Skip to content

Ransomware attack on insurance MSP Xchanging affects clients

Global IT services and solutions provider DXC Technology announced over the weekend a ransomware attack on systems from its Xchanging subsidiary.

Xchanging is known as a managed service provider for businesses in the insurance industry but its list of customers includes companies from other fields: financial services, aerospace and defense, automotive, education, consumer packaged goods, healthcare, manufacturing.

Several customers affected

DXC Technology notified its investors in an 8-K form filed with the U.S. Securities and Exchange Commission that Xchanging has detected a ransomware attack on some of its systems.

The company reported the incident on July 5, expressing confidence that it did not spread outside the Xchanging network. For the moment, the investigation did not reveal any indication of data being affected. It is unclear when the company detected the attack.

An undisclosed number of customers was impacted by the cyberattack, denying access to their operating environment, reads the notification from the company. Containment and remediation measures were deployed to resolve the situation.

In a statement to BleepingComputer, a company spokesperson said that the problem is isolated to a subset of the Xchanging business and that customer data was not compromised or lost.

Efforts to restore services to customers are ongoing and at the moment remediation work is being done for just a few of them.

“While the revenue from those impacted customers is not material to DXC financial position, we nevertheless take this situation very seriously and have already restored services as nearly all of them” – DXC Technology spokesperson

As is typically the case with such incidents, the company is working with law enforcement and authorities on the investigation. This is also why there are few details available at this time.

There is no information about the family of the file-encrypting malware used in the attack and BleepingComputer does not know of a ransomware gang claiming the attack.

Related Articles:

Ransomware hits Technion university to protest tech layoffs and Israel

The Week in Ransomware – February 10th 2023 – Clop’s Back

Clop ransomware claims it breached 130 orgs using GoAnywhere zero-day

City of Oakland systems offline after ransomware attack

A10 Networks confirms data breach after Play ransomware attack

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Bullwall
BullWall is a fast-growing international cybersecurity solution provider with a dedicated focus on protecting critical data during active ransomware attacks. We are the only security solution able to contain both known and unknown ransomware variants in seconds, preventing encryption and exfiltration across all data storage types.

10 個減少「數碼足跡」的方法

 

 

 

 

 

在網絡罪案日益增多的時代,限制和管理您的「數碼足跡」是絕對有意義的。「數碼足跡」並不是一個新事物,但足跡分佈在如此多的網站、帳戶和裝置上,到底應該從哪裡開始?

1. 減少下載應用程式
應用程式通常需要用戶輸入個人資料才可以正作運作,程式還可能會追蹤位置、瀏覽活動和其他信息,然後與第三方共享。建議適時檢視您的裝置,並刪除一些很久沒有使用的應用程式。

2. 減少建立帳號
試過在網購時建立帳號並加入信用卡資料嗎?減少建立帳號,讓系統不會紀錄您的付款信息。雖然在下次購物時會帶來不便,但可以更好的保障自己。

3. 保密行蹤
「位置追蹤」是其中一種最具侵入性的數據捕獲方式,第三方可以從中拼湊出關於您日常的活動和習慣,請務必阻止應用程式追蹤您的位置。

4. 禁用第三方 Cookie
Cookie 是在您訪問網站時,下載到您裝置上的小文件,雖然可能會改善瀏覽體驗,但當中可能會洩漏用戶名稱和密碼。如果在訪問網站時出現選擇,只需拒絕接受 Cookie,您還可以通過瀏覽器的私隱設定禁用第三方追蹤。

5. 行使刪除權
「刪除權」是歐盟 GDPR 相關的條例,您可以要求 Google 等科技公司刪除您不喜歡的信息,例如位置追蹤、搜索引擎紀錄或整個帳號。

6. 對敏感資料提高驚覺
有時為了獲得您想要的產品或服務,提供信息是不可避免的,但請對敏感資料提高驚覺,特別是電話號碼、電子郵件和家庭住址、財務等信息。

7. 不要填寫網上問卷
互聯網上充斥著網上問卷,通常以現金或禮物吸引人填寫,當中有可能會竊取您的個人信息用於網絡釣魚活動或在暗網上出售。

8. 減少訂閱品牌通訊電郵
如果您對某些品牌不太感興趣,可考慮使用專用電子郵件地址或一次性電子郵件帳戶。對大部份人來說,這些品牌通訊電郵只會堵塞我們的收件箱。

9. 謹慎使用社交媒體
考慮其他人和潛在雇主如何接收這些內容,當中是否包含有關您工作和個人生活的敏感信息,建議只添加您在現實生活中認識的人。

10. 限制您的裝置數量
最後,考慮您有多少個裝置和電腦處於活躍使用狀態。它們每一個都是潛在的數據寶庫,如果裝置丟失或被盜,這些數據可能就會洩漏。您真的需要購買那款新平板電腦嗎? 如果答案仍然是「是」,請考慮是否需要將所有個人數據同步到這個裝置?

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

10 個減少「數碼足跡」的方法

 

 

 

 

 

在網絡罪案日益增多的時代,限制和管理您的「數碼足跡」是絕對有意義的。「數碼足跡」並不是一個新事物,但足跡分佈在如此多的網站、帳戶和裝置上,到底應該從哪裡開始?

1. 減少下載應用程式
應用程式通常需要用戶輸入個人資料才可以正作運作,程式還可能會追蹤位置、瀏覽活動和其他信息,然後與第三方共享。建議適時檢視您的裝置,並刪除一些很久沒有使用的應用程式。

2. 減少建立帳號
試過在網購時建立帳號並加入信用卡資料嗎?減少建立帳號,讓系統不會紀錄您的付款信息。雖然在下次購物時會帶來不便,但可以更好的保障自己。

3. 保密行蹤
「位置追蹤」是其中一種最具侵入性的數據捕獲方式,第三方可以從中拼湊出關於您日常的活動和習慣,請務必阻止應用程式追蹤您的位置。

4. 禁用第三方 Cookie
Cookie 是在您訪問網站時,下載到您裝置上的小文件,雖然可能會改善瀏覽體驗,但當中可能會洩漏用戶名稱和密碼。如果在訪問網站時出現選擇,只需拒絕接受 Cookie,您還可以通過瀏覽器的私隱設定禁用第三方追蹤。

5. 行使刪除權
「刪除權」是歐盟 GDPR 相關的條例,您可以要求 Google 等科技公司刪除您不喜歡的信息,例如位置追蹤、搜索引擎紀錄或整個帳號。

6. 對敏感資料提高驚覺
有時為了獲得您想要的產品或服務,提供信息是不可避免的,但請對敏感資料提高驚覺,特別是電話號碼、電子郵件和家庭住址、財務等信息。

7. 不要填寫網上問卷
互聯網上充斥著網上問卷,通常以現金或禮物吸引人填寫,當中有可能會竊取您的個人信息用於網絡釣魚活動或在暗網上出售。

8. 減少訂閱品牌通訊電郵
如果您對某些品牌不太感興趣,可考慮使用專用電子郵件地址或一次性電子郵件帳戶。對大部份人來說,這些品牌通訊電郵只會堵塞我們的收件箱。

9. 謹慎使用社交媒體
考慮其他人和潛在雇主如何接收這些內容,當中是否包含有關您工作和個人生活的敏感信息,建議只添加您在現實生活中認識的人。

10. 限制您的裝置數量
最後,考慮您有多少個裝置和電腦處於活躍使用狀態。它們每一個都是潛在的數據寶庫,如果裝置丟失或被盜,這些數據可能就會洩漏。您真的需要購買那款新平板電腦嗎? 如果答案仍然是「是」,請考慮是否需要將所有個人數據同步到這個裝置?

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

Finding VMware ESXi assets

Popular hypervisor ESXi has been in the news recently due to fresh targeting by a new strain of ransomware. Known as ESXiArgs, this ransomware leverages a 2-year old heap overflow issue in the OpenSLP service that can be leveraged to gain remote code execution on exploitable targets (CVE-2021-21974). Many vulnerable public-facing ESXi servers have already been affected by this malware (currently over 1,900 via Censys search results).

What is the impact?

Targets of this new ransomware campaign are older ESXi servers running certain versions of 6.5, 6.7, or 7 releases and also have the OpenSLP service enabled (it has not been enabled by default in ESXi releases since 2021). Upon successful exploitation of CVE-2021-21974, the ESXiArgs ransomware will encrypt a number of file types on the target system, including VM-related files with extensions .vmxf, .vmx, .vmdk, .vmsd, and .nvram. Ransom notes are saved as HTML files on compromised systems for admins and users to subsequently discover. While some of these ransom notes claim to have stolen data from vulnerable targets, no data exfiltration has been observed at this time.

Are updates available?

VMware made patches available when the OpenSLP heap-overflow vulnerability was initially reported in 2021. The following ESXi releases have been patched against this attack vector currently being exploited by the ESXiArgs campaign:

  • ESXi version 7+ (ESXi70U1c-17325551 and later)
  • ESXi version 6.7+ (ESXi670-202102401-SG and later)
  • ESXi version 6.5+ (ESXi650-202102101-SG and later)

VMware also offers patched releases for Cloud Foundation (ESXi), which includes an ESXi component:

  • Cloud Foundation (ESXi) version 4.2+
  • Patching instructions for Cloud Foundation (ESXi) version 3.x can be found here

Patching (and also ensuring that your ESXi servers are running a supported, not end-of-life/end-of-support version) is the best course of action. If patching is not a near-term option, VMware has a recommended mitigation via disabling the OpenSLP service.

How do I find potentially vulnerable VMware ESXi assets with runZero?

From the Asset Inventory, use the following pre-built query to locate ESXi assets which may need remediation:

os.product:"ESX" and (os.version:="1.%" or os.version:="2.%" or os.version:="3.%" or os.version:="4.%" or os.version:="5.%" or os.version:="6.0%" or os.version:="6.5.0 build-4564106" or os.version:="6.5.0 build-4887370" or os.version:="6.5.0 build-5146843" or os.version:="6.5.0 build-5146846" or os.version:="6.5.0 build-5224529" or os.version:="6.5.0 build-5310538" or os.version:="6.5.0 build-5969300" or os.version:="6.5.0 build-5969303" or os.version:="6.5.0 build-6765664" or os.version:="6.5.0 build-7273056" or os.version:="6.5.0 build-7388607" or os.version:="6.5.0 build-7967591" or os.version:="6.5.0 build-8285314" or os.version:="6.5.0 build-8294253" or os.version:="6.5.0 build-8935087" or os.version:="6.5.0 build-9298722" or os.version:="6.5.0 build-10175896" or os.version:="6.5.0 build-10390116" or os.version:="6.5.0 build-10719125" or os.version:="6.5.0 build-10868328" or os.version:="6.5.0 build-10884925" or os.version:="6.5.0 build-11925212" or os.version:="6.5.0 build-13004031" or os.version:="6.5.0 build-13635690" or os.version:="6.5.0 build-13873656" or os.version:="6.5.0 build-13932383" or os.version:="6.5.0 build-14320405" or os.version:="6.5.0 build-14874964" or os.version:="6.5.0 build-14990892" or os.version:="6.5.0 build-15256468" or os.version:="6.5.0 build-15177306" or os.version:="6.5.0 build-15256549" or os.version:="6.5.0 build-16207673" or os.version:="6.5.0 build-16389870" or os.version:="6.5.0 build-16576879" or os.version:="6.5.0 build-16576891" or os.version:="6.5.0 build-16901156" or os.version:="6.5.0 build-17097218" or os.version:="6.5.0 build-17167537" or os.version:="6.7.0 build-8169922" or os.version:="6.7.0 build-8941472" or os.version:="6.7.0 build-9214924" or os.version:="6.7.0 build-9484548" or os.version:="6.7.0 build-10176752" or os.version:="6.7.0 build-10176879" or os.version:="6.7.0 build-10302608" or os.version:="6.7.0 build-10764712" or os.version:="6.7.0 build-11675023" or os.version:="6.7.0 build-13004448" or os.version:="6.7.0 build-12986307" or os.version:="6.7.0 build-13006603" or os.version:="6.7.0 build-13473784" or os.version:="6.7.0 build-13644319" or os.version:="6.7.0 build-13981272" or os.version:="6.7.0 build-14141615" or os.version:="6.7.0 build-14320388" or os.version:="6.7.0 build-15018017" or os.version:="6.7.0 build-15160134" or os.version:="6.7.0 build-15160138" or os.version:="6.7.0 build-15999342" or os.version:="6.7.0 build-15820472" or os.version:="6.7.0 build-16075168" or os.version:="6.7.0 build-16316930" or os.version:="6.7.0 build-16701467" or os.version:="6.7.0 build-16713306" or os.version:="6.7.0 build-16773714" or os.version:="6.7.0 build-17167699" or os.version:="6.7.0 build-17098360" or os.version:="6.7.0 build-17167734" or os.version:="7.0.0%" or os.version:="7.0.1 build-16850804" or os.version:="7.0.1 build-17119627" or os.version:="7.0.1 build-17168206" or os.version:="7.0.1 build-17325020")

