Flair Data Systems Cybersecurity News Update 12-20-2023

My name is Brent Forrest and I serve as a Field CISO at Flair Data Systems. Here is your cybersecurity update for 12/20/2023... 

Happy Wednesday and Merry Christmas! 

 

There has been an interesting set of events in play this week, even if there are only a few of them on the list below.  Some of these are updates and a few are new threats. Going into the end of the year, cyber criminals are not taking a break. So, in addition to this last cyber update of 2023, Jessica Nemmers and I took a moment to reflect and discuss some important focus areas to best protect your organization as we ring in the new year, if you want to check out that blog post as well: http://www.flairdata.com/end-of-year-cybersecurity-checkup-for-a-stronger-2024 

 

With next week being a short week due to Christmas and New Years, I plan on postponing my next update until 2024.  I hope you have a great Christmas with your family and friends and take time to catch a breath before 2024 strikes up in a couple of weeks.  Merry Christmas and Happy New Year! 

 

With that, let’s jump into this week’s cyber update... 

 

Box storage platform suffers outage 

 

Last Friday Box experienced a critical outage that prevented customers from accessing files that impacted logins, uploads, downloads, and API calls 

 

Alphv/Blackcat website seized  

 

On Tuesday (19th), the DOJ released a noticed that they had seized the domain of Alphv/Blackcat's systems through a multi-national operation to infiltrate and take down the ransomware gang 

  • This is the 3rd time over the years that law enforcement has breached Alphv's (the ransomware gang has operated under different names - DarkSide, BlackMatter, and now BlackCat/AlphV) 
  • Part of the operation allowed the FBI was able to obtain the encryption keys for 400+ organizations ransomed and built a decryption tool to help them 
  • Throughout the day, the FBI and Alphv were playing a game of seeing who could take the domain back which is capable of being done because both sides have the private keys used to register the onion URL in Tor 
  • Bad News: Alphv has also stated that the FBI had only captured roughly 400 companies' encryption keys but there are over 3,000 companies still in their possession and Alphv is stating those will never see their keys 
  • Now the even scarier part - because of this Alphv has stated that any restrictions they had in place against critical infrastructure and hospitals has been removed and are free game 
  • Link (1): https://www.bleepingcomputer.com/news/security/fbi-disrupts-blackcat-ransomware-operation-creates-decryption-tool/ 
  • Link (2): https://therecord.media/alphv-black-cat-ransomware-takedown-fbi 

 

MongoDB suffers breach 

 

Last Wednesday (13th), MongoDB detected an incident that led to investigating their systems and found that there was an unauthorized access of certain MongoDB corporate systems 

 

Seattle cancer center hit with ransomware 

 

Last Friday (15th), Hunters International ransomware group listed Fred Hutchinson Cancer Center on its leak site - claiming to have stolen 533 GB of data 

  • On December 11th, Fred Hutchinson Cancer Center had notified federal law enforcement agencies following the detection of unauthorized activity on its clinical network - however, this has probably been ongoing for a longer period of time 
  • It has been reported that the threat actor is also extorting individuals as well as the organization 
  • Ongoing investigation is underway 
  • Link (1): https://therecord.media/seattle-fred-hutch-cancer-center-ransomware-attack 

 

Hacking with Mr. Cooper 


This is an update to the incident / data breach that occurred on Oct 31st for Mr. Cooper 

 

SMTP smuggling to bypass email protections 

 

This was the results of a research project by SEC Consult Vulnerability Lab and Timo Longin 

  • By performing this exploit, it is possible to smuggle/send spoofed e-mails while still passing SPF alignment checks 
  • Microsoft, GMX, and Cisco Secure Email were products that the researchers identified vulnerabilities - Microsoft and GMX were able to fix these quickly... Cisco did not 
  • Please take the time to review the link - it is very informative and provides workarounds for Cisco 
  • Link (1): https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/ 

 

December Windows 11 Patch Breaks Wi-Fi Connectivity  

KB5033375 cumulative updated for December Patch Tuesday has been seen to cause Wi-Fi connectivity issues on some Windows 11 devices 

 

Comcast Xfinity Data Breach 


On December 18th, the Attorney General of Maine was notified of the Comcast breach 


Until next YEAR, it’s Brent Forrest signing off. Be cyber safe my friends! 


Merry Christmas and Happy New Year! 


About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or new technology while enabling the business.  With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security.  Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives.  Specifically with EnLink Midstream, he spent most of his time building resilience and developing the cybersecurity program. 



Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. 


He lives in Dallas, Texas with his wife and children. 


About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S.   


24 Apr, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 4/24/2024.
10 Apr, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 4/10/2024.
02 Apr, 2024
Are you being held hostage by the VMware pricing increases? Flair Data Systems discusses the top issues affecting your network cloud storage solutions and budget. Read on...
20 Mar, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 3/20/2024.
13 Mar, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 3/13/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 3/06/2024
06 Mar, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 3/06/2024.
On February 22nd, 2024- Flair Data Systems hosted Demo Day
05 Mar, 2024
On February 22nd, 2024- Flair hosted Demo Day, where technology partners were given the opportunity to pitch innovative technology and demo solutions to CIOs, CTOs, and CISOs from the DFW Metroplex. Read all about it!
My name is Brent Forrest and I serve as a vCISO at Flair Data Systems.
28 Feb, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 2/28/2024.
My name is Brent Forrest and I serve as a vCISO at Flair Data Systems.
21 Feb, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 2/21/2024.
My name is Brent Forrest and I serve as a vCISO at Flair Data Systems.
14 Feb, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 2/14/2024.
More Posts
Share by: