Cyber Security Today, May 11, 2022 – F5 BIG-IP devices under attack, a proposed settlement on a Clearview AI lawsuit and Colonial Pipeline may be fined

Share post:

F5 BIG-IP devices under attack, a proposed settlement on a Clearview AI lawsuit and Colonial Pipeline may be fined. Welcome to Cyber Security Today. It’s Wednesday May 11th, 2022. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com.
Cyb er Security Today on Amazon Alexa Cyber Security Today on Google Podcasts Subscribe to Cyber Security Today on Apple Podcasts
  Last Friday I reported that a serious vulnerability had been found in F5 Network’s BIG-IP network security devices that need patching. This week security researchers said threat actors are already trying to exploit appliances that aren’t fixed and are open to the internet. According to researchers at Randori, hackers can gain access to devices by bypassing authentication processes if their management interfaces are publicly available. Usually that’s not the way these devices are set up. However, administrators of BIG-IP devices should install the patch and make sure these devices aren’t open to the internet. The European Union has formally accused Russia of an unprovoked cyberattack on Viasat’s internet satellite network an hour before its invasion of Ukraine. The malware damaged thousand of modems used by subscribers in a number of countries, including Ukraine. This unacceptable cyberattack is yet another example of Russia’s continued pattern of irresponsible behaviour in cyberspace, the EU said. It also demanded Russia stop the war. Companies in the United States won’t be able to buy access to the database of billions of faces collected by facial recognition software provider Clearview AI. That’s according to a proposed settlement with civic groups including the American Civil Liberties Union. They sued Clearview AI for allegedly violating the state’s Biometric Information Privacy Act. Also as part of the proposed settlement Clearview won’t be able to sell access to it’s facial recognition service to any entity in Illinois for five years, including police forces. Clearview AI has been criticized around the world for scraping images of people from the internet and using them in its facial recognition software. Privacy commissioners in Canada have ruled collecting images without consent violates Canadian privacy laws. Clearview AI is fighting that ruling in court. The Illinois settlement, if approved by a court, would still allow Clearview to sell is facial recognition service to American police forces outside Illinois. Also in Illinois, Lincoln College said it will close this Friday, the result of the combined impact of the pandemic and a cyberattack. The pandemic cut recruitment, fundraising and enrollment. The college then had to spend heavily on technology. Then in December a ransomware attack shut IT systems needed for student recruitment, retention and fundraising. When systems were restored in March projections showed enrollment would be so low in the fall the college didn’t have enough money to survive. A detailed incident response plan covering all possibilities is essential for surviving a cyber attack. The American oil company Colonial Pipeline had one, but it wasn’t as prepared as it thought it was for last year’s ransomware attack. Now it faces the possibility of an $850,000 fine. That’s what the U.S. Department of Transportation wants to levy because Colonial didn’t have a plan for dealing with a loss of internal email or voice communications for manually running the pipeline. As a result, after it had to shut the IT systems because of the cyberattack Colonial wasn’t prepared to manually restart operation of the pipeline. American regulations require pipeline companies to have a tested and verified internal communications plan. Nokia is opening a cybersecurity testing lab in Dallas to learn ways of preventing attacks on 5G networks, software and hardware. The knowledge will be used by Nokia telecom equipment, enterprise and government customers. In Canada, Bell and Telus are Nokia 5G customers. In the U.S. carriers include Verizon and AT&T. Finally, yesterday was the monthly Patch Tuesday for Microsoft, Adobe and other software manufacturers. Make sure your systems have the latest security updates. One of the Windows patches covers a Network File System vulnerability that touches all Windows servers. Another fixes a vulnerability in Windows Server 2008 for x64-based systems running Service Pack 2. Adobe issued patches for Framemaker, InCopy, InDesign and ColdFusion. SAP released 17 new and updated SAP Security Notes, including four HotNews notes and two High Priority notes. Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. The post Cyber Security Today, May 11, 2022 – F5 BIG-IP devices under attack, a proposed settlement on a Clearview AI lawsuit and Colonial Pipeline may be fined first appeared on IT World Canada.
Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Meta’s new release sparks debate about open versus closed source AI: Hashtag Trending for Friday, April 19, 2024

Just how real is quantum computing? We have an amazing guest on our Weekend Edition who will talk about how she is helping people prepare for IT careers using quantum computing. Meta’s new AI release sparks a debate about open versus closed source AI, major legislation expanding US government surveillance capabilities goes largely unnoticed, big

IT World Canada 2024-04-17 21:18:05

More Windows PCs previously blocked are now able to upgrade to Windows 11. Apple has fallen to number two in terms of iPhone market share. Salesforce makes news with a possible acquisition of Informatica. And a new AI wearable device gets savage reviews. All this and more on the “winners and losers” edition of Hashtag

Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one...

Cyber Security Today, April 17, 2024 – More suspicious attempts to take over open source projects, a data theft at a Cisco Duo partner,...

This episode reports on security updates from Delinea and PuTTY, and reports on bad bots and threat actors going after Zoo

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways