updates etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
updates etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

15 Mayıs 2017 Pazartesi

Ransomware attacks: 29,000 infections in China as working week begins - live updates

[unable to retrieve full-text content]


Businesses and NHS brace for fresh impact as minister blames Labour for UK’s cyber-security failings


  • Did you pay money as a victim of ransomware?


Russia had nothing to do with a massive global cyberattack, President Vladimir Putin said Monday, criticising the US intelligence community for creating the original software, AFP reports.


“As for the source of these threats, Microsoft’s leadership stated this directly, they said the source of the virus was the special services of the United States,” Putin said.



Three hospitals in Ireland have been targeted by the cyber attack.


Health chiefs blocked external communication to servers until Wednesday to stop the spread of the “ransomware” virus as officials confirmed that up to 20 computers had been affected.



The health secretary, Jeremy Hunt, has broken his silence on the cyber- attacks after pressure to comment.


He said there has not been a second wave of cyber attacks after the NHS was struck by ransomware attacks on Friday, PA reports.



Thousands of NHS computers were still using the old Windows XP operating system, the government has revealed, though a Number 10 spokesman insisted other Windows’ systems were also affected.


The prime minister’s spokesman said the NHS had updated the vast majority of its systems but just under 5% were still operating Windows XP.



Health trusts across England were sent details of an IT security patch that would have protected them from the crippling ransomware attack, NHS Digital said.


NHS Digital, the arms-length body of the Department of Health that provides information, data and IT systems for the NHS, said it had made health trusts aware last month of IT protection that could have prevented the attack.



The French government cyber security agency ANSII knows of “fewer than 10” French companies that have fallen victim to a global hacking attack that hit car factories, hospitals and other organisations in about 100 countries, an ANSII spokesman said on Monday.



The Prime Minister’s official spokesman has defended health secretary Jeremy Hunt’s lack of public statements or appearances since the cyberattack on Friday.


“This is an international cyber crime, committed on an unprecedented scale.



Theresa May has rejected claims the government ignored warnings the NHS was vulnerable to a possible cyber security attack.


The Prime Minister said warnings had been given to hospital trusts.



If you paid money as a victim of ransomware we’d like to hear from you. How much were you asked to pay? Why did you decide to pay the ransom? What happened afterwards? We’d also like to hear the experiences of those who paid in other recent attacks.
You can share your stories with us – anonymously if you wish – by filling in our form here.



Few major problems have been reported in India with the hea of the government response team saying “everything seems to be normal, so far”, AP reports.


Experts estimated 5% of affected computers were in India, with the Computer Emergency Response Team of India issuing a red-colored “critical alert”.



Microsoft’s top lawyer has called on governments around the world to treat the international cyber attack as a “wake-up call” as he laid part of the blame at the door of the US administration, PA reports.


Brad Smith, the technology firm’s president and chief legal officer, criticised US intelligence agencies the CIA and the National Security Agency (NSA) for “stockpiling” software code which could be exploited by hackers.



“Hundreds of thousands” of Chinese computers at nearly 30,000 institutions including government agencies have been hit by the global ransomware attack, a leading Chinese security-software provider has said.


The enterprise-security division of Qihoo 360, one of China’s leading suppliers of anti-virus software, said 29,372 institutions ranging from government offices to universities, ATMs and hospitals had been “infected” by the outbreak as of late Saturday, AFP reports.



Blackpool Teaching Hospitals NHS Foundation Trust, NHS Blackpool Clinical Commissioning Group (CCG) and NHS Fylde and Wyre CCG are still experiencing some IT problems.


They said services are open and operating “as best as possible” but asked patients only to attend A&E in life-threatening and urgent cases.



The Royal Liverpool and Broadgreen University Hospitals Trust reported their IT system had not been attacked and was operating normally.


Likewise the Pennine Acute Hospitals NHS Trust, which runs hospitals in Manchester, Oldham and Rochdale, said they had not been affected by the attack but had taken precautionary measures to protect their IT systems.



The Southport and Ormskirk Hospital NHS Trust said patient safety is being “maintained” but difficulties are continuing.


Patients scheduled to have operations today have been asked not to attend hospital unless they have been contacted directly.



European governments and companies appeared early Monday to have avoided further fallout from a crippling global cyberattack, the police agency Europol said.


“The number of victims appears not to have gone up and so far the situation seems stable in Europe, which is a success,” senior spokesman for Europol, Jan Op Gen Oorth told AFP.



No patient data has been lost in the ransomware attack on Scottish NHS computer systems, Nicola Sturgeon has said.


Eleven health boards as well as NHS National Services and the Scottish Ambulance Service were affected Friday’s attack, PA reports.



Foreign Secretary Boris Johnson, arriving in Brussels for a meeting of EU foreign ministers, said the cyber-threat was not on the agenda.


He said: “Cyber-security is a huge issue for all of us in all our countries.



Three days on from the initial outbreak, fewer than a hundred victims of the WeCry malware appear to have given in and paid the ransom, according to analysis of the two bitcoin addresses to which the software demanded payment.


In order to restore encrypted files, the malware demands a payment of $ 300 in the cryptocurrency, sent to one of two addresses hardcoded into the software. Yet the contents of the addresses, which like all bitcoin wallets are publicly viewable, shows just under 14 bitcoin has been sent to them in total. At current exchange rates, that is worth slightly under $ 25,000, suggesting just 82 victims have paid the ransom.



Jeremy Hunt was warned last summer that the NHS was failing to prioritise cybersecurity and continued to use obsolete computer systems, the Times reported.


The Care Quality Commission and Dame Fiona Caldicott, the national data guardian, wrote to the health secretary to point out a worrying “lack of understanding of security issues” and that “the external cyberthreat is becoming a bigger consideration”.



York Teaching Hospital NHS Foundation Trust, which was hit by the attack on Friday, said some out-patient appointments had been cancelled on Monday – especially at Selby War Memorial Hospital – but most were not affected.


The trust said bone scan appoints had been cancelled in Scarborough and in Selby: “All outpatient appointments are cancelled except blood-taking and MSK physiotherapy.”



The British cybersecurity researcher described as an “accidental hero” for halting the global spread of the ransomware attack has spoken of his fears for his safety after a number of media outlets revealed his identity.


The 22-year-old, who tweets as @malwaretechblog, told the MailOnline: “In future someone might want to retaliate – they could find my identity within seconds.



Meanwhile in Japan, AP reports the ransomware attack hit computers at 600 locations but appeared to cause no major problems as Japanese started their workday Monday even as the attack caused chaos elsewhere.


Nissan Motor Co. confirmed some units had been targeted, but there was no major impact on its business.



As the UK wakes up on Monday braced for fresh impact as NHS returns to work, Chinese state media say more than 29,000 institutions across China have been infected by the global “ransomware” cyberattack, AP reports.


Xinhua News Agency reports that by Saturday evening, 29,372 institutions had been infected along with hundreds of thousands of devices. It cited the Threat Intelligence Center of Qihoo 360, a Chinese internet security services company.



Welcome to live coverage of the fallout from last Friday’s ransomware attack.


Ben Wallace, UK security minister has been on BBC Radio 4’s Today programme defending its record on investment in cyber-security.


Continue reading…



Ransomware attacks: 29,000 infections in China as working week begins - live updates

12 Mayıs 2017 Cuma

Global cyber-attack: NHS services among victims – live updates

[unable to retrieve full-text content]


• This is not targeted at the NHS, it’s an international attack, says Theresa May


• NHS England declares major incident after ransomware blocks access to patient records, internal phones and emails



More than half of Scotland’s health boards have been affected by a large-scale cyber attack on NHS computer systems. GP surgeries and dental surgeries were among some of the locations hit by the ransomware attack on IT networks, the Press Association reports.


NHS Lanarkshire said only those patients requiring emergency treatment should attend hospital while they dealt with the issue on Friday.



The Agence France-Presse news agency reports that, in Spain, employees at the telecom giant Telefónica were told to shut down their workstations immediately through megaphone announcements as the attack spread.


Forcepoint Security Labs said that “a major malicious email campaign” consisting of nearly 5m emails per hour was spreading the ransomware.



Some more quotes from the prime minister. She has told reporters:


I think what is important is that we have recognised that increasingly we need to be aware of the need to address cyber security issues, that’s why the National Cyber Security Centre has been set up. It is now able to work with the NHS to support the organisations concerned and to ensure that patient safety is protected.



After the prime minister said she was “not aware of any evidence that patient data has been compromised”, Ross Anderson, a professor of security engineering at Cambridge university, advises caution.


The NHS are saying that patient privacy hasn’t been compromised, but if significant numbers of hospitals have been negligently running unpatched computers for two months after the patch came out, how do they know?



Some more on that statement from the prime minister, Theresa May, who says:


We are aware that a number of NHS organisations have reported that they have suffered from a ransomware attack.


This is not targeted at the NHS, it’s an international attack and a number of countries and organisations have been affected.



There are reports around that as many as 40 NHS organisations have been hit by the cyber-attack. NHS Digital says it is not going to confirm the number until tomorrow.



The cyber-attack that has hit the NHS is part of a wider international attack, the prime minister Theresa May has confirmed.


She said there is no evidence that patient data had been compromised.



One expert who has worked closely with law enforcement says this would be seen as an attack on critical national infrastructure. He says investigators will be examining systems affected by the ransomware to see how badly they are affected and whether they, in turn, can or already have infected other computer systems connected to them.


He adds that the fear is that the ransonware cannot be broken and thus data and files infected are either lost or that the only way to get them back would be to pay the ransom, which would involve giving money to criminals.



One question arising from the attack on a sector of critical national infrastructure is whether the government has a policy on paying ransom to cyber hackers.


British government policy in the case of a terrorist attack or of the taking of a person hostage is clear: ransom will not be paid. But it is not clear if a policy exists for the 21st-century cyber equivalent. The lead agency dealing with the attack on the NHS is the National Cyber Security Centre, an arm of GCHQ.



The New York Times is reporting that 12 countries, including the UK, have been affected.


It reports that the attack struck “computers across a wide swath of Europe and Asia”, saying that Japan, Russia, Turkey, Vietnam and the Philippines are among those affected.



Prof Alan Woodward, a security expert from the University of Surrey, says the attackers appear to have taken advantage of a chink in the armour of Microsoft XP that was exposed in a recent leak of CIA hacking tools.


He says the problem may have been exacerbated because organisations have not updated their software with the fixes made available, or are using outdated versions.


From what we can see, it is a piece of ransomware called wanna decryptor. It goes by other names but it emerged in February 2017. Since then, it has been modified and there is evidence that it is spreading using a flaw in the Microsoft network protocol called SMB, which was exposed in the recent dump of exploits that were allegedly from US intelligence agencies.


It is not just the NHS affected: reports suggest it is a global problem. The virulence is likely to be because some organisations have either not applied the patch released by Microsoft, or they are using outdated operating systems (such as XP) that are no longer supported by Microsoft and hence no patch exists.



NHS England have released an updated statement. Dr Anne Rainsberry, the NHS incident director, said:


We’d like to reassure patients that if they need the NHS and it’s an emergency that they should visit A&E or access emergency services in the same way as they normally would and staff will ensure they get the care they need.


More widely, we ask people to use the NHS wisely while we deal with this major incident, which is still ongoing. NHS Digital are investigating the incident and across the NHS we have tried and tested contingency plans to ensure we are able to keep the NHS open for business.



Here’s a little background from my colleagues Damien Gayle, Alexandra Topping and Sarah Marsh. They report the situation as it stood at about 5pm today:


Hospitals across England have been hit by a large-scale cyber-attack, the NHS has confirmed, which has locked staff out of their computers and forced many trusts to divert emergency patients.


The IT systems of NHS sites across the country appear to have been simultaneously hit, with a pop-up message demanding a ransom in exchange for access to the PCs. NHS England has declared a major incident. NHS Digital said it was aware of the problem and would release more details soon.



The NHS has declared a major incident after it was hit by a cyber attack that is thought to have affected services across England and Scotland. Staff have been locked out of their computers and many trusts have been forced to divert emergency patients.


We’ll be updating you here as this story develops.


Continue reading…



Global cyber-attack: NHS services among victims – live updates

16 Eylül 2016 Cuma

Obama administration updates rules on publishing results of clinical trials

The Obama administration is publishing new rules that promise to help doctors and patients learn if clinical trials of treatments worked or not.


At issue is how to help people find medical studies that may be appropriate for them – and then to make the results public so that successes can reach patients more quickly and what fails isn’t duplicated.


Many clinical trials make news as they are published in scientific journals, and federal law requires reporting the results of certain studies on a government website, www.clinicaltrials.gov. But too often, that reporting doesn’t happen, especially the failures. In June, Vice-President Joe Biden cited concern that such secrecy was stifling cancer progress.


One analysis of 400 studies involving a variety of diseases found 30% had not disclosed results within four years of completion.


“That’s clearly unacceptable,” said Dr Francis Collins, director of the National Institutes of Health.


On Friday, federal health officials released updated rules making clear exactly what kinds of studies must be listed on the website so potential participants can consider enrolling, and which ones must post the results by certain deadlines.


“It does in fact have some teeth,” Collins added. Researchers that don’t meet the requirements for reporting results may face fines or lose taxpayer grants.


The long-awaited rules change takes effect on 18 January.



Obama administration updates rules on publishing results of clinical trials