Another #CitrixBleed, this one from mid November. 200k people impacted. HT @euroinfosec
https://apps.web.maine.gov/online/aeviewer/ME/40/5f9aa393-9c7a-49e0-855f-5e36adfb9e6c.shtml
#MOVEit, #Capita, #CitrixBleed and more: The biggest #data #breaches of #2023
Hackers had a busy year exploiting popular file-transfer tools and targeting under-resourced organizations
https://techcrunch.com/2023/12/27/moveit-capita-citrixbleed-biggest-data-breaches-2023/
The Church of Sweden(Svenska Kyrkan) was ransomwared on the 23rd of November. This is now being attributed to BlackCat.
Here's a #Citrixbleed vulnerable server serving a wildcard cert for *.svenskakyrkan.se, last scanned by Shodan on the 23rd. Probably not related at all
Like I always say, update yo stuff!
Comcast held a virtual door open for thieves to steal data - Desk Chair Analysts
https://dcanalysts.net/comcast-held-a-virtual-door-open-for-thieves-to-steal-data/
#Comcast Xfinity data breach affects over 35 million people
A #CitrixBleed fatality.
Data accessed includes customer usernames and hashed* passwords. Xfinity is forcing password changes next time you sign into an account.
In some cases data accessed may include:
- Last 4 of SSN
- DOBs
- Secret Questions / Answers exposed
#cybersecurity #security #infosec #xfinity
https://www.theverge.com/2023/12/18/24007082/xfinity-data-breach-hack-notice-citrix
Xfinity waited 13 days to patch critical Citrix Bleed 0-day. Now it’s paying the price - Enlarge / A Comcast Xfinity service van in San Ramon, California on Feb... - https://arstechnica.com/?p=1992160 #networkbreach #citrixbleed #security #comcast #xfinity #biz&it
#Comcast has disclosed a #CitrixBleed-related data breach which affected 35 million #Xfinity customers. The impacted info included names, contact information, last four digits of social security numbers, dates of birth and secret questions and answers.
https://apps.web.maine.gov/online/aeviewer/ME/40/49e711c6-e27c-4340-867c-9a529ab3ca2c.shtml
CTS, a cloud provider for legal firms in the UK, who were late patching #CitrixBleed, have appeared on Cactus ransomware's portal today.
They're offering downloads of CTS customer data. #threatintel
Two days left to patch those Netscalers against #Citrixbleed before you're on change freeze for a month!
Great take on HHS's #CitrixBleed alert in a recent edition of SANS NewsBites.
@merospit The #cybermuffins strategy worked for patching #citrixbleed
I recommend mass deployment of cyber muffins
Supply-chain ransomware attack causes outages at over 60 credit unions – Source: www.tripwire.com https://ciso2ciso.com/supply-chain-ransomware-attack-causes-outages-at-over-60-credit-unions-source-www-tripwire-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #grahamcluleycom #Vulnerability #CitrixBleed' #Grahamcluley #DataBreach #ransomware #Guestblog #Dataloss #Malware
Supply-chain ransomware attack causes outages at over 60 credit unions - Ransomware hits firm that providing cloud services to credit unions in order ensure that ... https://www.tripwire.com/state-of-security/supply-chain-ransomware-attack-causes-outages-over-60-credit-unions #vulnerability #citrixbleed #ransomware #databreach #guestblog #dataloss #malware
Supply-chain ransomware attack causes outages at over 60 credit unions.
Read more in my article on the Tripwire blog: https://www.tripwire.com/state-of-security/supply-chain-ransomware-attack-causes-outages-over-60-credit-unions
On Thursday, the Health Sector Cybersecurity Coordination Center (HC3), a component of the HHS security team, released a sector-wide alert with a specific focus on U.S. healthcare entities.
#Cybersecurity #CitrixBleed #Healthcare #USA #Government #Vulnerability #USHealthDept