The State of Cybersecurity for K-12 School Districts

From the Center for Internet Security: K-12 cybersecurity personnel, IT professionals, and leaders have faced significant challenges over the last several years. They’ve had to wade through operational and technological complexities as a result of shifting between in-person, virtual, and hybrid schooling. Simultaneously, they’ve found themselves one of the primary targets of cyber threat actors...

New AxLocker ransomware encrypts files, then steals your Discord account

Bill Toulas reports: The new ‘AXLocker’ ransomware family is not only encrypting victims’ files and demanding a ransom payment but also stealing the Discord accounts of infected users. When a user logs into Discord with their credentials, the platform sends back a user authentication token saved on the computer. This token can then be...

Pointer: SuspectFiles interviews Venus ransomware group

Over on SuspectFile, Marco A. De Felice has written up an interview with Venus, a relatively new group in the ransomware landscape. You can read the interview here in both English and Italian.  I found Venus’s answers to be a bit confusing at times, but some things do become clear from the interview —...

No sign patient information leaked; Interdev platform for Canadian paramedic agencies taken offline

Brendan Burke of The Peterborough Examiner reports: There’s nothing to suggest patients’ confidential information has been compromised after a cybersecurity incident forced Peterborough County-City Paramedics’ data collecting software system to be shut down earlier this week, says Chief Randy Mellow. “There’s absolutely no evidence that this incident has caused any medical or personal information...

Indian govt Govt plans penalty of up to Rs 500 crore for data breach

Pankaj Doval reports: The government on Friday released the draft personal data protection bill, seeking to provide a framework for a strict user-consent regime for data processing, along with a penalty of up to Rs 500 crore for data breaches by social media and net companies while offering concessions to tech firms. Read more...

Gateway Rehab issues notice about June ransomware incident

On July 8, DataBreaches reported that Gateway Rehab in Pennsylvania had apparently become the victim of a ransomware attack by Blackbyte. DataBreaches’s report included redacted screenshots of files sensitive protected health information that had been leaked on the threat actors’ leak site. Gateway had not responded to inquiries from this site nor posted any notice...

San Gorgonio Memorial Hospital Back Online After Malware Attack

Toni McAllister reports: A six-day shutdown of electronic health records at San Gorgonio Memorial Hospital was due to a malware attack that remains under investigation by a team of forensics professionals, according to SGMH CEO Steve Barron. The attack occurred Nov. 10 and all systems at the 600 N. Highland Springs Avenue campus were...