Friday, 23 January 2015

Computer with Patients’ Personal Information Stolen

HARLINGEN - Thousands of people throughout the Rio Grande Valley are in a vulnerable position because of a burglary.
Sunglo Home Health Services has thousands of patients across the Valley. Their personal information is in the hands of a Harlingen burglar.
He walked away with sensitive information and it was all caught on surveillance video.
Steven Means with Sunglo Home Health Services said, “We're covering from Rio Grande City all the way to Brownsville - including Raymondville as well.”
He said their patients include the elderly and the disabled. The company drives patients across the Valley in their vans. The vans are kept in a parking lot at the corporate office in Harlingen.
Means said the parking lot was the scene of a burglary early Monday morning.
Harlingen police said the suspect broke into a truck full of tools. Means said the thief was able to find a set of keys to one of the vans inside the truck.
The thief took the tools and some other gear, placed it in the van and then drove away.
Surveillance video showed the burglar return to take more property.
According to Means, the man broke a window with a fire extinguisher and stole a computer.
That computer contained the Social Security numbers and personal information belonging to thousands of their patients.
“We're just worried about the safety of the patients themselves because of the information. We had to contact local police to see what we could do,” said Means.
Sergeant Dave Osborne with the Harlingen Police Department said they are looking for the public’s help because the bad guy may not have been working alone.
Thousands of patients are now waiting to see if thieves log on and download their personal information.
Means, the IT director for Sunglo, said they have contacted all of their patients to let them know about the security breach. He said he will continue to monitor the computer in case someone decides to power it up.
There are specific steps you should take if you think someone has stolen your personal information.
The Better Business Bureau said to contact all the major credit reporting agencies. They also said you should ask them to put a fraud alert and credit freeze on your accounts.
Keep a close watch on your credit card and bank accounts to make sure no one is making charges or taking your money.
They also suggest filing an ID theft kit from the Texas Attorney General.

Symantec data centre security software has security holes

Security bod Stefan Viehböck has detailed holes in Symantec's data centre security platforms that the company plugged this week because they allowed hackers to gain privilege access to management servers.
The patches fix holes in the management server for Symantec Critical System Protection (SCSP) 5.2.9 and its predecessor Data Center Security: Server Advanced (SDCS:SA) 6.0.x and 6.0 MP1.
SEC Consult researcher Stefan Viehböck who found the flaws said the products should not be used until a full security audit was conducted.
"Attackers are able to completely compromise the SDCS:SA Server as they can gain access at the system and database level," Viehböck wrote in an advisory
"Furthermore attackers can manage all clients and their policies.
"It is highly recommended by SEC Consult not to use this software until a thorough security review (SDCS:SA Server, SDCS:SA Client Policies) has been performed by security professionals and all identified issues have been resolved."
Hackers with access to the SDCS:SA server could potentially pivot within the corporate network and could bypass client protections.
Four flaws were reported including an unauthenticated SQL injection (CVE-2014-7289) granting attackers read and write access to database records and SYSTEM code execution privileges.
A reflected cross-site scripting (CVE-2014-9224) was dug up allowing attackers to steal other users' sessions and gain access to the admin interface.
Information disclosure (CVE-2014-9225) was possible with a script that spewed internal server application data without requiring authentication, including file paths on the web server, and version information (OS, Java).
Multiple default security protection policy bypasses were discovered that were tempered by the requirement for administrator permissions. These included persistent code execution via Windows Services; remote code execution via remote procedure call; extraction of Windows passwords and hashes; privilege elevation via Windows Installer, and privilege elevation and code execution via Windows Management Instrumentation.
Proof of concept codes were published to exploit the respective vulnerabilities, giving urgency to the need for customers to apply patches and work-arounds for those flaws yet unfixed.
Viehböck first tipped Symantec off to the holes in November under a disclosure time line that appeared to run smoothly between bug hunter and vendor.