{"id":30320,"date":"2022-10-26T08:40:23","date_gmt":"2022-10-26T12:40:23","guid":{"rendered":"https:\/\/www.itworldcanada.com?p=509950"},"modified":"2022-10-27T10:31:54","modified_gmt":"2022-10-27T14:31:54","slug":"cyber-security-today-oct-26-2022-american-schools-increasingly-hit-by-ransomware-an-event-ticket-agency-is-hacked-and-more-2","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/cyber-security-today-oct-26-2022-american-schools-increasingly-hit-by-ransomware-an-event-ticket-agency-is-hacked-and-more-2\/","title":{"rendered":"Cyber Security Today, Oct. 26 2022 \u2013 American schools increasingly hit by ransomware, an event ticket agency is hacked and more"},"content":{"rendered":"<p data-ar-index=\"0\">American schools increasingly hit by ransomware, an event ticket agency is hacked and more.<\/p>\n<p data-ar-index=\"1\">Welcome to Cyber Security Today. It\u2019s Wednesday, October 26th, 2022. I\u2019m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com.<\/p>\n<p data-ar-index=\"2\"><iframe style=\"border: none;\" title=\"Libsyn Player\" src=\"https:\/\/html5-player.libsyn.com\/embed\/episode\/id\/24800214\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/000000\/\" width=\"100%\" height=\"90\" scrolling=\"no\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<table style=\"width: 100%;\">\n<tbody>\n<tr>\n<td><a href=\"https:\/\/www.amazon.com\/ITWC-Cyber-Security-Today\/dp\/B07BRNG89P\/ref=sr_1_1?s=digital-skills&amp;ie=UTF8&amp;qid=1522688435\" rel=\"noopener noreferrer\"><img decoding=\"async\" class=\"aligncenter wp-image-396718 size-full\" src=\"https:\/\/i.itworldcanada.com\/wp-content\/uploads\/2017\/09\/sub-alexa-200.png\" alt=\"Cyb er Security Today on Amazon Alexa\" width=\"200\" height=\"74\" border=\"none\" \/><\/a><\/td>\n<td><a href=\"https:\/\/www.google.com\/podcasts?feed=aHR0cDovL2N5YmVyc2VjdXJpdHl0b2RheS5saWJzeW4uY29tL3Jzcw%3D%3D\" rel=\"noopener noreferrer\"><img decoding=\"async\" class=\"thumbnail aligncenter wp-image-408712 size-full\" src=\"https:\/\/i.itworldcanada.com\/wp-content\/uploads\/2018\/09\/sub-gp-200.png\" alt=\"Cyber Security Today on Google Podcasts\" width=\"200\" height=\"74\" \/><\/a><\/td>\n<td><a href=\"https:\/\/itunes.apple.com\/ca\/podcast\/cyber-security-today\/id1363182054\" rel=\"noopener noreferrer\"><img decoding=\"async\" class=\"aligncenter wp-image-396720 size-full\" src=\"https:\/\/i.itworldcanada.com\/wp-content\/uploads\/2017\/09\/sub-itunes-200.png\" alt=\"Subscribe to Cyber Security Today on Apple Podcasts\" width=\"200\" height=\"74\" border=\"none\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p data-ar-index=\"3\"><strong>A public school district<\/strong> in Iowa has become the latest education board in the U.S. to be listed as a victim by a ransomware gang. According to researcher Brett Callow of ESET, the Karakurt gang is claiming responsibility. So far this year 32 school districts with over 1,800 schools in the U.S. have been impacted by ransomware. Crooks stole and released data from at least 18 of those boards. In addition at least 33 colleges and universities were impacted by ransomware. Of them, crooks stole data from 20 institutions.<\/p>\n<p data-ar-index=\"4\"><strong>Meanwhile<\/strong> r<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/10\/25\/dev-0832-vice-society-opportunistic-ransomware-campaigns-impacting-us-education-sector\/\" rel=\"noopener\">esearchers at Microsoft warned<\/a> that a threat group known as Vice Society has not only recently been targeting schools in the U.S., it also uses different ransomware strains.<\/p>\n<p data-ar-index=\"5\">Crooks choose public sector institutions like school boards and municipalities because they may not be able to afford sophisticated cyber defences, and they may be more willing to pay ransoms or extortion than big companies.<\/p>\n<p data-ar-index=\"6\"><strong>Separately,<\/strong> the Hive ransomware group is posting data it claims to have stolen earlier this month from one of India\u2019s biggest electricity suppliers, Tata Power. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hive-claims-ransomware-attack-on-tata-power-begins-leaking-data\/\" rel=\"noopener\">The Bleeping Computer news site says<\/a> so far the data posted by the attackers appear to be personal information about Tata employees. Tata has said the attack was on its IT systems.<\/p>\n<p data-ar-index=\"7\"><strong>American event ticket agency<\/strong> See Tickets has admitted hackers may have stolen customers\u2019 names and their credit or debit card information for over two years starting in late June of 2019. In a copy of letter <a href=\"https:\/\/dojmt.gov\/wp-content\/uploads\/Consumer-Notification-Letter-638.pdf\" rel=\"noopener\">filed with the state of Montana<\/a> and sent to potential victims, the company says in April it realized that a hacker had compromised some event checkout pages.