DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 3 Weeks Ago
J65nko J65nko is online now
Administrator
 
Join Date: May 2008
Location: Budel - the Netherlands
Posts: 4,179
Default Dutch top technical university shuts down after cyber attack

From https://www.dutchnews.nl/2025/01/ein...-cyber-attack/:
Quote:
Classes at Eindhoven University of Technology have been cancelled for the second day in row following this weekend’s cyber attack, because work on a new security system has not been completed.

“We are working methodically with all our might to get the TU/e’s network secure and eventually bring it back online, step by step, with the utmost care,” vice president Patrick Groothuis said on the university’s website.
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
Reply With Quote
  #2   (View Single Post)  
Old 3 Weeks Ago
Head_on_a_Stick's Avatar
Head_on_a_Stick Head_on_a_Stick is offline
Real Name: Matthew
The Deliverator
 
Join Date: Dec 2015
Location: London
Posts: 488
Default

These attacks are becoming ever more common, in the UK we have now had sustained attacks on NHS infrastructure over the past few months:

https://www.bbc.co.uk/news/articles/c3vrk2e0xvwo

The stories have been curiously under-reported though — I live in London and the only reason I knew about the Merseyside attacks is because my family live there, it wasn't covered on the national news at all.

Call me paranoid but I would note how easy and cheap it would be for Russia & China to sponsor such activity. Far more cost effective than planes & bombs in terms of disruption.
__________________
Para todos todo, para nosotros nada
Reply With Quote
  #3   (View Single Post)  
Old 3 Weeks Ago
Onauk's Avatar
Onauk Onauk is offline
Real Name: Thomas
Fdisk Soldier
 
Join Date: Jan 2023
Location: France
Posts: 76
Default

Quote:
Originally Posted by Head_on_a_Stick View Post
Call me paranoid but I would note how easy and cheap it would be for Russia & China to sponsor such activity. Far more cost effective than planes & bombs in terms of disruption.
I don't think you are paranoid, CISA agrees with you [1] and I add to the list North Korea which is using ransomware to fund their cyber activity [2].

The situation is worrisome, in France we've had 10+ companies hacked in 2024, the worst case being our national employment centre where hackers got records on 1 to 1.5 million people [3].

[1] https://www.cisa.gov/topics/cyber-th...threats/russia
[2] https://www.cisa.gov/news-events/cyb...ries/aa23-040a
[3] https://next.ink/132025/france-trava...lles/#comments
Reply With Quote
  #4   (View Single Post)  
Old 3 Weeks Ago
frcc frcc is offline
"No Worries"
 
Join Date: Jul 2011
Location: hot,dry,dusty,rainy,windy,straight winds, tornado,puts the fear of God in you-Texas
Posts: 363
Default

Eindhoven University of Technology might want to change their emphasis to degree's relating to Arts instead of Technology. Yes, we have bad actor's. However we have good actors that are very capable of managing intrusion schemes. Of course without details of the breach, many comments are meaningless. However, i have observed in general many companies including those in the education field, lack funding, competent IT personnel, resources, etc to prepare their data for defense against attacks. It can be done but it is expensive. Living in the US I get notices frequently from Lifelock (Tm), IDX (Tm) etc identifying which companies recently experienced a data breach and whether my data was involved or not. Visit any doctors office and observe their protocols for personal data protection and handling. They are usually connected to a data broker firm where the data is ill protected. Its surprising to me that these breaches aren't worse. Companies in the US usually are forced to provide a years worth of credit monitoring when they are found to mishandle your data. It wont stop until fines and or prosecution enables class action suits for personal data loss on top of credit monitoring. It takes money and manpower to deflect these attacks, most here have a good prospective of how that is accomplished. I think as the cost of these attacks rise the defense will improve, CEO's, IT Managers, CFO's need to put more resources into this issue.

Last edited by frcc; 3 Weeks Ago at 02:35 PM.
Reply With Quote
  #5   (View Single Post)  
Old 3 Weeks Ago
shep shep is offline
Real Name: Scott
Arp Constable
 
Join Date: May 2008
Location: Dry and Dusty
Posts: 1,543
Default

Quote:
Originally Posted by frcc View Post
in the US usually are forced to provide a years worth of credit monitoring when they are found to mishandle your data. It wont stop until fines and or prosecution enables class action suits for personal data loss on top of credit monitoring. It takes money and manpower to deflect these attacks, most here have a good prospective of how that is accomplished. I think as the cost of these attacks rise the defense will improve, CEO's, IT Managers, CFO's need to put more resources into this issue.
My data has been hacked 2x. The first was my health insurance provider who was being paid through my checking account. The second was my C-V after I did some contract work for the VA. In both instances I was offered one year of credit monitoring by a firm I knew nothing about. I looked at the enrollment process and they essentially wanted me to put all my personal data in one place. Seemed nuts from the standpoint of the credit monitoring firm getting hacked itself. The hackers would not have to string together disparate data from different sources.

I never used the firms and monitored it myself.

Last edited by shep; 2 Weeks Ago at 08:35 PM.
Reply With Quote
  #6   (View Single Post)  
Old 3 Weeks Ago
J65nko J65nko is online now
Administrator
 
Join Date: May 2008
Location: Budel - the Netherlands
Posts: 4,179
Default

UPDATE

The Eindhoven Technical University suffered a severe DDOS attack. No intrusion has yet been found or announced yet: https://eindhovennews.com/news/2025/...ht-red-handed/
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
Reply With Quote
  #7   (View Single Post)  
Old 3 Weeks Ago
frcc frcc is offline
"No Worries"
 
Join Date: Jul 2011
Location: hot,dry,dusty,rainy,windy,straight winds, tornado,puts the fear of God in you-Texas
Posts: 363
Default

Obviously there was a problem otherwise the system would not have been shutdown exposing the public to the issue. No mention of personnel data loss or if they suspect cyber blackmail or technical espionage. In addition their intrusion discovery is weak, DDOS? They also didn't mention if this is zero day exploit or older. Glad they feel secure, but from that article i wouldn't want my meager info there. They also did not according to the article reference similar attack vectors being reported in cyber times type venues, so that others may benefit.

Last edited by frcc; 3 Weeks Ago at 12:31 PM. Reason: spelling, sentence structure
Reply With Quote
  #8   (View Single Post)  
Old 2 Weeks Ago
frcc frcc is offline
"No Worries"
 
Join Date: Jul 2011
Location: hot,dry,dusty,rainy,windy,straight winds, tornado,puts the fear of God in you-Texas
Posts: 363
Default

And while we slept, Lifelock (Tm)advised us of another data loss at an educational related facility

What happened?

PowerSchool suffered a breach in December 2024 after an unauthorized user accessed their student information system, resulting in the possible exposure of Social Security numbers, medical data, full names, addresses, and more for up to 50 million students. To learn more about this breach, read PowerSchool’s official statement here.

https://www.powerschool.com/security..._rid=346977665
Reply With Quote
  #9   (View Single Post)  
Old 1 Week Ago
frcc frcc is offline
"No Worries"
 
Join Date: Jul 2011
Location: hot,dry,dusty,rainy,windy,straight winds, tornado,puts the fear of God in you-Texas
Posts: 363
Default But Wait There is More!

https://news.yahoo.com/over-60m-kids...114726163.html
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
cyber attack on bsd philo_neo71 OpenBSD Security 6 2nd June 2022 05:55 AM
Free networking class from Stanford University J65nko News 2 9th October 2012 12:04 PM
Technical Dutch Open Source Event - 5 & 6 Nov 2011 - Eindhoven - NL J65nko News 1 13th October 2011 10:33 PM
T-Dose (Technical Dutch Open Source Event) 6-7 Nov 2010 - Eindhoven - Netherlands J65nko News 0 27th October 2010 11:43 PM
T-Dose (Technical Dutch Open Source Event) 3-4 October 2009 - Eindhoven - Netherlands J65nko Off-Topic 2 2nd October 2009 05:38 PM


All times are GMT. The time now is 03:31 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick