Good afternoon!
Not a lot to report back on this week, as I have been out of pocket while working with some internal teams around our cybersecurity practice and today, I begin sitting in a 2-day class around Privileged Identity with BeyondTrust.
So, let’s jump into this week's cybersecurity news update....
Checkpoint 0-Day
CVE-2024-24919: Active Exploits target Check Point Security Gateway Zero-Day Information Disclosure flaw
Link (1): https://blog.checkpoint.com/security/enhance-your-vpn-security-posture
Link (2): https://support.checkpoint.com/results/sk/sk182336
44,000 individuals are affected by the breach of a major U.S. title insurance company
First American Financial Corporation, 2nd largest title insurance company in the U.S., experienced a data breach that affected 44,000 individuals in Dec 2023
Palo Alto firewalls found with crypto miner being deployed on them
CVE-2024-3400: allows an unauthenticated attacker to execute arbitrary code with root privileges
Link (1): https://thehackernews.com/2024/05/redtail-crypto-mining-malware.html
STAR test DDoS attack
An 18 year old, Keontra Lamont Kenemore, from Klein ISD is wanted for by the police for a cyberattack that disrupted the STAAR testing for thousands of students in the district
Ticketmaster hack affects 560 million customers, third-party denied liability
ShinyHunters, Pokemon-themed hacker, has claimed responsibility for two high profile attacks - Ticketmaster and Santander Bank
HHS changes tack, allows Change Healthcare to file breach notifications for others
Department of Health and Human Services has announced on May 31st that hospitals and health systems affected by the Change Healthcare incident can require UnitedHealth Group to perform the notification process to patients
3 billion records stolen from background check firm
USDoD, cyber gang, has put the database of 2.9 billion records of US, Canada, and British citizens for $3.5 million
Link (1): https://www.theregister.com/2024/06/03/usdod_data_dump/
Until next week, it’s Brent Forrest signing off. Be cyber safe my friends!
About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or modern technology while enabling the business. With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security. Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives. Specifically with EnLink Midstream, he spent most of his time building resilience and developing the cybersecurity program.
Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. He lives in Dallas, Texas with his wife and children.
About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S. We provide trusted cybersecurity services in Fort Worth, TX. and the DFW Metroplex.