Attacks/Breaches

6/29/2018
09:35 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail

The 6 Worst Insider Attacks of 2018 So Far

Stalkers, fraudsters, saboteurs, and all nature of malicious insiders have put the hurt on some very high-profile employers.
1 of 7

Image Source: Adobe Stock (Andrea Danti)

Image Source: Adobe Stock (Andrea Danti)

1 of 7
Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
No SOPA
50%
50%
No SOPA,
User Rank: Ninja
7/13/2018 | 9:58:34 AM
Yet Another Healthcare Breach - A Solution Soon?
Nuance is yet another healthcare breach that begs the question: When are Electronic Health Record (EHR) and medical application vendors going to wise up? In the EHR world (and even in the paper record world) de-identified patient data is an important step in the records workflow. Patient health information (PHI) from a medical record is stripped of all direct identifiers that can be used to identify the patient the record belongs to. Here's an idea inspired by that process that might actually work:

1. Any healthcare software vendor that houses patient data would be regulated to do the following:

a. Write into their PHI-housing software a feature that 1) encrypts PHI upon entry to the application, 2) ONLY decrypts the information for viewing and editing within the application based upon Multi-Factor Authentication (MFA) that could include user credentials, network IP signatures and local system certificates, etc. and 3) any attempt to extract the encrypted data outside the application database would results in a useless blob of encrypted information.

2. Any healthcare software vendor who did not execute #1 would be fined and withheld from Federal money until they achieved that task; perhaps incentives could be offered to encourage them, too.

This model is possible and while it took a long time just to move to EHRs, having the EHR and all the other medical software applications saves no money at all if they keep getting breached. The model above would protect PHI even from insider attacks because in order for anyone to read the PHI they would have to have all the required elements, including the application server, app client, local certificates, user logins, IP signatures and so on for the data to decrypt for viewing. Potentially massive PHI data breaches could be a thing of the past with something like this in place.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
7/13/2018 | 8:26:25 AM
Re: Whistleblowing
SUNTRUST had a horrible reputation in the IT field for firing a ton of workers to train Indian replacements and sign non-disclosures.  Theyhave zero respect for IT as it relates to corp and fully deserve what they bought. 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
7/3/2018 | 6:03:06 AM
Whistleblowing
Frankly, given the CEO's penchant for bombast, overstatement, and self-aggrandizement, I'm not entirely sure I personally find the Tesla employee's claims as untrustworthy here.

Moreover, employers tend to find whistleblowing to be just as much sabotage as actual wrench-throwing.

White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
The Fundamental Flaw in Security Awareness Programs
Ira Winkler, CISSP, President, Secure Mentem,  7/19/2018
Number of Retailers Impacted by Breaches Doubles
Ericka Chickowski, Contributing Writer, Dark Reading,  7/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14492
PUBLISHED: 2018-07-21
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
CVE-2018-3770
PUBLISHED: 2018-07-20
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.
CVE-2018-3771
PUBLISHED: 2018-07-20
An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.
CVE-2018-5065
PUBLISHED: 2018-07-20
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
CVE-2018-5066
PUBLISHED: 2018-07-20
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.