Mon Dieu! Nearly half the French population have data nabbed in massive breach
- Reference: 1707722828
- News link: https://www.theregister.co.uk/2024/02/12/infosec_news_roundup/
- Source link:
Payments outfits Viamedis and Almerys both experienced breaches of their systems in late January, the National Commission on Informatics and Liberty (CNIL) [1]revealed , leading to the theft of data belonging to more than 33 million customers. Affected data on customers and their families includes dates of birth, marital status, social security numbers and insurance information. No banking info, medical data or contact information was compromised, the CNIL added.
"This is the first time that there has been a violation of this magnitude [in France]," Yann Padova, digital data protection lawyer and former secretary general of the CNIL [2]told French radio network Franceinfo. Padova believes the breach is the largest in France's history.
[3]
Viamedis was [4]reportedly compromised through a phishing attack that targeted healthcare professionals, and used credentials stolen from such professionals to gain access to its systems. Almerys didn't disclose how its compromise occurred, but it's possible the ingress was similar in nature – it admitted the attacker gained access through a portal used by healthcare providers.
[5]
[6]
The CNIL said that it's working with Viamedis and Almerys to ensure those affected are informed – as is required under the EU's General Data Protection Regulation – but it'll likely take some time to get the word out to nearly half the country.
In the meantime, French officials are warning that the stolen data could be combined with data from other breaches to be used in phishing attacks or social engineering schemes. An investigation has been opened, the CNIL said, to determine whether either organization is at fault for the breach.
Juniper reportedly leaks customer info
Networking biz Juniper reportedly leaked information about the devices its customers owned, according to a Krebs on Security [7]report .
The source of the leak was Juniper's support portal, which was apparently found by a 17-year-old intern to allow searches on the name of any customer – and then to produce a list of devices they had acquired and registered with Juniper.
[8]
Juniper has fixed the flaw, which appears to stem from improper configuration of the Salesforce SaaS it uses to power its support site.
– Simon Sharwood
Critical vulnerabilities of the week
Cisco is [9]warning of some serious cross-site request forgery vulnerabilities in its Expressway Series devices that could give an attacker the ability to perform arbitrary actions on compromised devices.
There are three CVEs to be concerned with: CVE-2024-20252, CVE-2024-20254 and CVE-2024-20255, all of which affect the API for the collaboration hardware. "These vulnerabilities are due to insufficient CSRF protections for the web-based management interface of an affected system," Cisco explained. Patches are available, so get 'em installed on both Expressway-C and Expressway-E devices.
Elsewhere:
CVSS 9.8 – [10]Multiple CVEs : ProPump and Controls Osprey Pump Controller software prior to release 20230518 is affected by a whole slew of vulnerabilities that could give an attacker administrative control.
In known exploited vulnerability news:
CVSS 10.0 – [11]CVE-2023-22527 : Arctic Wolf security researchers say exploitation of [12]previously reported Atlassian Confluence Server vulnerabilities is continuing, with controllers of C3RB3R ransomware now trying to make use of the template injection flaw.
CVSS 8.8 – [13]CVE-2023-4762 : A known type confusion bug in Chromium's V8 JavaScript engine (in Chrome versions prior to 116.0.5845.179) that was [14]previously exploited to install Predator spyware is still being exploited.
No more tricks: Canada wants to ban the Flipper Zero
Canadian citizens who want to get their hands on the "multi-tool device for geeks" known as the Flipper Zero ought to move fast – the government [15]wants to ban them for fear they're being used to help criminals steal cars.
The government plans to pursue "all avenues to ban devices used to steal vehicles by copying the wireless signals for remote keyless entry, such as the Flipper Zero," Canadian public safety officials declared after a summit this week on combating auto theft.
The Flipper is a cool piece of hardware that's able to do a lot of stuff – but anyone familiar with the miniscule device is probably already shaking their head at the idea that the device, with its sub-GHz antenna, can help crooks steal cars.
[16]
Yes, [17]some models are [18]vulnerable to having wireless key fob codes sniffed. But most modern cars can't be cracked by the Flipper thanks to the use of rolling codes – supposing they're properly implemented, that is.
Besides, why hack a car when you can steal a Kia with some [19]brute force and an old USB cable ?
Florida man sentenced for dark web ID theft scheme … while already in prison
No, he didn't get caught with a tiny Linux box running Tor from under his mattress. Damien Dennis's long run as a con artist is just still catching up with him.
Currently [20]serving 12 years in prison for bank fraud and aggravated identity theft in Florida, Dennis [21]pled guilty this week to additional aggravated ID theft charges out of Georgia that appear related to his previous conviction.
Dennis was sentenced in Florida in 2022 for using fake IDs populated with real information to open bank accounts and take out fraudulent loans, in one case making off with $20k in cash using another person's identity.
Dennis didn't just buy and use stolen PII, though – he also crafted it into profiles to sell to other criminals, and offered guidance on how to use the dodgy dossiers to commit bank fraud.
The DoJ has added two years to Dennis's sentence for the trouble and fined him $250,000 as well. ®
Get our [22]Tech Resources
[1] https://cnil.fr/fr/violation-de-donnees-de-deux-operateurs-de-tiers-payant-la-cnil-ouvre-une-enquete-et-rappelle-aux
[2] https://www.francetvinfo.fr/sante/cyberattaque-chez-viamedis-et-almerys-ce-que-l-on-sait-du-vol-de-donnees-de-plus-33-millions-d-assures-en-france_6352741.html
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zcn6VX@9QQDde10zCjwzaQAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.euronews.com/next/2024/02/08/data-of-33-million-people-in-france-stolen-in-its-largest-ever-cyberattack-this-is-what-we
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zcn6VX@9QQDde10zCjwzaQAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zcn6VX@9QQDde10zCjwzaQAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://krebsonsecurity.com/2024/02/juniper-support-portal-exposed-customer-device-info/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zcn6VX@9QQDde10zCjwzaQAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-KnnZDMj3
[10] https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06
[11] https://arcticwolf.com/resources/blog/confluence-cve-2023-22527-leading-to-c3rb3r-ransomware/
[12] https://www.theregister.com/2024/01/22/atlassian_confluence_server_rce/
[13] https://nvd.nist.gov/vuln/detail/CVE-2023-4762
[14] https://www.theregister.com/2023/09/22/apple_emergency_patches/
[15] https://www.canada.ca/en/public-safety-canada/news/2024/02/government-of-canada-hosts-national-summit-on-combatting-auto-theft.html
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zcn6VX@9QQDde10zCjwzaQAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://www.theregister.com/2017/10/16/subaru_key_fobs_vulnerable_says_engineer/
[18] https://www.theregister.com/2022/03/25/honda_civic_hack/
[19] https://www.theregister.com/2023/02/15/hyundai_kia_software_upgrades/
[20] https://www.justice.gov/usao-mdfl/pr/jacksonville-man-sentenced-12-years-federal-prison-bank-fraud-and-aggravated-identity
[21] https://www.justice.gov/usao-mdga/pr/felon-lengthy-criminal-past-pleads-guilty-id-theft-dark-web-scheme
[22] https://whitepapers.theregister.com/
Re: Made me order a Flipper Zero
It does look like a fun toy, I'm not sure what I'd actually use it for though
Re: Made me order a Flipper Zero
Yeah, I'm not too sure, I guess I'm leaning in to that "fun toy" aspect of it. Maybe I'll find a use for it. That said, I don't have lots of free time.
Re: Made me order a Flipper Zero
"It does look like a fun toy, I'm not sure what I'd actually use it for though"
Amongst a plethora of illegal activities you could also break into cars that use RF for varying purposes.
Re: Made me order a Flipper Zero
There is a write up over on Ars Technica but it appears to be a lower cost protocol analyser for various RF tech.
Stated to be useless for stealing cars but one of Trudeau's (francophone?) ministers had his official car stolen three times which apparently really got on his tits (《courir sur son haricot》ou 《faire chier》)* which led to this ban.
* Translation into québécois left to the interested reader. :)
"it'll likely take some time to get the word out to nearly half the country"
Don't worry. I'm sure that spammers will be overjoyed to lend a helping hand, along with compromised emails, fake health portals and malware galore. They must be having a DefCon 1 moment right now.
Some people are going to have loads of fun this year, apparently . . .
Made me order a Flipper Zero
Now that was advertising that worked.