain Attack
➝ ▶️ 🛒 Play Goes Commercial - Now Offered as a Service to Cybercriminals
➝ 🇮🇳 Indian Hack-for-Hire Group Targeted U.S., , and More for Over 10 Years
➝ 🇷🇺 Russian hackers use feature and exploit to attack embassies
➝ 🇺🇸 🩺 Releases Cybersecurity Guidance for , Public Health Organizations
➝ 🇬🇧 🙏🏻 Thanking the vulnerability research community with Challenge Coins
➝ 🧅 Network Removes Risky Relays Associated With Scheme
➝ 🇺🇦 👋🏻 fires top cybersecurity officials
➝ 🩹 Johnson Controls Patches Critical in Industrial Refrigeration Products
➝ 🦠 🦀 New WailingCrab Loader Spreading via Shipping-Themed Emails
➝ 🦠 📨 New Agent Tesla Malware Variant Using ZPAQ Compression in Email Attacks
➝ 🦠 🎠 NetSupport Infections on the Rise - Targeting Government and Business Sectors
➝ 🚫 Google will limit ad blockers starting June 2024
➝ 🐛 ☁️ 3 Critical Vulnerabilities Expose Users to Data Breaches
➝ 🔓 ☁️ Researchers Discover Dangerous Exposure of Sensitive Secrets
➝ 🔓 ☝🏻 New Flaws in Fingerprint Sensors Let Attackers Bypass Hello Login
➝ 🔓 🩸 ‘’ vulnerability targeted by nation-state and criminal hackers: CISA
➝ 🐡 Researchers extract RSA keys from server signing errors

📚 This week's recommended reading is: "How I Rob Banks: And Other Such Places" by FC a.k.a. Freakyclown

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-472023

clarinette, to security
@clarinette@mastodon.online avatar
majorlinux, to infosec
@majorlinux@toot.majorshouse.com avatar

I bet nobody likes to MOVEit now.

AutoZone is the latest to fall to MOVEit issues - Desk Chair Analysts

https://dcanalysts.net/autozone-is-the-latest-to-fall-to-moveit-issues/

cybernews, to Cybersecurity

Health activation company Welltok has suffered a breach of its MOVEit Transfer server, exposing the health data of members of several health plan providers.

https://cybernews.com/news/welltok-moveit-breach-impacts-millions/?utm_source=mastodon&utm_medium=social&utm_campaign=cybernews&utm_content=post

majorlinux, to infosec
@majorlinux@toot.majorshouse.com avatar

Couldn't be me, though

Ransomware attack leaks nearly every Maine resident's data - Desk Chair Analysts

https://dcanalysts.net/ransomware-attack-leaks-nearly-every-maine-residents-data/

avoidthehack, to Cybersecurity

Basically all of Maine had data stolen by a gang

Add another to the list of those impacted by the MOVEit vulnerability/exploit.

Data compromised depends on the person and their interaction with Maine state entities. But data compromised could include:

  • social security numbers
  • taxpayer IDs
  • date of birth
  • medical information
  • driver’s license/state ID numbers
  • full names

https://www.engadget.com/basically-all-of-maine-had-data-stolen-by-a-ransomware-gang-061407794.html

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • everett
  • ngwrru68w68
  • magazineikmin
  • rosin
  • Youngstown
  • slotface
  • InstantRegret
  • khanakhh
  • mdbf
  • kavyap
  • cisconetworking
  • DreamBathrooms
  • JUstTest
  • cubers
  • ethstaker
  • tacticalgear
  • Durango
  • osvaldo12
  • normalnudes
  • modclub
  • GTA5RPClips
  • provamag3
  • tester
  • Leos
  • anitta
  • lostlight
  • All magazines