News – February 2024


  • India: EPFO, PMO data breach, Centre says aware of reports, Cert-In looking into details

    February 21, 2024

    The government is aware of reports of a data breach that claims having datasets from the Prime Minister’s Office (PMO) and the Employees’ Provident Fund Organisation, and has asked the Indian Computer Emergency Response Team (Cert-In) to look into it, senior officials told ET. “We are aware of it but need to verify if the claims ...

  • Cybersecurity for satellites is a growing challenge, as threats to space-based infrastructure grow

    February 20, 2024

    In today’s interconnected world, space technology forms the backbone of our global communication, navigation and security systems. Satellites orbiting Earth are pivotal for everything from GPS navigation to international banking transactions, making them indispensable assets in our daily lives and in global infrastructure. However, as our dependency on these celestial guardians escalates, so too does their ...

  • Toronto Public Library uncertain whose data stolen in October cyber attack

    February 20, 2024

    The Toronto Public Library needs more time to investigate whether cardholder, volunteer and donor data has been compromised during a serious cyberattack four months ago. In a final report to the board on the October 2023 security breach that the library said exposed the personal data of staff and family members, it said it is “currently ...

  • ConnectWise Releases Critical Security Update for ScreenConnect

    February 20, 2024

    ConnectWise has released a security update addressing two vulnerabilities in on-premise ScreenConnect deployments. The update addresses a critical authentication bypass vulnerability with a CVSSv3 score of 10 and a path traversal vulnerability with a CVSSv3 score of 8.4. A remote unauthenticated attacker could exploit these vulnerabilities to read arbitrary files, gain root access on the underlying ...

  • IACIPP ANNOUNCES LAUNCH OF ‘CIP WEEK’ IN EUROPE 12th-14th November 2024, Madrid, Spain

    February 20, 2024

    The International Association of Critical Infrastructure Protection Professionals (IACIPP) has announced the launch of ‘Critical Infrastructure Protection Week’ in Europe as part of an initiative focused towards enhancing collaboration and cooperation amongst the industry. With the imminent implementation of The Critical Entities Resilience Directive (CER Directive), which lays down obligations on EU Member States to take ...

  • Law enforcement disrupt world’s biggest ransomware operation

    February 20, 2024

    In a significant breakthrough in the fight against cybercrime, law enforcement from 10 countries have disrupted the criminal operation of the LockBit ransomware group at every level, severely damaging their capability and credibility. LockBit is widely recognised as the world’s most prolific and harmful ransomware, causing billions of euros worth of damage. This international sweep follows ...

  • Cambridge faces cyber attack

    February 19, 2024

    The University faced a cyberattack yesterday (20/02), which is affected internet and services across multiple UK higher education institutions. Students at various colleges were notified of the attack, which affected access to IT services such as CamSIS and Moodle. An internal email revealed that the incident was a Distributed Denial of Service (DDoS) attack, described as ...

  • UK: Council worker took tens of thousands of email addresses in massive data breach

    February 19, 2024

    A massive data breach by a worker at Stratford-on-Avon District Council saw tens of thousands of email addresses taken. The breach, which happened in November last year, was over a database of email addresses given by residents, the authority said. The probe found that around 79,000 email addresses from the garden waste collection database were affected. ...

  • SolarWinds Releases Critical Security Updates for Access Rights Manager

    February 19, 2024

    SolarWinds has released security updates addressing five remote code execution (RCE) vulnerabilities in Access Rights Manager (ARM). Path traversal vulnerabilities, CVE-2024-23476 and CVE-2024-23479, are both rated as critical with a CVSSv3 score of 9.6. An unauthenticated attacker could exploit these vulnerabilities, which could lead to RCE. Read more… Source: NHS Digital  

  • Ransomware Attack Disrupts Over 100 Romanian Hospitals, Including Cancer and Pediatric Centers

    February 19, 2024

    A massive ransomware attack has disrupted operations in multiple Romanian hospitals after encrypting databases and files. It targeted the Hipocrate Information System (HIS), an integrated healthcare management system sold by Romanian Soft Company (RSC). A significant portion of the Romanian healthcare system, including pediatric and oncology centers, was impacted, forcing staff to resort to manual systems ...