Verizon Publishes 2019 Data Breach Investigations Report (DBIR)
Verizon 2019 DBIR Shows Financially Motivated Attacks Increasing While Criminals Switch to Easiest Targets
The Verizon 2019 Data Breach Investigations Report (DBIR) was published just after midnight today. This is the 12th edition since its launch in 2008, and the most extensive to date, with 73 contributors and an analysis of 41,686 security incidents including 2,013 confirmed breaches. A breach is defined as an incident that results in the confirmed disclosure or exposure of data.
Cyberattack Cripples Baltimore's Government Computer Servers
Baltimore’s government on Tuesday rushed to shut down most of its computer servers after its network was hit by a ransomware virus. Officials believe it has not touched critical public safety systems.
Agents with the FBI’s cyber squad were helping city technology employees try to determine the source and extent of the cyberattack. Baltimore Mayor Bernard “Jack” Young said police, fire and EMS dispatch systems have not been affected, but other layers of the mid-Atlantic city’s network have been “infected with a ransomware virus.”
Microsoft Launches New Solutions to Protect Elections From Hacking
In an effort to make voting more secure and protect political parties and campaigns from cyberattacks, Microsoft this week added new solutions to its previously announced Defending Democracy Program.
The new solutions include ElectionGuard, a free open-source software development kit (SDK) developed in collaboration with Galois, and Microsoft 365 for Campaigns, a new service that brings high-end security capabilities to political campaigns.
Dell Patches Remote Code Execution Vulnerability in SupportAssist Client
Dell recently patched two security vulnerabilities in its SupportAssist Client, including one that could be exploited to achieve remote code execution.
Tracked as CVE-2019-3718, the first of the vulnerabilities is an improper origin validation flaw that could allow an unauthenticated remote attacker to potentially attempt cross-site request forgery (CSRF) attacks on users of the impacted systems.
State-Sponsored Hackers Use Sophisticated DNS Hijacking in Ongoing Attacks
With growing concern over DNS manipulation attacks, details on a new elite state-sponsored DNS hijacking campaign have been released. Called operation Sea Turtle, researchers believe that at least 40 different organizations across 13 countries have been compromised.
Researchers at Cisco Talos discovered the ongoing campaign targeting both public and private entities, and including national security agencies, located primarily in the Middle East and North Africa. While confident that the attackers are state-sponsored, the researchers do not attribute the campaign to any specific state. They do, however, believe that this campaign is separate from -- and more severe than -- the DNSpionage operations it described in November 2018.
