Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

4/1/2019
04:25 PM
50%
50%

City of Albany Hit in Ransomware Attack

Few details yet on the March 30 ransomware attack.

The computer systems of the City of Albany, New York, suffered a ransomware attack over the weekend that still disrupted the city clerk's office today.

Albany Mayor Kathy Sheehan in a press briefing today said while some of the city's computers were down during the attack, no personal information appears to have been stolen, nor were emergency services dispatch affected.

City officials have provided few details on the attack, which began on March 30. 

Read more here

 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MelBrandle
50%
50%
MelBrandle,
User Rank: Moderator
4/19/2019 | 12:06:21 AM
Highly unexpected
It seems that attacks vary and we cannot truly anticipate from which channel that hackers would leak the virus into. One instance they are hitting the updates and on another instance, they are sending the virus directly onto machines. Attackers are getting more advanced these days so sometimes security lapses happen unknowingly out of the blue.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
4/5/2019 | 3:29:45 PM
Re: Cities are targets
Of course corect and since I am working with a malware forensics team, it seems obvious to us does it not?  You are dealing with civic mentality here, budgets and games.  Whomever controls IT in government holds real power and disruption of that power is frowned upon.   Admit that something is not done correctluy????  NEVER.   So goes civic IT departments.   And backups?  My forever mantra of shame. 
LironB107
50%
50%
LironB107,
User Rank: Apprentice
4/2/2019 | 3:44:28 PM
Cities are targets
Cities are vulnerable and therefore are a good target for attackers. Their characteristics such as their size, organizational structure and high level of communication with a wide variety of individuals, organizations and external entities make them a great opportunity for attackers, who look for easy targets with high value. 

The key problem is that most existing security solutions are reactive, adjusting their defenses based on past attacks. This is not effective considering that new attacks are emerging on a daily basis. A different approach must be taken.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
4/2/2019 | 8:14:52 AM
on NY State
I moved to Georgia in 2014 where we have some but real corruption in government.  Now NY State is different.  Albany is a cesspool of junk and vice and graft.  It's BAD, real bad and the governor is a sham, a king without clothes so expetcting honest admission here is an impossibility.  Not going to happen.  EVER.  
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15058
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
CVE-2020-15059
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
CVE-2020-15060
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
CVE-2020-15061
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.
CVE-2020-15062
PUBLISHED: 2020-08-07
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.