Microsoft and Cisco published advisories about the flaw, and developers released a fix late last week. But a solution depends on thousands of companies putting the fix in place before it is exploited.
The Assembly’s voicemail system was down and many of the systems involved in budgeting were disrupted due to the attack. The Virginia Law Portal is also down because of the attack.
Previously, only certain industries, like the financial sector, had the absolute need and requirement to rely on interconnected information systems to carry out automated transactions and processes.
In reality, these criminal actions are a way for unscrupulous individuals or criminal rings to secure gift card codes they can use illicitly or resell through online black markets for profit.
Kronos Private Cloud was hit by a ransomware attack. The company, also known as Ultimate Kronos Group (UKG), provides timekeeping services to companies employing millions of people across the world.
Cybereason released a mitigation tool named Logout4shell. It is freely available on GitHub and Cybereason said it “is a relatively simple fix that requires only basic Java skills to implement.”
Purple Fox focuses on SQL servers as its target as opposed to normal computers for cryptomining activities. This is because of the better hardware configuration that the servers would usually have.
The decentralized nature of U.S. state and local agencies has made it harder to reach a consensus approach against such attacks, said Ron Sanders, staff director of Florida Center for Cybersecurity.
Besides CVE-2021-30955, a total of five Kernel and four IOMobileFrameBuffer (a kernel extension for managing the screen framebuffer) flaws have been remediated with the latest updates.
The arrests are the latest police action against groups committing cybercrime in the country, with hacking groups and forums being shut down and cybercriminals’ databases seized.