Le fabricant de vaccins AstraZeneca pris pour cible par des hackers nord-coréens #veille (29 nov 2020)

In Carnet de veille
Déroulez ici

Voici le rapport de veille de la semaine faisant le tour des actualités les plus intéressantes. Vous retrouverez un développement de certaines d’entre elles dans les prochains articles. Bonne lecture et belle semaine à vous !

Vol / perte de données

Personal data of 16 million Brazilian COVID-19 patients exposed online | ZDNet

The personal and health information of more than 16 million Brazilian patients has been leaked online after a hospital employee uploaded a spreadsheet with usernames, passwords, and access keys to sensitive government systems on GitHub this month. Among the systems that had credentials exposed were E-SUS-VE and Sivep-Gripe, two government databases used to store data on COVID-19 patients.

Sophos security breach exposes customer support records

“An access permission issue in a tool used to store information on customers” Well, this is awkward. Security firm Sophos is contacting “a small subset” of its customers warning that their details have been exposed following a breach in security.

Spotify Users Hit with Rash of Account Takeovers

Users of the music streaming service were targeted by attackers using credential-stuffing approaches.

NHS Error Exposes Data on Hundreds of Patients and Staff

Hundreds of NHS patients and staff have had their personal data exposed to strangers after internal process failures, it has emerged this week. Human error at NHS Highland earlier this month led to the personal information of 284 patients with diabetes being shared via email with 31 individuals, according to local reports.

Fertility Patients’ Sensitive Personal Information Stolen During…

US Fertility network took two months to go public about attack. Health information of patients may be at risk. Fertility clinics across the United States have been struck by a ransomware attack that has not only encrypted networks, but also stolen patients’ sensitive personal and medical information.

A hacker is selling access to the email accounts of hundreds of C-level executives | ZDNet

A threat actor is currently selling passwords for the email accounts of hundreds of C-level executives at companies across the world. The data is being sold on a closed-access underground forum for Russian-speaking hackers named Exploit.in, ZDNet has learned this week.

Hundreds of female sports stars and celebrities have their naked photos and videos leaked online

Threat actors have stolen naked photos and videos from hundreds of female sports stars and celebrities and leaked them online. The attack took place in the same hours as hackers hit Manchester Unitedand brings us back to mind the Fappening cases that exposed online cache of nude photos and videos of celebrities back in 2014.

Cyberattaques / fraudes

COVID Vaccine Maker AstraZeneca Targeted by Alleged North Korean…

Reuters today is running a story saying “suspected” North Korean hackers have targeted employees at British drugmaker AstraZeneca in an attempt to infect their computers with malware. The company is one of the leading groups developing a promising COVID-19… #AstraZeneca #covid #covidvaccine

Sopra Steria expects €50 million loss after Ryuk ransomware attack

French IT services giant Sopra Steria said today in an official statement that the October Ryuk ransomware attack will lead to a loss of between €40 million and €50 million. Sopra Steria is a European information technology firm with 46,000 employees in 25 countries providing a large array of IT services, including consulting, systems integration, and software development.

Tesla Model X hacked and stolen in minutes using new key fob hack | ZDNet

A Belgian security researcher has discovered a method to overwrite and hijack the firmware of Tesla Model X key fobs, allowing him to steal any car that isn’t running on the latest software update.

Hackers Dupe GoDaddy Into Helping Them Take Down Cryptocurrency Sites

Roughly one year after a data breach at GoDaddy compromised 28,000 customer accounts, the world’s largest internet domain registrar is once again at the center of a security scandal. Hackers brought down several cryptocurrency services using GoDaddy domains in recent weeks, and apparently the company’s own staff unwittingly helped in these attacks.

Brazilian government recovers from “worst-ever” cyberattack | ZDNet

After suffering the most severe cyberattack ever orchestrated against a Brazilian public sector institution, the Superior Electoral Court (STJ, in the Portuguese acronym) has managed to get its systems back up and running, after more than two weeks facing disruption.

FBI warns of criminals spoofing its website domain names

The FBI is warning internet users to be on their guard against copycat websites that spoof FBI-related domain names. According to a public service announcement issued today by Federal Bureau of Investigation, it has observed cybercriminals registering “numerous domains spoofing legitimate FBI websites.”

Cyberattaque contre les cliniques privées Hirslanden

Une cyberattaque a touché le groupe Hirslanden cet été. La NZZ rapporte en effet que des pirates informatiques sont parvenus à pénétrer jusqu’au cœur du réseau IT du groupe de cliniques privées le 21 juillet dernier. Ils ont pu chiffrer une partie du stockage central des fichiers.

Failles / vulnérabilités

Un journaliste s’immisce dans une visioconférence secrète de ministres européens

La ministre de la Défense néerlandaise a tweeté une photo sur laquelle on pouvait distinguer le code d’accès à la visioconférence avec ses homologues européens. Ce qui n’est pas passé inaperçu.

Une faille critique permettait de prendre le contrôle de dizaines de millions de sites Web

L’authentification forte d’un outil d’administration particulièrement populaire pouvait facilement être contournée par force brute. Un patch a déjà été diffusé.

Hacker posts exploits for over 49,000 vulnerable Fortinet VPNs

A hacker has posted a list of one-line exploits to steal VPN credentials from almost 50,000 Fortinet VPN devices. Present on the list of vulnerable targets are domains belonging to high street banks and government organizations from around the world.

Smart Doorbells Are Wide Open to Security Flaws

A consumer rights group has found security vulnerabilities in 11 popular smart doorbell products available on two of the world’s biggest online marketplaces. Which? enlisted the help of researchers at NCC Group to run tests on the smart devices they found on eBay and Amazon, many of which had scores of five-star reviews, were recommended as “Amazon’s Choice,” or on a bestsellers list.

Réglementaire / juridique

Romanians arrested for running underground malware services

Romanian police forces have arrested this week two individuals suspected of running two malware crypter services called CyberSeal and DataProtector, and a malware testing service called CyberScan. The arrests are the result of a joint operation conducted with the support of the FBI, Europol, Australian, and Norwegian police.

https://www.infosecurity-magazine.com/news/us-police-make-arrest-in-1m/

Home Depot agrees to $17.5 million settlement over 2014 data breach | ZDNet

Home Depot has agreed to a $17.5 million settlement in a multi-state investigation of a data breach suffered by the company in 2014. Delaware Attorney-General Kathy Jennings announced the settlement on Tuesday, in which a total of 46 states, as well as the District of Columbia, have reached a resolution with the US retailer.

Nigerians Arrested Over International BEC Scam

Alleged members of a Nigerian cybercrime gang that compromised 500,000 companies and government organizations in more than 150 countries have been arrested. The arrests were made in Lagos as part of the year-long, INTERPOL-led Operation Falcon targeting cyber-criminals who use business email compromise (BEC) scams to steal money.

Divers

Suspected Chinese hackers impersonate Catholic news outlets to gather intel about Vatican diplomacy

Written by Shannon Vavra Nov 23, 2020 | CYBERSCOOP After months of public reporting on a suspected Chinese hacking campaign targeting entities linked with diplomacy between the Vatican and Beijing, the hackers are still trying their luck.

La newsletter