Intelligent CISO Issue 75 | Page 25

UPDATES
3
4
4
2 3

threat

UPDATES
3
AUSTRALIA
The Australian Government is working with a former national prescription delivery service provider , MediSecure , to respond to a cyberincident affecting the company .
This service enabled prescriptions to be delivered from prescribers to a pharmacy of an individual ’ s choice ( for paper and electronic prescriptions ). Until late 2023 , MediSecure was one of two prescription delivery services operating nationally .
In May 2023 the Australian Government finalised a tender for this service , awarded exclusively to another company , Fred IT Group ’ s eRx Script Exchange ( eRx ).
The national prescription delivery service , eRx , was not affected by this cyberincident . Consumers continued to access medicines safely , and healthcare providers still prescribed and dispensed as usual .
4
CHINA
A forensic investigation report published by Sygnia uncovered how the chinese-nexus state-sponsored threat actor , Velvet Ant , well-known for its sophisticated and innovative espionage tactics , had been involved in an extensive infiltration of a large East-Asian organisation for almost three years before being uncovered .
Velvet Ant used outdated F5 BIG-IP equipment as internal commandand-control ( C & C ) servers to stay under the radar in a bid to maintain multiple footholds to the target network and methodically obtain private data , including financial and customer information .
This incident highlights the importance of establishing resilient defence strategies against sophisticated threats – particularly those posed by state-sponsored groups .
The National Cyber Security Coordinator is working with agencies across the Australian Government , as well as states and territories to co-ordinate a whole-of-government response to this incident .
4
2 3
WWW . INTELLIGENTCISO . COM 25