Cybercriminals Switch File Types to Infect More Organizations with Malware
During the past year, spam volume increased considerably, as did the percentage of those emails that were malicious. The increase in malicious messages coincided with increased botnet activity. Botnets are now being used to send large-scale malware and ransomware campaigns. While spam email delivery of malware may have fallen out of favor in recent years, that is clearly no longer the case. During 2016, cybercriminals favored malicious Office macros and JavaScript for downloading their malicious payloads. However, the Microsoft Malware Protection Center has identified a new trend. Rather than JavaScript, which is becoming easier to identify and block, cybercriminals have turned to less suspicious looking file types to infect end users. Large-scale spamming campaigns are now being conducted that distribute malicious LNK and SVG files. These files are less likely to arouse suspicions than JavaScript and may make it past anti-spam defenses. LNK files – Windows shortcut files – are combined with PowerShell scripts which download malicious payloads when opened. Over the past year,...
Cisco Launches First Cloud-Based Secure Internet Gateway
The popularity of Software-as-a-Service (SaaS) applications has grown considerably in recent years. Working practices have changed, and SaaS is well suited to an increasingly mobile workforce. SaaS is certainly not a fad. The use of SaaS is likely to grow considerably over the coming years, with Gartner predicting an increase in SaaS use of 70% by 2018. While branch offices used to connect to the Internet via the corporate network, now many offices are connecting to the Internet directly, which means they bypass many network and Internet security controls. Not only does this increase risk, organizations potentially now lack visibility into threats targeting certain sections of the enterprise. One way organizations have got around this is with the use of virtual private networks (VPNs), although VPNs are not always used by employees. A recent survey conducted by IDG revealed 82% of mobile workers did not always use VPNs. An alternative strategy is to use on-premise web gateway solutions; however, multiple secure web gateways add complexity and latency and are therefore far from an...
Automatic Email Forwarding Rule Sent 1,700 Patients’ PHI to Employee’s Personal Account
Health Department officials in Multnomah County, OR, have discovered that an employee set up an automatic mail forwarder on an email account that sent all email correspondence to a personal Google email account for a period of around three months. The emails were forwarded to an account outside the control of Multnomah County, in violation of the Health Insurance Portability and Accountability Act. Since the employee works in the Health Department, emails sent to that individual’s official email account contained a range of patients’ electronic protected health information (ePHI). The ePHI included first and last names, ages, medical record numbers, medical diagnoses, dates of service, medication names and prescription numbers. The email forwarder was discovered during a random audit that was conducted on November, 22, 2016. An internal investigation into the incident revealed that the ePHI of 1,700 patients was exposed. The investigation did not uncover any evidence to suggest that any of the forwarded emails had been opened or read, but the possibility that ePHI was...
Singh and Arora Oncology Hematology Breach Notifications Sent After 5 Months
A Singh and Arora Oncology Hematology breach is finally being communicated to individuals who had their electronic protected health information exposed, although it has taken 5 months for those letters to be sent. The Health Insurance Portability and Accountability Act’s (HIPAA) Breach Notification Rule requires covered entities – healthcare providers, health plans, healthcare clearinghouses, and business associates of covered entities – to send breach notification letters to patients within 60 days of the discovery of an ePHI breach. The Department of Health and Human Services’ Office for Civil Rights (OCR) must also be notified of a breach in the same timeframe. However, in the case of the Singh and Arora Oncology Hematology breach, the Flint, MI-based cancer treatment center discovered that its systems had been breached on August 22, 2016. While OCR was notified of the breach on October 21, 2016, patients have only just started receiving their letters. The Singh and Arora Oncology Hematology breach actually occurred between February 27, 2016 and July 14, 2016. An...
New York Giants Star and ESPN Agree to Settle Privacy Breach Lawsuit
A privacy breach lawsuit filed against ESPN by New York Giant’s defensive end Jason Pierre-Paul has been amicably resolved. ESPN has agreed to settle the lawsuit, although the terms of the settlement have not been announced. On July 4, 2015, Pierre-Paul was involved in a fireworks accident and sustained serious burns to his hand. He was rushed to Jackson Memorial Hospital in Miami to receive treatment for his injuries. News soon broke that the NFL star had been taken to hospital, although it was initially unclear what injuries had been sustained. That was until details of the injuries were leaked to Schefter. Schefter sent a tweet containing a photograph of Pierre-Paul’s medical chart which showed Pierre-Paul had sustained serious damage to his hand that required the amputation of his index finger. The disclosure and dissemination of Pierre-Paul’s medical charts involved a violation of the Health Insurance Portability and Accountability Act (HIPAA), although not by Adam Schefter. While the HIPAA Privacy Rule prohibits the unauthorized disclosure of patients’ Protected Health...



