Brent Forrest Cybersecurity News Update 11-29-2023

My name is Brent Forrest and I serve as a vCISO at Flair Data Systems. Here is your cybersecurity update for 11/29/2023

It's a chilly morning this week and it is very welcome!  For those that know how much I truly love 
running, this week was the first week to break out the gloves.  Sadly, a few of the updates provided below have affected some businesses either in North Texas or East Texas.


As we move into the Holidays, it is the time for scams and phishing attempts to take a rise with sales, gift cards, and other tricks.  Please take the time to continue to educate your employees about the dangers that come along with the joys of the holiday season.  There are plenty of options available for bringing this awareness; KnowBe4, Wizer-Training, Proofpoint Security Awareness, Barracuda Security Awareness, and others.  Also remember, mixing both education (i.e., video, info graphics, etc.) and training (i.e., phishing tests, gamification) is a great way to solidify diligence when it comes to phishing (email), vishing (voice), and smishing (texting) attacks. 


Let’s dive into this week's “chilling” cyber update. 


Play Ransomware Update 


Play ransomware has shifted to a Ransomware-as-a-Service model. 

  • Utilizing legitimate credentials, exposed RDP servers, and exploits specific to FortiOS vulnerabilities for initial access. 
  • Propagating ransomware internally through GPO's, scheduled tasks, PSExec, or wmic where the ransomware extensions end with ". play" 
  • Incidents in November hit an all time high of 36 cases reported in a single day (Nov 28th)


Google to weaken ad blockers on Chrome in a push for security 


Starting in June 2024, adblockers (uBlock Origin as an example) extensions on Chrome will no longer work as intended. 

  • The older platform, Manifest V2, will be disabled as Chrome moves to Manifest V3 
  • V3 is supposed to bring more security, higher efficiency, and ask for few user permissions; yet with more limited feature sets will mean limited functionality. 
  • Speculation is that this is a way for Google to move away from 3rd party adblockers due to their loss in ad-revenue. 
  •  Link (1): https://cybernews.com/privacy/google-to-weaken-chrome-ad-blockers-push-for-security/ 


Fidelity National Financial attacks 


On November 22, Blackcat/AlphV publicly took credit for attack on Fidelity Nation Financial 

  • This attack has affected consumers attempting to close on their homes, causing delays on closing the purchase/sale of homes. 
  • The SEC 8-K Filing (Link 2) was released Nov. 19th per the filing, within the document they have restricted access to certain systems that has had a business disruption (title insurance, escrow, and other title related services, mortgage transaction services, and technology to the real estate and mortgage industry) 
  • No other information was released, other than that the threat actor gained access to certain FNF systems and acquired credentials. 
  • Blackcat/AlphV called FNF out on hiring Google Mandiant as their Incident Response 
  • Link (1): https://therecord.media/fidelity-national-financial-ransomware-alphv-black-cat 
  • Link (2): https://www.sec.gov/ix?doc=/Archives/edgar/data/1331875/000133187523000064/fnf-20231119.htm 

 

Gulf Air exposed to data breach 


Gulf Air, air carrier for Kingdom of Bahrain, has experienced an incident that resulted in the theft of sensitive customer information. 

 

Idaho National Labs data breach 


SiegedSec, a hacktivists group, leaked stolen HR data online that was obtained from Idaho National Labs (INL) 

  • INL is a nuclear research center ran by the U.S. Department of Energy - employing roughly 5,700 specialists in atomic energy, integrated energy, and national security 
  • SiegedSec is claiming to have obtained data on users, employees, and citizens with the following information: Name, DoB, Email, Phone number, SS#, Address, Employment Info 
  • As of right now, INL has confirmed that servers supporting their Oracle HCM system was affected and they are working to investigate the incident 
  • I have personally been to one of their training facilities several years ago where we were able to perform a true tabletop scenario of an attack on an Operational Technology environment where we had to protect a SCADA / PLC environment 
  • Knowing their team that protects their systems (at least at that point in time), there is no telling how long SiegedSec was in that environment moving around very slowly 
  • Link (1): https://www.bleepingcomputer.com/news/security/hacktivists-breach-us-nuclear-research-lab-steal-employee-data/ 

 

ownCloud releases 3 vulnerabilities 


CVE-2023-49103 (10): disclosure of sensitive credentials and configuration in containerized deployments (actively being exploited) 

 

North Texas water utility hit by cyberattack 


Daixin Team, cyber gang that first appeared in June 2022 and has also targeted Oakbend Medical Center (Richmon, TX), Fitzgibbon Hospital (Missouri), and Ista International (Germany) 

  • The Threat Actor's page on data exfiltrated is a bit interesting in that they claim to have obtained both PII and PHI data - yet this is a Water, Wastewater, and Solid Waste Management company, so how did they obtain PHI OR is this more of a canned statement? 
  • NTMWD (North Texas Municipal Water District) has stated that only the business network was affected and not any of the Operational network - most of which has been restored at this point. 
  • Pennsylvania water authority was also hit a bit harder by an alleged pro-Iran group (Cyber Av3ngers) by attacking an outpost (Municipal Water Authority of Aliquippa) - this outpost contains a collection of pumps that maintain water pressure and regulate water flow; equipment was taken offline, and they are utilizing backup tools to maintain water pressure. 
  • Link (1): https://therecord.media/north-texas-water-utility-cyberattack 
  • Link (2): https://therecord.media/water-authority-pennsylvania-cyberattack-pro-iran-group 

 

UT Health East Texas resumes divert status; access to MyChart, video visits unavailable in wake of cyberattack. 


Ardent Health Services, oversees 30 hospitals across the United States, experienced a severe ransomware attack in Oklahoma, New Mexico, and Texas 

 


Until next week, it’s Brent Forrest signing off. Be cyber safe my friends! 



My name is Brent Forrest and I serve as a vCISO at Flair Data Systems.

About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or new technology while enabling the business.  With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security.  Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives.  Specifically with EnLink Midstream, he spent the majority of his time building resilience and developing the cybersecurity program from the ground up. 

Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. 

He lives in Dallas, Texas with his wife and children. 


About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S.   


24 Apr, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 4/24/2024.
10 Apr, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 4/10/2024.
02 Apr, 2024
Are you being held hostage by the VMware pricing increases? Flair Data Systems discusses the top issues affecting your network cloud storage solutions and budget. Read on...
20 Mar, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 3/20/2024.
13 Mar, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 3/13/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 3/06/2024
06 Mar, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 3/06/2024.
On February 22nd, 2024- Flair Data Systems hosted Demo Day
05 Mar, 2024
On February 22nd, 2024- Flair hosted Demo Day, where technology partners were given the opportunity to pitch innovative technology and demo solutions to CIOs, CTOs, and CISOs from the DFW Metroplex. Read all about it!
My name is Brent Forrest and I serve as a vCISO at Flair Data Systems.
28 Feb, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 2/28/2024.
My name is Brent Forrest and I serve as a vCISO at Flair Data Systems.
21 Feb, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 2/21/2024.
My name is Brent Forrest and I serve as a vCISO at Flair Data Systems.
14 Feb, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 2/14/2024.
More Posts
Share by: