Riksrevisjonen hacket helseregionene: Fikk pasientopplysninger til flere hundre tusen pasienter – NRK

https://www.nrk.no/trondelag/riksrevisjonen-hacket-helseregionene_-fikk-pasientopplysninger-til-flere-hundre-tusen-pasienter-1.15294490

I det simulerte dataangrepet mot Norges fire helseregioner, prøvde Riksrevisjonen å lage støy for å bli avslørt.

Likevel klarte de å gjøre det de fryktet: Å hacke seg tilgang på sensitiv, taushetsbelagt informasjon om norske pasienter.

I Helse Sør-Øst fikk de tilgang på helseinformasjonen til svært mange. I de tre andre fikk de tilgang på helseinformasjonen til absolutt alle.

– Vi påpekte alvorlige feil for fire år siden, og det var et angrep også i 2018. Det virker som det ikke er blitt gjort så mye mer med datasikkerheten ved norske sykehus etter det. Sykehusene i Norge ligger langt bak grunnleggende krav til IKT-sikkerhet, sier Gohn-Hellum.

Tesla Model X hacked with $195 Raspberry Pi based board - Embedded.com

https://www.embedded.com/tesla-model-x-hacked-with-195-raspberry-pi-based-board/

The Belgian researchers first informed Tesla of the identified issues on the 17th of August 2020. Tesla confirmed the vulnerabilities, awarded their findings with a bug bounty and started working on security updates. As part of the 2020.48 over-the-air software update, that is now being rolled out, a firmware update will be pushed to the key fob.

The untold story of a cyberattack, a hospital and a dying woman - WIRED UK

https://www.wired.co.uk/article/ransomware-hospital-death-germany

German prosecutors tried to prove that a ransomware attack on a hospital was to blame for someone losing their life. Their story is a warning

Hacking-skandale ryster Finland - pasienter presset for penger – NRK

https://www.nrk.no/urix/hacking-skandale-ryster-finland---pasienter-presset-for-penger-1.15214710

Pasientopplysninger fra et finsk psykoterapisenter er på avveie etter hacking, og flere pasienter er blitt presset for penger.

Utpresseren skal ha presset selskapets ledelse for 40 bitcoin, tilsvarende nesten 5 millioner kroner, for ikke å publisere pasientjournalene på det mørke nettet.

Utpresseren skal ha truet med å publisere 100 journaler på det mørke nettet per dag.

Kravet ble avvist, dermed begynte lekkasjene. Etter dette begynte det å dukke opp trusselmeldinger til hver enkelt pasient.

– Nå må vi ordne krisehjelp til ofrene, sier Ohisalo.

North Korea has tried to hack 11 officials of the UN Security Council - ZDNet

https://www.zdnet.com/article/north-korea-has-tried-to-hack-11-officials-of-the-un-security-council/

consisted of a series of spear-phishing campaigns aimed at the Gmail accounts of UN officials.

The emails were designed to look like UN security alerts or requests for interviews from reporters, both designed to convince officials to access phishing pages or run malware files on their systems.

Spies hacked Azerbaijan government officials as Nagorno-Karabakh conflict escalated, researchers say

https://www.cyberscoop.com/nagorno-karabakh-azerbaijan-armenia-espionage-talos-hackers/

shows how digital espionage often coincides with bursts of violence in modern war.

German Hospital Hacked, Patient Taken to Another City Dies - SecurityWeek.Com

https://www.securityweek.com/german-hospital-hacked-patient-taken-another-city-dies

what appears to have been a misdirected hacker attack caused the failure of IT systems at a major hospital in Duesseldorf, and a woman who needed urgent admission died after she had to be taken to another city for treatment.

Tony Abbott hacked after posting boarding pass on Instagram - BBC News

https://www.bbc.com/news/world-australia-54193764

The hacker explained in a blog post published on Wednesday that he was able to find Mr Abbott’s information because his booking reference was printed on the boarding pass. He was then able to log in to Mr Abbott’s booking and search through HTML code to find his passport number and phone number. The code also included conversations with Qantas staff about Mr Abbott.

EU imposes the first ever sanctions against cyber-attacks - Consilium

https://www.consilium.europa.eu/en/press/press-releases/2020/07/30/eu-imposes-the-first-ever-sanctions-against-cyber-attacks/

Chinese-Made Smartphones Are Secretly Stealing Money From People Around The World

https://www.buzzfeednews.com/article/craigsilverman/cheap-chinese-smartphones-malware

Preinstalled malware on low-cost Chinese phones has stolen data and money from some of the world’s poorest people.

Current security concerns about Chinese apps and hardware have largely focused on potential back doors in Huawei’s 5G equipment. More recently, people have focused on how user data collected by TikTok could be abused by the company and the Chinese government. But an overlooked and ongoing threat is the consistent presence of malware on cheap smartphones from Chinese manufacturers and how it exacts a digital tax on people with low incomes.

Dataangrep mot Sykehuset Innlandet – NRK

https://www.nrk.no/innlandet/dataangrep-mot-sykehuset-innlandet-1.15132961

Analyser viser at det kan ha blitt hentet ut personsensitive data.

Researchers one step closer to bomb-sniffing cyborg locusts - Washington University in St. Louis

https://source.wustl.edu/2020/08/researchers-one-step-closer-to-bomb-sniffing-cyborg-locusts/

they were able to hijack a locust’s olfactory system to both detect and discriminate between different explosive scents — all within a few hundred milliseconds of exposure.

Datainnbrotet ved NHH viser kor viktig det er å halde seg oppdatert på datatryggleik

https://www.bt.no/btmeninger/leder/i/wP7BB5/datainnbrotet-ved-nhh-viser-kor-viktig-det-er-aa-halde-seg-oppdatert-paa

Norges Handelshøyskole har latt døra til internett stå ulåst

Feilen vart retta for meir enn eitt år sidan, men NHH installerte aldri oppdateringa.

NHH utsatt for datainnbrudd – Over 300 studenter og ansatte rammet

https://nrkbeta.no/2020/08/06/nhh-utsatt-for-datainnbrudd-over-300-studenter-og-ansatte-rammet/

NRKs gjennomgang av datalekkasjen tilsier at over 300 studenter og ansatte er kompromittert.

Det skal ha skjedd etter et større internasjonal datainnbrudd som har påvirket flere hundre organisasjoner.
Ifølge teknologinettstedet ZDNet skal 900 VPN-servere være rammet.

Blackberry cracked five years after seizure sparks mass arrests for drug importation

https://www.smh.com.au/national/nsw/silver-bullet-mass-arrests-after-blackberry-cracked-five-years-after-seizure-20200731-p55hbq.html

In April, new technology “capabilities” allowed authorities to probe the encrypted device

Garmin reportedly paid multimillion-dollar ransom after suffering cyberattack - The Verge

https://www.theverge.com/2020/8/4/21353842/garmin-ransomware-attack-wearables-wastedlocker-evil-corp

Twitter says hackers downloaded private account data - BBC News

https://www.bbc.com/news/technology-53455092

The attackers successfully manipulated a small number of employees and used their credentials to access Twitter’s internal systems,” it said in a statement

Hackers Convinced Twitter Employee to Help Them Hijack Accounts

https://www.vice.com/en_us/article/jgxd3d/twitter-insider-access-panel-account-hacks-biden-uber-bezos

A Twitter insider was responsible for a wave of high profile account takeovers on Wednesday, according to leaked screenshots obtained by Motherboard and two sources who took over accounts.

On Wednesday, a spike of high profile accounts including those of Joe Biden, Elon Musk, Bill Gates, Barack Obama, Uber, and Apple tweeted cryptocurrency scams in an apparent hack.

Today’s Twitter Breach Reveals How It Is Often Used as Critical Infrastructure — Pixel Envy

https://pxlnv.com/linklog/twitter-critical-infrastructure/

Studenter avslørte alvorlig sikkerhetsfeil i biblioteksystemet Bibliofil – NRK

https://www.nrk.no/kultur/studenter-avslorte-alvorlig-sikkerhetsfeil-i-biblioteksystemet-bibliofil-1.15076878

I april fant tre studenter ved NTNU et sikkerhetshull i Bibliofil. Utlånssystemet er i bruk ved 159 forskjellige bibliotek i Norge, og har registrert informasjon om 3,5 millioner lånere.

Siden januar 2019 har blant annet navn, adresse, telefonnummer og personnummer vært tilgjengelig med kun enkle tekniske grep.