Hello, Habr! Today we want to share information about new cyberattacks that have recently been discovered by our cyber defense analytics centers. Under the cut, you'll find a story about a significant data loss by a silicon chip manufacturer, an account of network outages in an entire city, a bit about the dangers of Google notifications, statistics on hacks in the U.S. healthcare system, and a link to Acronis' YouTube channel.
In addition to protecting your data, Acronis is also engaged in threat monitoring, developing patches for new vulnerabilities, and preparing security recommendations for various systems. Recently, a global network of Acronis Cyber Protection Operations Centers (CPOCs) was established. These centers continuously analyze traffic to detect new types of malware, viruses, and cryptojacking.
Today, we want to talk about the results of the CPOCs, which are now regularly published on Acronis' YouTube channel. Here are the 5 hottest news stories about incidents that could have been avoided with at least basic protection against Ransomware and phishing.
The Black Kingdom Ransomware has learned to compromise Pulse VPN users.

The VPN provider Pulse Secure, which 80% of Fortune 500 companies rely on, has fallen victim to ransomware attacks from the Black Kingdom family. They exploit a system vulnerability that allows them to read a file and extract account data. The stolen login and password are then used to access the compromised network.
Although Pulse Secure has already released a patch that eliminates this vulnerability, companies that haven't installed the update are at increased risk.
However, as tests have shown, solutions that use artificial intelligence to detect threats, such as Acronis Active Protection, prevent Black Kingdom from infecting end-user computers. So if a company has such protection or a system with a built-in update monitoring mechanism (for example, Acronis Cyber Protect), there is no need to worry about Black Kingdom.
The ransomware attack in Knoxville led to network outages.

On June 12, 2020, a massive ransomware attack took place in Knoxville, Tennessee, which resulted in the shutdown of computer networks. As a result, law enforcement lost the ability to respond to incidents except in emergencies and life-threatening situations. Even days after the attack had ended, the city’s website still displayed a notice that online services were unavailable.
The initial investigation revealed that the attack was the result of a large-scale phishing campaign targeting city service employees with fraudulent emails. Ransomware such as Maze, DoppelPaymer, or NetWalker was used in the attack. As in the previous example, if city authorities had utilized ransomware countermeasures, such an attack could not have succeeded, as AI-powered protection systems would have immediately detected the variations of the used encryptors.
MaxLinear reported an attack utilizing Maze and a data leak.

Integrated circuit manufacturer MaxLinear confirmed that the company's networks were compromised by the Maze ransomware. Approximately 1TB of data was stolen, including personal data and financial information of employees. The attackers have already published 10GB of this data.
As a result, MaxLinear had to take all company networks offline and hire consultants to conduct an investigation. This attack serves as a reminder: Maze is a well-known and easily recognizable variant of ransomware. If MaxLinear had employed ransomware protection systems, they could have saved considerable funds and avoided reputational damage.
Malware 'leaked' through fake Google Alerts notifications.

Cybercriminals began using Google Alerts to send out fake data breach notifications. As a result, alarmed users receiving these notifications clicked on counterfeit websites and downloaded malware in hopes of 'resolving the issue.'
The malicious notifications work in Chrome and Firefox. However, URL filtering services, including the Acronis Cyber Protect service, prevented users in protected networks from accessing the infected links.
The U.S. Department of Health has reported 393 violations of HIPAA safety requirements over the past year

The Department of Health and Human Services (HHS) has reported 393 breaches of patient health information that resulted in violations of the Health Insurance Portability and Accountability Act (HIPAA) from June 2019 to June 2020. This includes 142 incidents resulting from phishing attacks on the District Medical Group and Marinette Wisconsin, where 10,190 and 27,137 electronic medical records were compromised, respectively.
Unfortunately, practice has shown that even specially trained and prepared users, who have been repeatedly instructed against clicking links or opening attachments from suspicious emails, can still fall victim. Without automated systems to block suspicious activity and URL filtering to prevent access to fake sites, it becomes very difficult to defend against sophisticated attacks that use very convincing situations, plausible email addresses, and a high level of social engineering.
If you're interested in news about the latest threats, you can subscribe to the Acronis YouTube channel, where we discuss the most recent findings from the CPOC monitoring in near real-time. You can also subscribe to our blog on Habr.com, as we will stream the most interesting updates and research results here.
Only registered users can participate in the survey. , please.
Have you received any highly plausible phishing emails in the past year?
33,3%Yes7
66,7%No14
21 users voted. 6 users abstained.
Source: habr.com
