Thousands of people throughout the Rio Grande Valley are in a vulnerable position because of a burglary.
Sunglo Home Health Services has thousands of patients across the
Valley. Their personal information is in the hands of a Harlingen
burglar.
He walked away with sensitive information and it was all caught on surveillance video.
Steven
Means with Sunglo Home Health Services said, “We're covering from Rio
Grande City all the way to Brownsville - including Raymondville as
well.”
He said their patients include the elderly and the
disabled. The company drives patients across the Valley in their vans.
The vans are kept in a parking lot at the corporate office in Harlingen.
Means said the parking lot was the scene of a burglary early Monday morning.
Harlingen
police said the suspect broke into a truck full of tools. Means said
the thief was able to find a set of keys to one of the vans inside the
truck.
The thief took the tools and some other gear, placed it in the van and then drove away.
Surveillance video showed the burglar return to take more property.
According to Means, the man broke a window with a fire extinguisher and stole a computer.
That computer contained the Social Security numbers and personal information belonging to thousands of their patients.
“We're
just worried about the safety of the patients themselves because of the
information. We had to contact local police to see what we could do,”
said Means.
Sergeant Dave Osborne with the Harlingen Police
Department said they are looking for the public’s help because the bad
guy may not have been working alone.
Thousands of patients are now waiting to see if thieves log on and download their personal information.
Means,
the IT director for Sunglo, said they have contacted all of their
patients to let them know about the security breach. He said he will
continue to monitor the computer in case someone decides to power it up.
There are specific steps you should take if you think someone has stolen your personal information.
The
Better Business Bureau said to contact all the major credit reporting
agencies. They also said you should ask them to put a fraud alert and
credit freeze on your accounts.
Keep a close watch on your credit card and bank accounts to make sure no one is making charges or taking your money.
They also suggest filing an ID theft kit from the Texas Attorney General.
Information Security, Ethical Hacking, website Security, Database Security, IT Audit and Compliance, Security news, Programming, Linux and Security.
Friday, 23 January 2015
Symantec data centre security software has security holes
Security bod Stefan Viehböck has detailed holes in Symantec's data
centre security platforms that the company plugged this week because
they allowed hackers to gain privilege access to management servers.
The patches fix holes in the management server for Symantec Critical System Protection (SCSP) 5.2.9 and its predecessor Data Center Security: Server Advanced (SDCS:SA) 6.0.x and 6.0 MP1.
SEC Consult researcher Stefan Viehböck who found the flaws said the products should not be used until a full security audit was conducted.
"Attackers are able to completely compromise the SDCS:SA Server as they can gain access at the system and database level," Viehböck wrote in an advisory
"Furthermore attackers can manage all clients and their policies.
"It is highly recommended by SEC Consult not to use this software until a thorough security review (SDCS:SA Server, SDCS:SA Client Policies) has been performed by security professionals and all identified issues have been resolved."
Hackers with access to the SDCS:SA server could potentially pivot within the corporate network and could bypass client protections.
Four flaws were reported including an unauthenticated SQL injection (CVE-2014-7289) granting attackers read and write access to database records and SYSTEM code execution privileges.
A reflected cross-site scripting (CVE-2014-9224) was dug up allowing attackers to steal other users' sessions and gain access to the admin interface.
Information disclosure (CVE-2014-9225) was possible with a script that spewed internal server application data without requiring authentication, including file paths on the web server, and version information (OS, Java).
Multiple default security protection policy bypasses were discovered that were tempered by the requirement for administrator permissions. These included persistent code execution via Windows Services; remote code execution via remote procedure call; extraction of Windows passwords and hashes; privilege elevation via Windows Installer, and privilege elevation and code execution via Windows Management Instrumentation.
Proof of concept codes were published to exploit the respective vulnerabilities, giving urgency to the need for customers to apply patches and work-arounds for those flaws yet unfixed.
Viehböck first tipped Symantec off to the holes in November under a disclosure time line that appeared to run smoothly between bug hunter and vendor.
The patches fix holes in the management server for Symantec Critical System Protection (SCSP) 5.2.9 and its predecessor Data Center Security: Server Advanced (SDCS:SA) 6.0.x and 6.0 MP1.
SEC Consult researcher Stefan Viehböck who found the flaws said the products should not be used until a full security audit was conducted.
"Attackers are able to completely compromise the SDCS:SA Server as they can gain access at the system and database level," Viehböck wrote in an advisory
"Furthermore attackers can manage all clients and their policies.
"It is highly recommended by SEC Consult not to use this software until a thorough security review (SDCS:SA Server, SDCS:SA Client Policies) has been performed by security professionals and all identified issues have been resolved."
Hackers with access to the SDCS:SA server could potentially pivot within the corporate network and could bypass client protections.
Four flaws were reported including an unauthenticated SQL injection (CVE-2014-7289) granting attackers read and write access to database records and SYSTEM code execution privileges.
A reflected cross-site scripting (CVE-2014-9224) was dug up allowing attackers to steal other users' sessions and gain access to the admin interface.
Information disclosure (CVE-2014-9225) was possible with a script that spewed internal server application data without requiring authentication, including file paths on the web server, and version information (OS, Java).
Multiple default security protection policy bypasses were discovered that were tempered by the requirement for administrator permissions. These included persistent code execution via Windows Services; remote code execution via remote procedure call; extraction of Windows passwords and hashes; privilege elevation via Windows Installer, and privilege elevation and code execution via Windows Management Instrumentation.
Proof of concept codes were published to exploit the respective vulnerabilities, giving urgency to the need for customers to apply patches and work-arounds for those flaws yet unfixed.
Viehböck first tipped Symantec off to the holes in November under a disclosure time line that appeared to run smoothly between bug hunter and vendor.
Subscribe to:
Posts (Atom)