Flair Data Systems Cybersecurity News Update 6-05-2024

My name is Brent Forrest and I serve as a vCISO at Flair Data Systems. Here is your cybersecurity news update for 6/05/2024...

My name is Brent Forrest cybersecurity news update for 6/05/2024...

Good afternoon! 


Not a lot to report back on this week, as I have been out of pocket while working with some internal teams around our cybersecurity practice and today, I begin sitting in a 2-day class around Privileged Identity with BeyondTrust. 

 

So, let’s jump into this week's cybersecurity news update.... 

 

Checkpoint 0-Day  

 

CVE-2024-24919: Active Exploits target Check Point Security Gateway Zero-Day Information Disclosure flaw 

  • This activity has been seen exploited in the wild, if running Checkpoint VPN make sure you to resolve this as soon as possible 
  • Checkpointed noted that attempts to access these vulnerable systems that had old local accounts with unrecommended password-only authentication 
  • Link 2 contains fixes for the vulnerability that was released by Checkpoint 

Link (1): https://blog.checkpoint.com/security/enhance-your-vpn-security-posture 

Link (2): https://support.checkpoint.com/results/sk/sk182336 

 

44,000 individuals are affected by the breach of a major U.S. title insurance company 

 

First American Financial Corporation, 2nd largest title insurance company in the U.S., experienced a data breach that affected 44,000 individuals in Dec 2023 

  • In December 2023, First American took their systems down to contain the impact of the breach - however, they did not notify the SEC until May 28th (5 months later) once the investigation had concluded 
  • No one has currently been notified of their information being compromised, but First American has stated that they will be providing appropriate notification 
  • The concerning question here is 1) did it take them 5 months to determine a data breach actually occurred or 2) are they playing the rules against the SEC (material incident) as it is required that a 8-k is to be filed within 4 days of that determination 

Link (1): https://www.bleepingcomputer.com/news/security/first-american-december-data-breach-impacts-44-000-people/ 

 

 

Palo Alto firewalls found with crypto miner being deployed on them 

 

CVE-2024-3400: allows an unauthenticated attacker to execute arbitrary code with root privileges 

  • RedTrail is a new cryptocurrency mining malware being used in the wild against Palo Alto Firewalls through the above CVE 
  • The vulnerability has patched through the latest updates by Palo Alto 
  • Palo is not the only one being affected by RedTrail: TP-Link routers (CVE-2023-1389), ThinkPHP (CVE-2018-20062), Ivanti Connect Secure (CVE-2023-46805 and CVE-2024-21887), and VMWare Workspace ONE Access and Identity Manager (CVE-2022-22954) 
  • This goes back to threat actors ever evolving attack techniques to continue to profit in one way or another 

Link (1): https://thehackernews.com/2024/05/redtail-crypto-mining-malware.html 

 

STAR test DDoS attack 

 

An 18 year old, Keontra Lamont Kenemore, from Klein ISD is wanted for by the police for a cyberattack that disrupted the STAAR testing for thousands of students in the district 

  • The action, electronic access interference, is considered a third-degree felony 
  • The ability to do these types of attacks are very easy with the fact there are many services on the dark web that provide the ability to do DDoS-as-a-Service 
  • Due to the interruptions, students had to retake their STAAR testing over again - affecting over 24k students over two days 

Link (1): https://www.click2houston.com/news/local/2024/05/28/klein-isd-student-accused-of-orchestrating-cyber-attack-that-disrupted-staar-testing/ 

 

Ticketmaster hack affects 560 million customers, third-party denied liability 

 

ShinyHunters, Pokemon-themed hacker, has claimed responsibility for two high profile attacks - Ticketmaster and Santander Bank 

  • Two US customers of Ticketmaster have filed claims against Ticketmaster, claiming the company was negligent in protecting their data 
  • Snowflake has denied responsibility for either Ticketmaster or Santander Bank but has confirmed that a demo account for a former Snowflake employee was compromised, which did not contain sensitive data nor was it connected to production or corporate systems 
  • Both Ticketmaster and Santander Bank are claiming their data breaches were through third-party systems, but neither are naming which vendor it is 

Link (1): https://www.informationweek.com/cyber-resilience/-it-wasn-t-me-snowflake-denies-attack-responsibility-admits-hack-of-former-worker 

Link (2): https://www.informationweek.com/cyber-resilience/shinyhunters-strikes-again-group-hacks-santander-bank-ticketmaster-customers-file-suit 

 

HHS changes tack, allows Change Healthcare to file breach notifications for others 

 

Department of Health and Human Services has announced on May 31st that hospitals and health systems affected by the Change Healthcare incident can require UnitedHealth Group to perform the notification process to patients 

  • But to do so, the hospitals and health systems are to contact United Health directly   

Link (1): https://www.aha.org/news/headline/2024-05-31-hhs-says-hospitals-impacted-change-healthcare-cyberattack-can-delegate-breach-notifications#:~:text=%22Affected%20covered%20entities%20that%20want,be%20performed%20by%20Change%20Healthcare. 

 

3 billion records stolen from background check firm 

 

USDoD, cyber gang, has put the database of 2.9 billion records of US, Canada, and British citizens for $3.5 million 

  • Supposedly the data was obtained from National Public Data, a small information broker out of Florida that offers API lookups to other companies for things like background checks 
  • Interesting finding for this incident is that anyone that performed the Opt-Out option did not have their data in the breach - looks like the process has some benefits! 

Link (1): https://www.theregister.com/2024/06/03/usdod_data_dump/ 

 

Until next week, it’s Brent Forrest signing off. Be cyber safe my friends! 



About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or modern technology while enabling the business.  With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security. Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives. Specifically with EnLink Midstream, he spent most of his time building resilience and developing the cybersecurity program. 

Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. He lives in Dallas, Texas with his wife and children. 


About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S.  We provide trusted cybersecurity services in Fort Worth, TX. and the DFW Metroplex. 



Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 7/22/2024
July 22, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 7/22/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 7/17/2024
July 17, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 7/17/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 7/10/2024
July 10, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 7/10/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 7/03/2024
July 3, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 7/03/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 6/26/2024
June 26, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 6/26/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 6/19/2024
June 20, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 6/19/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 6/12/2024
June 12, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 6/12/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 5/29/2024
May 29, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 5/29/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 5/15/2024
May 15, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 5/15/2024.
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 5/8/2024
May 8, 2024
Brent Forrest, vCISO at Flair Data Systems, gives his weekly cybersecurity news update for 5/8/2024.
More Posts
Share by: