Good evening!
Today’s update brought back a wave of memories. I am reflecting on stories like the one about UnitedHealth, particularly regarding a significant turning point in my perspective on security. It's disheartening to see parallels between UnitedHealth's ordeal and an experience I had during a pen test years ago. The scenario of compromised credentials leading to unauthorized access via a non-MFA system, such as Citrix, feels all too familiar.
For me, that incident occurred over a decade ago during a sanctioned and paid engagement. However, for UnitedHealth, it unfolded as an unauthorized and paid engagement, resulting in widespread distress for countless individuals. It serves as a poignant reminder of the real-world consequences of security vulnerabilities and the importance of proactive measures to safeguard sensitive information.
With that, let’s get into today’s cybersecurity news update....
UnitedHealth Group CEO faces congress & cause of hack revealed
It has been publicly confirmed that UnitedHealth paid the $22 million ransom
Link (1): https://therecord.media/unitedhealth-ceo-testifies-senate-hearing
ByteDance on the clock to divest TikTok
ByteDance, the parent company of TikTok, has been given 9 months to sort out a deal to divest TikTok with the ability to extend for another 3 months if necessary
Link (1): https://www.theverge.com/2024/4/24/24139036/biden-signs-tiktok-ban-bill-divest-foreign-aid-package
Kaiser Permanente website tracking tools may have compromised customer data

Kaiser Permanente, a healthcare giant, has been notifying more than 13 million customers of their personal information had been potentially shared with third-party vendors
Link (1): https://therecord.media/kaiser-permanente-potential-third-party-data-exposure
Avast gets GDPR fine:
Avast, a Czech endpoint protection company, was fined by GDRP for $14.9 million for processing customers' data illegally per GDPR rules
Link (1): https://www.techradar.com/news/avast-hit-with-multimillion-euro-fine-for-gdpr-failure
Major U.S. wireless carriers face $200M FCC fine
AT&T, Sprint, T-Mobile, and Verizon are all being levied fines totaling nearly $200 million for illegally sharing access to customer's location information without consent
Marriott backtracks claims of encryption protection
Over the past 5 years, Marriot has defended its 2018 data breach by arguing that its encryption (AES-128) was strong enough and that it should be dismissed
Until next week, it’s Brent Forrest signing off. Be cyber safe my friends!
About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or modern technology while enabling the business. With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security. Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives. Specifically with EnLink Midstream, he spent most of his time building resilience and developing the cybersecurity program.
Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. He lives in Dallas, Texas with his wife and children.
About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S. We are a trusted cyber security company in Plano, TX.
SEO: flair data systems cybersecurity, cybersecurity blog, cybersecurity news, cyber security company plano tx