{"id":1121657,"date":"2024-01-30T22:27:11","date_gmt":"2024-01-31T03:27:11","guid":{"rendered":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/uncategorized\/cyber-security-headlines-microsoft-takes-another-hit-energy-giant-hit-by-ransomware-the-nsa-is-secretly-buying-your-ciso-series\/"},"modified":"2024-01-30T22:27:11","modified_gmt":"2024-01-31T03:27:11","slug":"cyber-security-headlines-microsoft-takes-another-hit-energy-giant-hit-by-ransomware-the-nsa-is-secretly-buying-your-ciso-series","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/nsa-2\/cyber-security-headlines-microsoft-takes-another-hit-energy-giant-hit-by-ransomware-the-nsa-is-secretly-buying-your-ciso-series\/","title":{"rendered":"Cyber Security Headlines: Microsoft takes another hit, Energy giant hit by ransomware, the NSA is secretly buying your &#8230; &#8211; CISO Series"},"content":{"rendered":"<p><p>Microsoft Teams takes another hit    <\/p>\n<p>    Adding to Microsofts recent woes, on the heels of the outage    on Friday that we reported on yesterday, the company has now    faced yet another outage. Thats two outages across North and    South America in the last three days. Microsoft confirmed that    Mondays outage impacted users in North America, Canada, and    Brazil, with customers experiencing connectivity issues or    delays in sending and receiving messages. As of this recording,    Microsoft released a statement on their X account    (formerly known as Twitter), stating they are actively    monitoring the situation, but all internal service telemetry    is healthy.  <\/p>\n<p>        (Bleeping Computer), Microsofts    X Account  <\/p>\n<p>    Schneider Electric continues to grapple with the aftermath of a    ransomware breach that targeted their sustainability business    division earlier this month. The energy management and    automation giant fell victim to a Cactus ransomware attack,    reportedly resulting in the theft of terabytes of corporate    data. According to Bleeping Computer, the ransomware gang is    now attempting to extort the company by threatening to leak the    stolen data.  <\/p>\n<p>    In a statement provided to Bleeping Computer,    Schneider Electric confirmed the attack and clarified that only    one division of the company was impacted., No word on whether    the company plans to negotiate with the ransomware group.    Customers of the sustainability business division include    Clorox, DHL, Hilton, and Walmart.  <\/p>\n<p>        (Bleeping Computer)  <\/p>\n<p>    The U.S. National Security Agency (NSA) wants to know what    websites and apps Americans are using. The agency has    acknowledged purchasing internet browsing records without the    need for a court order, as revealed in a statement from Senator    Ron Wyden, a member of the Senate Intelligence Committee. In a    letter to the Director of National Intelligence, Wyden stated,    The U.S. government should not be funding and legitimizing a    shady industry whose flagrant violations of Americans privacy    are not just unethical but also illegal. In response, the NSA    stated that they are  taking steps to minimize the collection    of U.S. person information.  <\/p>\n<p>    (Hacker    News,     Wyden Release)  <\/p>\n<p>    The IT software firm Ivanti is officially one week behind    schedule in releasing critical zero-day patches, and this delay    is just the beginning. Weve been covering this story since    early January when researchers at Volexity discovered a Chinese    government-backed hacking team exploiting two zero-day    vulnerabilities in Ivanti. The Cybersecurity and Infrastructure    Security Agency (CISA) issued an emergency directive, setting a    deadline for federal agencies to deploy fixes by January 22nd.    However, Ivanti has confirmed that the release of patches will    be delayed. Ivanti now aims to release some patches next week    for Ivanti Connect Secure (versions 9.1R17x, 9.1R18x, 22.4R2x,    and 22.5R1.1), Ivanti Policy Secure (versions 9.1R17x, 9.1R18x,    and 22.5R1x), and ZTA version 22.6R1x. Additional patches are    still expected to be released on a staggered schedule, but the    timing of those releases remains unclear.  <\/p>\n<p>    (Security    Week)  <\/p>\n<p>          Vanta is the leading          Trust Management Platform that helps you centralize your          efforts to establish trust and enable growth across your          organization.        <\/p>\n<p>          Over 6,000 companies partner with Vanta to automate          compliance, strengthen security posture, streamline          security reviews, and reduce third-party risk.        <\/p>\n<p>          To learn more, go to vanta.com\/ciso and watch          their 3-minute product demo.        <\/p>\n<p>    Three former Department of Homeland Security (DHS) employees    have been sentenced for conspiring to steal proprietary    software and sensitive law-enforcement databases from the U.S.    government for commercial use. According to court documents,    the stolen information included sensitive law-enforcement data    and personally identifiable information of over 200,000 federal    employees. The three individuals charged are Charles K.    Edwards, former Acting Inspector General of the DHS Office of    Inspector General, who received a 1.5-year prison sentence;    Sonal Patel and Murali Y. Venkata, both from the DHS-OIGs    information technology department, were sentenced to 2 years of    probation and 4 months in prison, respectively. The trio had    planned to use the stolen data to create a commercial software    product for sale to other government agencies.  <\/p>\n<p>        (Bleeping Computer), (U.S.    Department of Justice)  <\/p>\n<p>    SolarWinds is dismissing the SECs fraud charges against the    company as unfounded as they are unprecedented. We of course,    all remember that 18,000 organizations were impacted by the    supply chain attack, ranging from major entities like Microsoft    and Intel to government agencies such as the Pentagon and    Treasury. In the aftermath, the SEC filed a lawsuit against    SolarWinds, alleging the company and its CISO misled investors    about their security practices. SolarWinds has filed a motion    to dismiss the lawsuit, with a representative for the company    telling The Register that SolarWinds took the proper    steps when disclosing the incident. The company claims the    SECs lawsuit is an attempt to force companies to disclose    internal details about their cybersecurity programs. As    of this recording, the SEC has not responded to The    Registers request for comment.  <\/p>\n<p>    (The    Register)  <\/p>\n<p>    Ukraines agency for Prisoners of War faced a weekend    denial-of-service (DDoS) attack. According to The    Record, the agency works with families of military    personnel who were captured or missing and negotiates prison    exchanges and the return of bodies of fallen soldiers. Access    to the website has since been restored, the state agency claims    the attack aimed at suppressing information on a planned    prisoner exchange. While the hackers behind the attack have not    been identified, the agency has accused Moscow as retribution    for a recent Russian transportation crash.  <\/p>\n<p>        (The Record)  <\/p>\n<p>    Scammers beware. The FBI is warning about a government    impersonation scam that is primarily targeting seniors.    According to the FBI, from May to December 2023 this scam cost    victims over $55 million dollars. The fraudulent scheme    consists of instructing victims to liquidate their assets into    cash and\/or buy gold, silver, or other precious metals. Once    completed, the scammers would send couriers to retrieve the    items from the victim with the promise they would be put into a    secure account. Needless to say, those items were never seen    again.  <\/p>\n<p>    (Federal    Bureau of Investigations)  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Here is the original post:<br \/>\n<a target=\"_blank\" href=\"https:\/\/cisoseries.com\/cyber-security-headlines-microsoft-takes-another-hit-energy-giant-hit-by-ransomware-the-nsa-is-secretly-buying-your-data\" title=\"Cyber Security Headlines: Microsoft takes another hit, Energy giant hit by ransomware, the NSA is secretly buying your ... - CISO Series\" rel=\"noopener\">Cyber Security Headlines: Microsoft takes another hit, Energy giant hit by ransomware, the NSA is secretly buying your ... - CISO Series<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Microsoft Teams takes another hit Adding to Microsofts recent woes, on the heels of the outage on Friday that we reported on yesterday, the company has now faced yet another outage. Thats two outages across North and South America in the last three days.  <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/nsa-2\/cyber-security-headlines-microsoft-takes-another-hit-energy-giant-hit-by-ransomware-the-nsa-is-secretly-buying-your-ciso-series\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[94881],"tags":[],"class_list":["post-1121657","post","type-post","status-publish","format-standard","hentry","category-nsa-2"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/1121657"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=1121657"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/1121657\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=1121657"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=1121657"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=1121657"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}