Each ESXi asset returned in the query results should be checked if the OpenSLP service is enabled. If OpenSLP is enabled, then the asset is vulnerable to exploitation.

VMware ESXi prebuilt query is available in the Queries Library

As always, any prebuilt queries are available from our Queries Library. Check out the library for other useful inventory queries.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

How to Guarantee a Completely Secure Migration to M365

Many organizations are now choosing to migrate to Microsoft 365 for a number of reasons including collaborative working options and Microsoft 365. Doing so has a number of advantages, but the movement of data can be difficult. A main consideration during the migration process can be maintaining data integrity whilst securing the data throughout the migration. Here are some migration security measures to consider to ensure a secure migration to Microsoft 365.

 

Encryption of Data
End-to-end encryption is the most secure way to communicate securely and with privacy online. The messages are encrypted at both ends of the conversation which prevents anybody in the middle from reading the private communications. Neither hackers nor unwanted third parties can access the encrypted data on the server.

CloudM Migrate has end-to-end encryption between migration endpoints. The option to Self Host CloudM Migrate will completely isolate your migration data from your source environment to the destination cloud tenant.

Both primary and secondary servers use the following components to temporarily store migration data during a migration.

  • Encrypted SQLite databases (AES256)
  • Encrypted temporary file storage (AES256)

Where CloudM Migrate requires a username or password to interact with a system, and stores sensitive data like this, that data is stored encrypted within SQL Server (AES256). SQL Server 2019 Express is installed by default but you can specify your own SQL instance.

Know your source data
Before you start migrating data, you need to know exactly what it is you’re moving. Ensure you know the format of the data, where it is in the system, and if it does actually need to be migrated. Ensure the data is clean and any data that does not need to be kept, can be disposed of to reduce costs and decrease the chance of security risks.

Know your destination
Knowing everything about where the data is coming from is half the battle, the other half is knowing where it’s going.

Ensure that you know the exact destination your data will be going to. From simple things like username conflicts to license fees, the new system will have its own set of rules and regulations.

For example, if you are moving from a legacy endpoint to Microsoft 365, you need to know that all data will be working as expected and the appropriate security compliances are in place. It is also important to ensure everything will be compatible
Back up data
Before the migration begins, ensure all data has been backed up, especially the files you will be migrating. If there are any issues or problems during the migration, such as corrupt or missing files, then you can always restore from the backup.

Get us to help
Migrations are a specialized area, bringing with them their own challenges and solutions, and the right advice from experts like us can make things go a lot smoother. It’s important to understand your limitations, as mishandling a migration can have disastrous consequences.

We know how important security is during migrations. Move to the cloud with confidence with guaranteed data integrity with zero downtime for users with our secure cloud migration tool.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About CloudM
CloudM is an award-winning SaaS company whose humble beginnings in Manchester have grown into a global business in just a few short years.

Our team of tech-driven innovators have designed a SaaS data management platform for you to get the most from your digital workspace. Whether it’s Microsoft 365, Google Workspace or other SaaS applications, CloudM drives your business through a simple, easy-to-use interface, helping you to work smarter, not harder.

By automating time-consuming tasks like IT admin, onboarding & offboarding, archiving and migrations, the CloudM platform takes care of the day-to-day, allowing you to focus on the big picture.

With over 35,000 customers including the likes of Spotify, Netflix and Uber, our all-in-one platform is putting office life on auto-pilot, saving you time, stress and money.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×