Cloud & IT Staffing Solutions in Chicago, Boston, Dallas
1

CyberSecurity

Cybersecurity Roundup for August–September 2024

Tech Hiring Company Chicago - Peterson Technology Partners
Tech Hiring Company Chicago - Peterson Technology Partners

DATE POSTED

September 24, 2024

CATEGORIES

Table of Contents

WRITTEN BY

Doug McCord
Doug McCord
Doug McCord has a diverse educational and professional background, with degrees in Computer Science from Oregon State and Cinema-Television from the University of Southern California. He has a passion for learning, writing, and sharing what he can with others.

“There appears to have been a data security incident that may have involved some of your personal information.” 

This is background-check provider National Public Data finally admitting to a hack of their system starting in late December of last year, with leaks in April and this summer. But word first broke through Bloomberg, from a class action suit about the breach. 

What’s at stake is 2.9 billion records of stolen data that supposedly contain information from the entire population of the US, Canada, and more. This includes email addresses, home addresses, names, social security numbers, and other personal information—at least some of which has been verified to be accurate, but it may not all be reliable. 

This is just the latest in the seemingly endless cascade of user data flowing from the Internet to criminals who are working to profit from it. And while we’ve often covered businesses losing customer data, this comes from a data aggregator who gathered it themselves from other sources. 

In this week’s cybersecurity roundup for August and September, we look at: the big breaches and changes in ransomware attacks in 2024, new attack types, a survey of corporate readiness, and what’s brewing in international cybercrime.  

With so many cybersecurity threats and attack surfaces available, let us help you keep up with the cyberattack news as we close out the summer of 2024!  

Ransomware/Breaches 

In a profile of security consultant Troy Hunt’s popular website Have I Been Pwned?, Scientific American writer Ben Guarino references stunning statistics: the website has more than 6 billion unique email addresses, and each account has been breached, on average, twice. This site allows users to enter email addresses to check exposure, a service that is increasingly in need with each passing month. 

And while that stat may be mind-boggling, results from a recent study by the University of Minnesota are more heartbreaking, finding that hospitals that experience severe ransomware attacks witness an increased mortality rate between 36–55%, which is even higher for patients of color (62–73%)   

Overall, ransomware attacks by volume have been down, but by the ransoms demanded (and paid) they’ve been way up, showing that attackers are focusing on fewer, bigger targets, many of which, unfortunately, are in healthcare. 

Ransomware Attack Stats and Trends 2024

These numbers climb daily.

Since we created the visuals above just a few days ago, attacks this month have reached 268.

Known ransomware attacks involving leaked data also climbed to 3,534 at the time of publication.

Ransomware groups now have more tools available.

The FBI and CISA recently issued an advisory about RansomHub.

RansomHub is a ransomware-as-a-service (RaaS) provider.

Its attack methods include:

  • Phishing
  • Password brute-force attacks
  • More than nine known exploits in internet-facing systems
  • Credential dumping
  • Lateral movement
  • Data theft tools such as PuTTY, WinSCP, and AWS S3 tools

According to Cybernews, RansomHub claims one victim every day on average.

Significant data breaches reported in August and September 2024 include:

  • National Public Data Breach: Hackers stole 2.9 billion records of personal data from people in the US, Canada, and Britain.

    The stolen information includes real social security numbers and other personal details.

    Because so much data was exposed, people should freeze their credit with the major reporting agencies:

    • Equifax
    • Experian
    • TransUnion

    Credit freezes are free and relatively easy to set up.

    They can help stop criminals from opening new accounts in your name.

    Security expert and former reporter Brian Krebs notes on Krebs on Security that enough personal information is already available to support identity theft.

  • Port of Seattle: Rhysida (RaaS) ransomware was used to encrypt data and shut down systems in late August.

    The attack disrupted:

    • Baggage services
    • Check-in systems
    • Parking
    • Other airport operations

    The government agency that runs the port refused to pay the ransom.

    Most systems were restored within a week.

    It remains unclear what stolen data may appear later.

  • Service Bridge Leaks 32 Million Documents: Security researcher Jeremiah Fowler discovered an open database containing 2.68TB of ServiceBridge customer data.

    The database was available without a password or other authentication.

    Exposed information included:

    • Work orders
    • Partial credit card data
    • Usernames
    • Email addresses
    • Phone numbers
    • HIPAA consent forms
    • Health information

    Some records dated back to 2012 and covered many different businesses.

    The database has since been secured.

    However, it is unclear how long the information remained exposed.

  • Disney’s Leak Get Worse: We wrote last time about Disney’s cybersecurity breakdown.

    Since then, the situation has become worse.

    The Wall Street Journal reported that the stolen data includes:

    • Financial information
    • Strategy documents
    • Employee information
    • Customer information
    • Passport numbers
    • Visa details
    • Some user login credentials

    The data covers services ranging from Disney Cruise Lines to ESPN+.

  • Halliburton Hacked: Multinational oil services company Halliburton confirmed a Reuters report from late August.

    Hackers gained access to company systems.

    Halliburton then took some services offline and activated its response plan.

    In September, the company filed with government regulators and confirmed that data had also been stolen.

    TechCrunch later reported that RansomHub claimed responsibility.

    The full impact of the attack remains unclear.

  • Microsoft Warns of Healthcare Attacks: In late September, Microsoft’s threat intelligence team warned about attacks on US healthcare providers.

    The attacks were linked to the Vanilla Tempest group using INC ransomware, another RaaS provider.

    Vanilla Tempest often uses different RaaS services to target:

    • Healthcare
    • Education
    • Manufacturing

    It remains unclear which organizations were targeted in this campaign.

On Attack Types and Readiness 

In addition to familiar attack methods, cybersecurity teams must also watch for new and updated threats.

Attackers often combine older techniques with tools and methods already used by the private sector.

Google’s Threat Analysis Group (TAG) reported on one example in August.

Russia’s Cozy Bear group used a watering hole attack that copied techniques linked to commercial spyware vendors Intellexa and NSO.

A vulnerable device could be attacked simply by loading an infected website.

This type of attack often targets devices that have not been patched.

Another example was profiled in depth by Seguranca Informatica in late August.

The attack used Microsoft Office files, including Word and Excel documents.

These files were disguised as financial reports.

Once opened:

  • VBA macros wrote a DLL file to disk
  • The DLL loaded into memory
  • A BAT file was downloaded from a server
  • A private key was also downloaded
  • An SSH backdoor was opened
  • A Cobalt Strike beacon was launched through legitimate Windows processes

This allowed attackers to keep control of the system while remaining hidden.

Windows also faced another serious security issue.

At the Black Hat security conference in early August, SafeBreach researchers revealed a flaw that could allow hackers to roll back your version of Windows.

This could restore older security weaknesses.

Some of those flaws could even allow attackers to take control of a machine.

Microsoft acknowledged the issue and began working on a fix.

WordPress also faced another major security problem.

A vulnerability was found in WPML, a widely used plugin for multilingual websites.

According to Cybernews, this was the third WordPress plugin requiring an urgent update in just the last two weeks.

A patch was released in August.

However, the vulnerability affected more than one million websites worldwide.

[For more on WordPress and alternative website solutions, check out this edition of The PTP Report.]

Cybersecurity readiness also remains a major concern.

The Cybernews Business Digital Index reviewed 1,000 global companies in the financial and healthcare sectors.

The results were troubling:

  • 63% received a D rating
  • 40% received an F
  • Only 11% received an A

The report also identified several common security problems.

Key Business Security Issues and Affected Percentage

Making matters worse, they found that 35% have high-risk vulnerabilities, with 49% having employees still reusing compromised passwords. 

International/Governance Corner 

In addition to the Port of Seattle attack mentioned above, US utilities are facing a sharp increase in cyber threats.

Check Point Research found that attacks against US utilities rose by more than 70% this year.

So far, these attacks have not caused large-scale shutdowns.

However, a coordinated strike could still create serious problems for critical infrastructure.

Elections have also increased cyber risks in 2024.

Countries around the world have faced attacks and misinformation campaigns.

The US is no exception.

Cyber activity has targeted both candidates and has been linked to several countries, including:

  • Russia
  • China
  • Iran
  • North Korea

North Korea also made cybersecurity news through fake job campaigns.

Attackers posed as recruiters from major companies.

They targeted workers in industries such as:

  • Aerospace
  • Energy
  • Technology

Malware was delivered through:

  • PDF files that appeared to contain job descriptions
  • Online coding challenges
  • Fake recruiting messages

Attackers often used real job descriptions.

They then changed the details to closely match the intended target.

This connects with tactics we covered previously.

In those cases, the attack worked in reverse.

Bad actors tried to get hired by security companies.

Once hired, they attempted to compromise their new employer.

Conclusion 

There’s much more to report on than we even have the space for, including cybersecurity regulations, the US prisoner exchange with Russia that included (for the first time) hackers, and law enforcement successes with Chinese hacking groups the Ghost cybercrime platform. 

It’s no surprise that profits are surging for many cybersecurity firms, too, with companies like Avast, Datadog, Palo Alto Networks, and Fortinet beating financial estimates over the period.  

But showing the scale and reach of these ongoing attacks, even Fortinet was breached, confirming in September a leak of some 440GB of customer data from a shared third-party cloud drive after they declined to pay a ransom.  

This concludes our coverage for now, but if you have need of cybersecurity experts, or are game to join the fight yourself, contact PTP for onsite or remote consultants! 

You can also catch up on our prior bi-monthly roundups here: 

References 

Security Incident, National Public Data 

What Giant Data Breaches Mean for You, Scientific American 

NationalPublicData.com Hack Exposes a Nation’s Data, Krebs on Security 

#StopRansomware: RansomHub Ransomware, CISA  

Ransomware newcomer RansomHub claiming one victim per day, Cybernews 

2 TB of Sensitive “ServiceBridge” Records Exposed in Cloud Misconfiguration, HackRead 

Port of Seattle says August cyberattack was Rhysida ransomware, CSO 

Leaked Disney data reveals financial and strategy secrets, WSJ reports, Reuters 

Halliburton confirms data was stolen in ongoing cyberattack, TechCrunch 

State-backed attackers and commercial surveillance vendors repeatedly use the same exploits, Google TAG Updates 

A Flaw in Windows Update Opens the Door to Zombie Exploits, Wired 

Microsoft warns of ransomware attacks on US healthcare, CSO 

Cybernews Business Digital Index reveals major shortcomings in corporate customer data security, Cybernews 

Cyberattacks on US utilities surged 70% this year, says Check Point, Reuters 

North Korean Hackers Lure Critical Infrastructure Employees With Fake Jobs, Security Week 

Fortinet confirms breach that likely leaked 440GB of customer data, CSO

WRITTEN BY

Doug McCord
Doug McCord
Doug McCord has a diverse educational and professional background, with degrees in Computer Science from Oregon State and Cinema-Television from the University of Southern California. He has a passion for learning, writing, and sharing what he can with others.

PREVIOUS POST

Spotlight on Innovation: Innovators Shaping 2024 and Beyond

NEXT POST

Adobe Experience Manager for Enhanced Digital Experiences

IT Staffing Firm - PTP