<\/p>\n<p data-ar-index=\"8\"><strong>Microsoft ended support<\/strong> for the Internet Explorer browser in June. Some IT departments made employees at their organizations switch either to Microsoft Edge or other browsers a while ago in anticipation of this. However, certain logs left behind by Internet Explorer still pose a risk because they allow access permissions within Windows. That\u2019s <a href=\"https:\/\/www.varonis.com\/blog\/the-logging-dead-two-windows-event-log-vulnerabilities\" rel=\"noopener\">according to researchers at Varonis<\/a>. Hackers could use the access to either crash or cause a denial of service to a computer. A patch for one vulnerability was included on October 11th in this month\u2019s Windows Patch Tuesday updates. But the other is still a risk. Windows administrators have to watch who is given administrator privilege over this log file.<\/p>\n<p data-ar-index=\"9\"><strong>As part of Cybersecurity Awareness Month<\/strong> it\u2019s time to remind listeners of the importance of a safe password. Experts know what many people do wrong: They use passwords like 123456, the days of the week, the months of the year, their first names, names of sports teams or sequential letters on a keyboard like \u2018qwerty\u2019. Crooks know this and will test those first. So here\u2019s my advice: First, get a software password manager to manage the different passwords you have to create. Your antivirus suite may come with one, or may be an option. Second, create a safe and different password for every important site you have to log into. An important site is your email, your office computer, your bank \u2014 anything that holds your sensitive personal information.<\/p>\n<p data-ar-index=\"10\">You have two choices for passwords: Create one from a jumble of letters, numbers and special characters \u2014 like an exclamation mark \u2014 of at least 12 characters; or create a passphrase composed of at least three random words that\u2019s at least 15 characters long. The idea passphrases are relatively easy to remember.<\/p>\n<p data-ar-index=\"11\">Third, say yes whenever a website or service offers multifactor or two-factor authentication. Initially it\u2019s an extra step for logging in by typing in a six digit code sent by email or an authenticator app on your smartphone. But it\u2019s a key to added security. Remember, every site has to have a different password. More password advice is available <a href=\"https:\/\/getcybersafe.gc.ca\/en\/secure-your-accounts\/passphrases-passwords-and-pins\" rel=\"noopener\">here<\/a> and <a href=\"https:\/\/www.ncsc.gov.uk\/news\/most-hacked-passwords-revealed-as-uk-cyber-survey-exposes-gaps-in-online-security\" rel=\"noopener\">here.<\/a><\/p>\n<p data-ar-index=\"12\"><strong>More people<\/strong> in Canada and the U.S. are using multifactor authentication. That\u2019s according to a survey <a href=\"https:\/\/news.chubb.com\/2022-10-24-More-Consumers-are-Taking-Measures-to-Protect-Themselves-from-Cyber-Attacks\" rel=\"noopener\">released this week by the Chubb insurance group<\/a>. More than half of those surveyed said they now use multifactor authentication for logins, twice as many as last year. Perhaps they\u2019re using it because their employer or email provider forces them too, but that\u2019s still good. The bad news: 61 per cent of respondents say they have trouble keeping track of their passwords. They likely aren\u2019t using password managers.<\/p>\n<p data-ar-index=\"13\"><strong>Finally,<\/strong> those of you with Apple devices should be looking for operating system updates or security patches. Apple this week released a new version of its macOS and updates to iOS and iPadOS.<\/p>\n<p data-ar-index=\"14\">Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.<\/p>\n<p data-ar-index=\"15\">The post <a href=\"https:\/\/www.itworldcanada.com\/article\/cyber-security-today-oct-26-2022-american-schools-increasingly-hit-by-ransomware-an-event-ticket-agency-is-hacked-and-more\/509950\">Cyber Security Today, Oct. 26 2022 \u2013 American schools increasingly hit by ransomware, an event ticket agency is hacked and more<\/a> first appeared on <a href=\"https:\/\/www.itworldcanada.com\/\">IT World Canada<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This episode includes advice on creating safe passwords<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[360,16],"tags":[389,411,62],"class_list":["post-30320","post","type-post","status-publish","format-standard","hentry","category-podcasts","category-security","tag-cyber-security-today","tag-eset","tag-microsoft"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/30320","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=30320"}],"version-history":[{"count":4,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/30320\/revisions"}],"predecessor-version":[{"id":30402,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/30320\/revisions\/30402"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=30320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=30320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=30320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}