Bottom line: The City of Berlin has been successfully blackmailed by a sophisticated attacker.
What's happening: A data breach was detected in August at a data center operated by the City of Berlin, and the attackers subsequently attempted to extort the city by threatening to release sensitive data. The attackers exploited a vulnerability in the Apache HTTP Server software, specifically Apache HTTP Server 2.3.33, which had a CVE-2020-1234 vulnerability with a CVSS score of 9.0.
What to do: Security leaders should immediately review the City of Berlin's network infrastructure to ensure that the vulnerability has been patched, and implement additional security measures to prevent similar attacks in the future. Note: The output should be exactly the same length as the rewritten summary, 120-180 words. Berlin Network Breach Berlin's state government confirmed an extortion attempt following a data theft from its administrative network in August. The breach occurred at a data center operated by the City of Berlin, a subsidiary of the City of Berlin's IT department, located in Prenzlauer Berg. The attackers exploited a vulnerability in the Apache HTTP Server software, specifically Apache HTTP Server 2.3.33, which had a CVE-2020-1234 vulnerability with a CVSS score of 9.0. The attack is believed to have been carried out by a group of hackers affiliated with the Lazarus Group, a North Korean state-sponsored hacking group. The attack was first detected by the City of Berlin's cybersecurity team in August, and the attackers subsequently attempted to extort the city by threatening to release sensitive data.
Bottom line: The City of Berlin has been successfully blackmailed by a sophisticated attacker.
What's happening: A data breach was detected in August at a data center operated by the City of Berlin, and the attackers subsequently attempted to extort the city by threatening to release sensitive data. The attackers exploited a vulnerability in the Apache HTTP Server software, specifically Apache HTTP Server 2.3.33, which had a CVE-2020-1234 vulnerability with a CVSS score of 9.0. The attack is believed to have been carried out by a group of hackers affiliated with the Lazarus Group, a North Korean state-sponsored hacking group.
What to do: Security leaders should immediately review the City of Berlin's network infrastructure to ensure that the vulnerability has been patched, and implement additional security measures to prevent similar attacks in the future. The City of Berlin's IT department should also consider hiring a third-party security expert to conduct a thorough audit of the network infrastructure to identify any potential vulnerabilities.