Attacks/Breaches

8/9/2018
01:20 PM
50%
50%

PGA of America Struck By Ransomware

Hackers provided a Bitcoin wallet number, though no specific ransom amount was demanded, for the return of files.

While golfing fans have been all about this week's PGA Championship, extortion-minded hackers were more focused on the PGA of America's computer servers.

On Tuesday, employees at the sporting organization found themselves locked out of files relating to marketing materials for this week's event, in Missouri, and next month's Ryder Cup in France.

According to Golfweek, "Staff realized Tuesday morning that their systems had been compromised when attempts to work on the files generated an ominous message: 'Your network has been penetrated. All files on each host in the network have been encrypted with a strong algorythm [sic].'"

They were also warned not to try to break the encryption or else they might not be able to get back certain files.

The PGA said it won't respond to exortion demands; the hackers had included a Bitcoin wallet number, though no specific ransom amount was demanded. The situation remains unresolved as of yesterday.

Read more details here

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
8/13/2018 | 3:43:49 PM
Oh - eh - did they have a BACKUP?
Sounds like another case where an effective and tested backup and restoration plan WOULD be helpful.  I have been writing this for years and years.   Today I still have several 3.5" floppies (remember) from some of my earliest computers containing data.  Hey, you never know?
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Why We Need a 'Cleaner Internet'
Darren Anstee, Chief Technology Officer at Arbor Networks,  4/19/2019
4 Tips to Protect Your Business Against Social Media Mistakes
Guy Bunker, CTO of Clearswift,  4/22/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-16558
PUBLISHED: 2019-04-25
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
CVE-2018-18369
PUBLISHED: 2019-04-25
Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for executi...
CVE-2018-19442
PUBLISHED: 2019-04-25
A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute arbitrary code with root privileges via a crafted POST request to a nucleo.neatocloud.com:4443/vendors/neato/robots/[robot_serial]/messages Neato clou...
CVE-2019-9135
PUBLISHED: 2019-04-25
DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. .
CVE-2019-9136
PUBLISHED: 2019-04-25
DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed JPEG2000 format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.