jon greig

@jgreig.bsky.social

cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to jonathangreig11@protonmail.com or signal: jgreig.51

West Pharmaceutical warned the SEC that critical systems used to ship, receive and manufacture products were shut down due to a ransomware attack The company said it has “taken steps intended to mitigate the risk of dissemination of the exfiltrated data.” therecord.media/west-pharmac...

West Pharmaceutical warns of ransomware attack impacting business operations

West Pharmaceutical Services filed a report with the Securities and Exchange Commission (SEC) on Monday evening warning customers that a hacker breached the company network on May 4, stole data and en...

therecord.media

Overnight, Instructure said it paid a ransom to the ShinyHunters cybercriminal group after its data was "returned" and the hackers allegedly sent digital confirmation of data destruction Congress has demanded a briefing from Instructure on the incident therecord.media/instructure-...

Instructure pays ransom after Canvas incident as Congress announces investigation

The company said its agreement with the hackers involved their data being “returned” to them and digital confirmation of data destruction.

therecord.media

Zambia announced it was cancelling the large digital freedoms conference RightsCon days before it was to be held in Lukasa even as thousands were en route. Officials cited concerns about the conference's themes. The Chinese govt reportedly bankrolled the event venue. therecord.media/zabia-cancel...

Zambia cancels global digital freedoms conference days before start

On Tuesday, Zambia’s Minister of Technology and Science offered the first hint that the conference would be cancelled, telling a Zambian news outlet that participants’ security clearances were incompl...

therecord.media

A business's website has been hit by a ransomware attack, demanding 0.1 BTC and a tweet for file recovery. The attack isn't unique to them, as similar messages and values appear on other sites. They are seeking advice on the vulnerability exploited and how to resolve the issue.

Our business is under attack by ransomware (Any help is appreciated)

to recover your files, kindly send 0.1 BTC to bc1q9nh4revv6yqhj2gc5usncrpsfnh7ypwr9h0sp2 and tweet ty15b6TOTuBuzUhfypJeagHl4e2sAs26, then we will help u <3 This is the message that our website got...

reddit.com

NIST announced deep changes to the NVD today, writing that it would no longer enrich every vuln submission. The only bugs that will have info added are in: - CISA's known exploited list - tools used by federal government - software deemed 'critical' therecord.media/nist-to-limi...

NIST to limit work on CVE entries as submissions surge

NIST said it will only add details and information to the records of vulnerabilities that meet a certain threshold — changing a longstanding mission to categorize every CVE, which stands for cybersecu...

therecord.media

A North Korea expert compared last week's $280 million theft from Drift to the assassination of Kim Jong Un's brother in 2017 Pyongyang created a fake company and hired people to meet up with Drift officials in person at conferences before launching the 4/1 attack therecord.media/drift-crypto...

‘It reads like a spy novel’: $280 million theft from Drift involved North Korean fake companies, cutouts

Drift officials said the operation began six months ago, when they were approached at a cryptocurrency conference by members of a company claiming to focus on quantitative trading.

therecord.media

Winona County Administrator Maureen Holte told @therecordmedia.bsky.social that Monday's ransomware attack did not involve the same cybercriminal responsible January's ransomware attack Minnesota governor Tim Walz sent the National Guard to help the county recover therecord.media/minnesota-se...

Minnesota governor sends national guard to county after cyberattack

Minnesota governor Tim Walz issued an executive order on Tuesday, writing that Winona county experienced a cyberattack on critical systems that began on Monday.

therecord.media

Buried in the FBI, DOD and NSA advisory on Iran cyberattacks on critical infrastructure operational technology was acknowledgement that 75 devices were compromised during the CyberAv3ngers campaign in 2023/2024 therecord.media/fbi-pentagon...

FBI, Pentagon warn of Iran hacking groups targeting operational technology

The advisory said Iranian actors are targeting local municipal governments, water and wastewater systems and the energy sector.

therecord.media

Interesting from @jgreig.bsky.social, w/ confirmation of "historical" data from FBI. Imagine attempting to conduct hostile operations in the U.S. and **you have access to the personal email account** of the counterintelligence agency's director. What would you burn that access for? A cheap info op?

FBI confirms theft of director’s personal emails by Iran-linked hacking group

An FBI spokesperson told Recorded Future News that the information is “historical in nature and involves no government information,” adding that the agency has “taken all necessary steps to mitigate p...

therecord.media

Electronic health record company CareCloud told the SEC that a recent cyberattack "is material in light of the sensitivity of the potentially affected information and the potential consequences of the incident.” therecord.media/carecloud-ha...

Healthcare software firm CareCloud informs SEC of potential patient data leak

The healthcare software firm CareCloud warned the Securities and Exchange Commission that a cyberattack may have resulted in the leak of patient data.

therecord.media