https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Master Agents
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity & Inclusion
  • MSSP Insider
  • MSP 501
    • Back
    • Apply Now
    • 2020 MSP 501 Rankings
    • 2020 Hot 101 Rankings
    • 2020 MSP 501 Report
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • Videos
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
    • Channel Educational Series
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
    • Channel Convergence
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Content Resources
  • Awards
    • Back
    • 2021 MSP 501
    • Circle of Excellence
    • Excellence in Digital Services
    • Top Gun 51
  • Events
    • Back
    • CP Conference & Expo
    • Channel Evolution Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Master Agents
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity & Inclusion
  • MSSP Insider
  • MSP 501
    • Back
    • Apply Now
    • 2020 MSP 501 Rankings
    • 2020 Hot 101 Rankings
    • 2020 MSP 501 Report
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • Videos
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
    • Channel Educational Series
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
    • Channel Convergence
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Content Resources
  • Awards
    • Back
    • 2021 MSP 501
    • Circle of Excellence
    • Excellence in Digital Services
    • Top Gun 51
  • Events
    • Back
    • CP Conference & Expo
    • Channel Evolution Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

Cybersecurity Roundup

Law Firm Cyberattack Exposes Tens of Thousands of Patient Records

  • Written by Edward Gately
  • February 17, 2021
Cybercriminals prefer to target entities like law firms because of the enterprise data they possess.

… their activity becomes part of that network activity. You can’t move laterally if you’re not on the network. You can’t evade privileges if you’re not on the network.

Finally, you need to find out the hackers compromised.

“Organizations need to start operating with a mindset that a breach investigation is going to require more than a few days or a few weeks of lookback,” Sundaralingam said.

New Simulation Training Mimics Supply Side Attacks

Cloud Range has developed and released new simulation training for detection of supply side attacks like the SolarWinds hack.

A supply chain attack needs only to find the weakest link in a network to be successful, the company said. This type of attack, as a result, proves difficult to prepare for without experiencing it in a live environment.

Debbie Gordon is Cloud Range’s founder and CEO.

Cloud Range Cyber's Debbie Gordon

Cloud Range’s Debbie Gordon

“Cloud Range has developed this new supply side compromise attack scenario to provide security teams with the opportunity to practice detecting and responding to this attack type in a safe, simulated environment in order to prepare them for a similar attack that may happen in real life in the future,” she said.

Cyber defenders can “build muscle memory” and gain skills to make decisions in a split second, Gordon said.

Cyber professionals are immersed in real world cyberattacks, like the SolarWinds attack, in a safe virtual environment.

“These attacks are especially difficult to identify because the attack is coming from an otherwise trusted source,” Gordon said. “As information security matures, attackers are finding fewer soft targets remain every year. But as the name suggests, a supply chain attack need only find the weakest link in a network to be successful.”

Every SOC relies on third-party tools to perform their work, she said. Frequently patching and updating software address the overwhelming majority of security vulnerabilities. They’re two of the most valuable tools in the workbench of security personnel.

“A supply side compromise occurs when an update or patch from a third party tool has trojanized malware buried within it, waiting to spring into action once installed within an organization,” Gordon said.

By leveraging Cloud Range’s cyber range simulation exercises, MSSPs are more effective and can establish market leadership by showing customers they are proactively preparing for cyberattacks, she said.

“Cloud Range helps MSSPs and other cybersecurity providers meet their customers’ expectations by ensuring their team is constantly practicing and honing their skills in order to keep up with the growing threat landscape,” Gordon said.

Approov: Mobile Health Care Apps Leaking Sensitive Data

Many popular mobile health care apps are leaking sensitive patient data through their APIs, potentially compromising millions of patients.

That’s according to new findings issued by Approov and cybersecurity researcher Alissa Knight.

The study tested 30 popular mobile health apps. The apps exposed a minimum of 23 million users. The average number of downloads for each app tested was more than 772,000. Analysts expect the number of users exposed by the apps now available on major app stores is likely far greater.

Among vulnerabilities detailed in the report:

  • One-half (50%) of the records accessed contained names, social security numbers, addresses, birthdates, allergies, medications and other sensitive patient data.
  • One-half of the APIs tested allowed users to access the pathology, x-rays and clinical results of other patients.
  • One-half of the APIs tested also did not authenticate requests with tokens.

David Stewart is Approov‘s CEO.

Approov's David Stewart

Approov’s David Stewart

“The value of health care records on the dark web is $1,000 or six times the value of credit cards,” he said. “It’s very sensitive information because you can learn a lot about someone by reading their health care record.”

Cybercriminals will be all over this, Stewart said. That’s because people are paying that much for the information.

The pandemic has pushed services delivered by mobile apps into the spotlight, Stewart said. Health care organizations need to up their game regarding app and related API security.

  • Page 1
  • Page 2
  • Page 3
Tags: MSPs Endpoint MSSP Insider Network Specialty Practices Training and Policies

Related


  • Sophisticated hacker
    Mass Microsoft Exchange Exploitation Still Impacting Organizations
    Threat actors have a lot of options, including launching ransomware and other attacks.
  • Email Security
    Cofense's Cyberfish Acquisition Creates Email Security Solution for MSPs, MSSPs
    Both Cofense and Cyberfish are focused on email security, but have not been competitors.
  • Flaming New
    New Cybereason MSSP Program Launches in North America
    Much of the structure, resources and pricing available in the program were built based on partner guidance.
  • VPN shield on a digital background
    Fortinet FortiOS VPN Likely Exploited by Hackers, Feds Say
    Threat actors have been targeting VPNs even more this last year.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • REvil Ransomware Hits Acer, Demands Potential $100 Million Ransom
  • McAfee: Software Vulnerabilities Threaten Schools Amid Return to Campuses
  • Phishing Email Warning Shows Cybercriminals Seizing on Tax Filing Delay, Vaccine Rollout
  • Claroty Partners Get Expanded, Enhanced Channel Program

Galleries

View all

10 Ways to Keep Customers Safe with Threat Protection by Year’s End

April 9, 2021

Industry Perspectives

View all

Why Every MSP Should Consider TCO When Selecting a BCDR Solution

April 9, 2021

6 Ways to Ready Your Customers for 5G Security Challenges

April 5, 2021

Endpoint Security Is Huge in the Merging New World of Work

April 2, 2021

Webinars

View all

Top 3 Intel Security Technologies To Help Against Advanced Cybercrime Attacks

April 15, 2021

What to Look For: 2021 Threat Report

April 22, 2021

Health Care and SD-WAN: A Seller’s Guide

April 27, 2021

White Papers

View all

Top Tips: How Resellers Can Leverage Rackspace to Enhance Customer’s Cyber Security Protection with Microsoft 365 Security

March 30, 2021

Top Tips: Optimize Your Microsoft 365 Investment with Rackspace Technology

March 30, 2021

The Smart Approach to Cloud Workload Placement Decisions

March 19, 2021

Upcoming Events

View all

Channel Partners Conference & Expo

November 1, 2021 - November 4, 2021

MSP Summit

November 1, 2021 - November 2, 2021

Channel Evolution Europe

November 30, 2021 - December 1, 2021

Videos and Fastchats

View all

FASTCHAT: How Fortinet Reduces Complexity Through Networking, Security

Strong Customer Experience Needs Strong Partner Experience

December 22, 2020

Happy Holidays from Channel Partners & Channel Futures!

December 21, 2020

2021 Excellence in Digital Services Awards App Open

December 9, 2020

Twitter

ChannelFutures

"Who could ask for more?? These guys bring an awesome energy and always highlight the need-to-know of the channel..… twitter.com/i/web/status/1…

April 10, 2021
ChannelFutures

Anti-Asian racism, and racism and discrimination of all forms, have zero place in our society. #StopAsianHate and t… twitter.com/i/web/status/1…

April 9, 2021
ChannelFutures

MSSP @inc_renaissance promotes Trish Kapos to channel chief. #cybersecurity dlvr.it/RxLQ6g https://t.co/oWCdHeRqIW

April 9, 2021
ChannelFutures

.@GetSpectrum ordered to pay @Windstream more than $19 million for deceptive mailer. #lawsuit… twitter.com/i/web/status/1…

April 9, 2021
ChannelFutures

.@Percona says channel can help with #opensource solutions and #databases for everything from aspirational to must-… twitter.com/i/web/status/1…

April 9, 2021
ChannelFutures

Our latest #Cybersecurity Roundup features @HuntressLabs on @Microsoft Exchange exploitation, @ptsecurity,… twitter.com/i/web/status/1…

April 9, 2021
ChannelFutures

.@SemperisTech unveils first branded partner program. #cybersecurity dlvr.it/RxH4Bq https://t.co/TVjG8xhGNv

April 8, 2021
ChannelFutures

.@PerchSecurity announces its 2021 MSP Threat Report, calling on MSPs to build a mature cybersecurity practice.… twitter.com/i/web/status/1…

April 8, 2021

MSSP Insider

Business advice for MSSPs and news from the broader security channel.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2021 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X