Posts

Showing posts with the label Canada

CrowdStrike update crashes Windows systems, causes outages worldwide

Image
By Ionut Ilascu,  Bleeping Computer A faulty component in the latest CrowdStrike Falcon update is crashing Windows systems, impacting various organizations and services across the world, including airports, TV stations, and hospitals. The glitch is affecting Windows workstations and servers, with users reporting massive outages that took offline entire companies and fleets of hundreds of thousands of computers. According to some reports, emergency services in the U.S. and Canada have also been impacted. Worldwide outage By the time of the correction, though, many large organizations across multiple verticals had already been affected. Some reports say that CrowdStrike’s update impacted some 911 emergency service agencies in the state of New York (EMS, police, fire department), Alaska, and Arizona, as well as 911 services in parts of Canada. A 911 telecommunicator in Illinois said that they were “working off of paper until things come back.” There also reports that the health hotlin...

British Columbia investigating cyberattacks on government networks

Image
By Sergiu Gatlan, Bleeping Computer The Government of British Columbia is investigating multiple "cybersecurity incidents" that have impacted the Canadian province's government networks. Premier David Eby said in a Wednesday statement that there is no evidence that the attackers had accessed or stolen sensitive information from the compromised networks. However, an ongoing investigation is assessing the incidents' impact and looking into what data, if any, may have been accessed. "Recently, the Government of B.C. has identified sophisticated cybersecurity incidents involving government networks," Eby said. "The government is working closely with the Canadian Centre for Cyber Security (Cyber Centre) and other agencies to determine the extent of the incidents and implement additional measures to safeguard data and information systems." The Government of B.C. has yet to disclose the number of cybersecurity incidents that impacted its networks and when...

CISA shares critical infrastructure defense tips against Chinese hackers

Image
By Sergiu Gatlan,  Bleeping Computer CISA, the NSA, the FBI, and several other agencies in the U.S. and worldwide warned critical infrastructure leaders to protect their systems against the Chinese Volt Typhoon hacking group. Together with the NSA, the FBI, other U.S. government agencies, and partner Five Eyes cybersecurity agencies, including cybersecurity agencies from Australia, Canada, the United Kingdom, and New Zealand, it also issued defense tips on detecting and defending against Volt Typhoon attacks. Last month, they also warned that Chinese hackers had breached multiple U.S. critical infrastructure organizations and maintained access to at least one of them for at least five years before being discovered. Authorities have observed that the cyber espionage group Volt Typhoon's targets and tactics differ from typical activities, suggesting their goal is to obtain access to Operational Technology (OT) assets within networks, which could be exploited to disrupt critical infra...

An Entire Canadian Town Is Being Extorted By Ransomware Cyber Criminals

Image
by Lane Babuder,  Hot Hardware Ransomware attacks have been on the rise. This time around, the small Ontario, Canada town of St. Marys has been targeted. The ransomware organization behind the attack seems to be LockBit. So far though, no ransom has been paid. The town itself claims that most city functions are still operational and staff are still working and getting paid. Upon visiting the official web site of the town visitors are greeted with a large red box containing the following quote. "The Town of St. Marys is currently investigating a cyber security incident that locked our internal server and encrypted our data. We are working closely with cyber security experts to investigate the source of the incident, restore our back up data, and assess impacts on our information, if any." "We have a skilled and knowledgeable team of Town staff, cyber security experts and legal counsel working around the clock to resolve any issues related to this incident. I have full con...

Canadian Affiliated With NetWalker Ransomware Group Pleads Guilty to Hacking Charges

By Sophie Webster, Tech Times A Canadian who previously worked as an IT expert for the Canadian government has pleaded guilty to being a high-level hacker. He also admitted to being a member of a Russian cyber-crime group. 

Our battle with China over the future of the Internet is just beginning

By Joseph Marks & Aaron Schaffer, Washington Post Welcome to The Cybersecurity 202! Before the month is over consider checking out Louis Malle's 1990 film “May Fools” about the 1968 Paris student riots. Arcade Fire's “Month of May” isn't half bad either.  Below: Twitter will pay a $150 million fine for collecting users' personal information for security but using it for advertising, and the U.N. Security Council is poised to vote on sanctioning North Korean hackers.  The United States has mostly won the fight to restrict China’s role in building next-generation 5G telecom systems over spying concerns. But the battle over who will control the future of global communications technology is only beginning. Canada belatedly joined the U.S. and its closest allies this month in blocking the Chinese tech giant Huawei from its 5G system.  The move followed years of warnings from U.S. officials that Huawei is too closely tied to the Chinese Communist Party and could be leaned...

New risk profile emerges for managed service providers

By Dr. Tim Sandle, Digital Journal The U.S., U.K., Australia and Canadian Cybersecurity Advisories have released a warning of an expected increase in attacks on managed service providers (MSPs). A managed security service provider provides outsourced monitoring and management of security devices and systems. Common services used by companies include managed firewall, intrusion detection, virtual private network, vulnerability scanning and anti-viral services. The main concern expressed by these state agencies is that if hackers are able to successfully breach a service provider’s network, the door is wide open for follow-up ransomware attacks across a provider’s infrastructure and customer base. In the wake of this warning, Mike Walkey, SVP Global Channels and Alliances at Veritas Technologies, tells Digital Journal why businesses should get up to speed. Walkey has developed some key points to advise MSPs and organizations on the best practices required to prepare and respond from rans...

Cybersecurity agencies reveal top exploited vulnerabilities of 2021

By Sergiu Gatlan, Bleeping Computer In partnership with the NSA and the FBI, cybersecurity authorities worldwide have released today a list of the top 15 vulnerabilities routinely exploited by threat actors during 2021. The cybersecurity authorities urged organizations in a joint advisory to promptly patch these security flaws and implement patch management systems to reduce their attack surface. Globally, malicious actors have been observed focusing their attacks on internet-facing systems, including email and virtual private network (VPN) servers, using exploits targeting newly disclosed vulnerabilities. "U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities assess, in 2021, malicious cyber actors aggressively targeted newly disclosed critical software vulnerabilities against broad target sets, including public and private sector organizations worldwide," the advisory reads. This might be due to malicious actors and security researchers releasing proof o...

Hackers Claim to Target Russian Institutions in Barrage of Cyberattacks and Leaks

Image
By Kate Conger and David E. Sanger, New York Times Hackers claim to have broken into dozens of Russian institutions over the past two months, including the Kremlin's internet censor and one of its primary intelligence services, leaking e-mails and internal documents to the public in an apparent hack-and-leak campaign that is remarkable in its scope. The hacking operation comes as the Ukrainian government appears to have begun a parallel effort to punish Russia by publishing the names of purported Russian soldiers who operated in Bucha, Ukraine, the site of a massacre of civilians, and agents of the FSB, a major Russian intelligence agency, along with identifying information like dates of birth and passport numbers. It is unclear how the Ukrainian government obtained those names or whether they were part of the hacks. Much of the data released by the hackers and the Ukrainian government is by its nature impossible to verify. As an intelligence agency, the FSB would never confirm a l...

Five Eyes Alert Warns of Heightened Risk of Russian Cyber Attacks

Image
By John Besley, Bloomberg Critical infrastructure organizations within the UK have been urged to ramp up their cyber security defenses as they face a heightened risk of Russian state-sponsored cyber attacks. An alert issued by the Five Eyes intelligence alliance, which consists of the UK, Australia, Canada, New Zealand and the United States, has warned the Russian government is exploring options for potential cyberattacks against critical organizations such as the NHS, nuclear power stations and parts of the civil service. According to the alert, "evolving intelligence" suggests hackers within the Russian government are seeking to engage in "malicious cyber activity" in response to the "unprecedented economic sanctions" imposed on Russia following its invasion of Ukraine. There is also concern that hackers are targeting critical infrastructure in countries that have provided "materiel support" to Ukrainian forces. There are also risks posed by nu...