Saturday , December 21 2024

Canada cyber centre issues warning after group issues threat

The Canadian government’s cyber authority has issued a warning to IT administrators here to watch for attacks, after a group or individual claiming to be from India issued a retaliation threat over allegations India may have been behind the assassination of a Canadian man advocating for an independent Sikh state.

“CSE [the Canadian Security Establishment] and its Canadian Centre for Cyber Security (Cyber Centre) have observed that geopolitical events often result in an increase in disruptive cyber campaigns. We continue to monitor for any developing cyber threats and share threat information with our partners and stakeholders to help prevent incidents,” says the statement.

Authority Denies
Hacker claim ransomware attack on Indonesia’s state bank BRI

Bank Rakyat Indonesia (BRI), the largest state bank by assets, has assured customers that their data and funds are secure...
Read More
Authority Denies  Hacker claim ransomware attack on Indonesia’s state bank BRI

London-based company “Builder.ai” reportedly exposed 1.2 TB data

Cybersecurity researcher Jeremiah Fowler reported to Website Planet that he found a non-password-protected 1.2 TB dataset containing over 3 million...
Read More
London-based company “Builder.ai” reportedly exposed 1.2 TB data

(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)
Sophos resolved 3 critical vulnerabilities in Firewall

Sophos has fixed three separate security vulnerabilities in Sophos Firewall.  The vulnerabilities CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729 present major risks, such...
Read More
(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)  Sophos resolved 3 critical vulnerabilities in Firewall

“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

A time-demanding workshop on "Cybersecurity Awareness and Needs Analysis" was held on Thursday (December 19) at Bangladesh Bank Training Academy...
Read More
“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

CVE-2023-48788
Kaspersky reveals active exploitation of Fortinet Vulnerability

Kaspersky's Global Emergency Response Team (GERT) found that attackers are exploiting a patched SQL injection vulnerability (CVE-2023-48788) in Fortinet FortiClient...
Read More
CVE-2023-48788  Kaspersky reveals active exploitation of Fortinet Vulnerability

U.S. Weighs Ban on Chinese-Made Router TP-Link: WSJ reports

The US government is considering banning a well-known brand of Chinese-made home internet routers TP-Link due to concerns that they...
Read More
U.S. Weighs Ban on Chinese-Made Router TP-Link:  WSJ reports

Daily Security Update Dated: 18.12.2024

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update Dated: 18.12.2024

CISA released best practices to secure Microsoft 365 Cloud environments

CISA has issued Binding Operational Directive (BOD) 25-01, requiring federal civilian agencies to improve the security of their Microsoft 365...
Read More
CISA released best practices to secure Microsoft 365 Cloud environments

Data breach! Ireland fines Meta $264 million, Australia $50m

The Irish Data Protection Commission fined Meta €251 million ($263.6 million) for GDPR violations related to a 2018 data breach...
Read More
Data breach! Ireland fines Meta $264 million, Australia $50m

Over 25K SonicWall VPN Firewalls exposed to critical flaws

More than 25,000 SonicWall SSL VPN devices are vulnerable to critical flaws, with 20,000 running outdated SonicOS/OSX firmware that is...
Read More
Over 25K SonicWall VPN Firewalls exposed to critical flaws

ALSO READ:

AI in traffic signal in BD, Auto case while crossing white spot

“However, the Cyber Centre’s primary focus is on defending Government of Canada networks from cyber threats. We focus on the type of threat, not where the threat originates. For that reason, we generally do not provide statistics, or information on reporting trends.

“We encourage Canadians and Canadian organizations to be aware of cyber threats and to remain vigilant.”

The statement came after IT World Canada asked the Cyber Centre if it had received reports or seen evidence of hacking groups based in India launching recent retaliatory attacks here.

According to Brett Callow, a B.C.-based threat analyst with Emsisoft, a group calling itself the Indian Cyber Force posted a threatening message last week on the X messaging platform. It says, “Get ready to feel the power of IndianCyberForce attacks will be launching on Canada cyber space in the coming 3 days. It’s for the mess your started.” [This is the actual wording of the posting]

A website with a .ca suffix that appears to belong to a Canadian dental clinic has been defaced with the message, “Hacked by Indian Cyber Force.” However, the real website, whose address begins with ‘www,’ isn’t affected. The defaced website has a similar name and could be a spoof. Or the dental clinic’s site was defaced and it quickly set up a new one. IT World Canada asked the site on Sunday for comment. None was received by our deadline.

“At this point it’s impossible to say whether this is an organized hacktivist operation or a lone high school kid,” Callow said of the threat. “Whatever the case, even the most unsophisticated cyberattacks have the potential to cause real-world problems, as the disruption caused by the recent DDoS attack on the Canadian Border Services Agency demonstrated.

“Given current geo-political tensions, all Canadian organizations should assume that they may be targeted and ensure their shields are fully up.”

As for why a dental website would be targeted, Callow suspects it was random: The site came up after a scan for vulnerable Canadian websites.

Website administrators must ensure their sites are fully patched and that admin access is restricted. That includes making sure management consoles aren’t available on the public internet unless shielded with VPN access and multifactor authentication for logins. Websites should also be prepared to deal with DDoS attacks.

Source: itworldcanada

Check Also

AI

AI-made nude images incident, one school, 50 female victim

Nearly half of the high school’s female students were victimized in AI based deepfake the …

Leave a Reply

Your email address will not be published. Required fields are marked *