| Cyber / MSP / MSSP | An authentication bypass vulnerability allowing remote code execution was discovered in the User Portal and Webadmin of Sophos Firewall and responsibly disclosed to Sophos. It was reported via the Sophos bug bounty program by an external security researcher. The vulnerability has been fixed. There is no action required for Sophos Firewall customers with the “Allow automatic installation of hotfixes” feature enabled. Enabled is the default setting. Sophos has observed this vulnerability being used to target a small set of specific organizations primarily in the South Asia region. We have informed each of these organizations directly. Sophos will provide further details as we continue to investigate. https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce |
| Healthcare | The healthcare industry suffered the highest number of cyber attacks in 2021, with ransomware the leading danger, as bad actors took advantage of the Covid-19 pandemic, a study by Cisco has found. “The main reasons adversaries are continuing to target this industry is due to healthcare providers’ often underfunded cyber-security budgets and extremely low downtime tolerance, the latter of which has been exacerbated by the ongoing Covid-19 pandemic.” https://www.thenationalnews.com/business/technology/2022/03/23/gisec-2022-health-care-most-targeted-sector-for-cyber-attacks-in-2021-cisco-says/ |
| SaaS Providers | CISOs turn to Remote Browser Isolation for zero trust- Reducing the size of the attack surface by isolating every user’s internet activity from enterprise networks and systems is the goal of remote browser isolation. The most compelling aspect of RBI is how well it integrates into their zero trust strategies and is complementary to their security tech stacks. Zero trust looks to eliminate trusted relationships across an enterprise’s tech stack because any trust gap is a major liability.https://venturebeat.com/2022/03/31/why-remote-browser-isolation-is-core-to-zero-trust-security/ |
| Financial Services | Attackers have stolen $1.4 million from the One Ring protocol via a flash loan attack, blockchain platform One Ring Finance has revealed. Losses from the attack, which unfolded on Monday (March 21), totaled $2 million after swap and flash loan fees, said One Ring, a ‘multi-chain cross-stable yield optimizer platform’.https://portswigger.net/daily-swig/flash-loan-attack-on-one-ring-protocol-nets-crypto-thief-1-4-million |
| Biotech / Pharma | The sensitive medical data of more than 1,200 Washington residents has been exposed after a successful phishing attack against a local public health agency. Spokane Regional Health District (SRHD) said that “files containing client protected health information” associated with 1,260 individuals and two departments may have been “previewed” by an attacker during the incident on February 24, 2022.https://portswigger.net/daily-swig/washington-residents-medical-data-exposed-by-phishing-attack-on-spokane-regional-health-district |
| Government, Military, and Critical Infrastructure | Texas Power Grid- Energy Sectors on high alert- Russian hackers have been probing Texas’ energy infrastructure for weak points in digital systems that would allow them to steal sensitive information or disrupt operations, according to interviews with energy companies, state officials and cybersecurity experts. https://www.texastribune.org/2022/03/31/texas-energy-grid-russia-cyberattack-hackers/ The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Energy (DOE) have issued a joint cybersecurity advisory on Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector. US engergy sector entities should be on high alert based on indicators of possible attacks being planned by Russia. https://www.cisa.gov/uscert/ncas/alerts/aa22-083a |