Warning

 

Close

Confirm Action

Are you sure you wish to do this?

Confirm Cancel
BCM
User Panel

Site Notices
Page / 5
Link Posted: 12/18/2020 11:45:19 PM EST
[#1]
I really wouldn't want to be on 365 or Azure right now.
Link Posted: 12/18/2020 11:46:14 PM EST
[#2]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Which 3 states?
View Quote

Not sure if NC is one but the county I’m in was hit about a month ago and still down. I only know ‘cause my wife hasn’t been able to check out any e-books from the county library. I have no clue if it’s related.
Link Posted: 12/18/2020 11:47:20 PM EST
[#3]
Link Posted: 12/18/2020 11:47:25 PM EST
[#4]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I thought I’d read somewhere today that the attack has been going on for 8-9 months and it’s just in the last month that it was discovered.
View Quote


That’s usually how it works. You finally find out there’s something going on and perform forensics to see how long and a whole host of other stuff.
Link Posted: 12/18/2020 11:50:00 PM EST
[#5]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
@navvet89

My exposure to .gov IT is much more limited than yours (3 years here), but I'm utterly fucking astounded and how much 'zero fucks given' is taken to IT security where I work.  It wasn't until we got hit with a virus that my boss went "how did this happen?!" like it was some fucking surprise.

I won't list the details, but guessable passwords, deprecated unpatched OS's running in the LE side of things, passwords written on post it notes, you name it were abound.  Hell we still have an ASA running code from 10 years ago that has never been patched, and that's our primary firewall.

View Quote


Public/private entities spend more money, time and effort on compliance. This is because the auditors are more visible than the attackers.

I also have been in cybersecurity for 20 years and the money spent on compliance blows away the true defensive measures investment.
Link Posted: 12/18/2020 11:53:09 PM EST
[#6]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

Catherine Herridge has always seemed to me to be  a no nonsense,no  bullshit reporter.....
I wonder why she left Fox?
View Quote



She probably was fed up with the bs from paul ryan and Donna Brasíle
Link Posted: 12/18/2020 11:55:05 PM EST
[#7]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

it's like that just about everywhere.

In my experience executive leaderships concerns center around looking good, keeping audit and regulators off their ass and setting themselves up for the next gig. Very very rarely do they actually have the skill sets, wherewithal and fucks to give to do the right thing. My current employer only has about 3 people that have any real experience, the rest of the organizations leadership and worker bees have a complete lack of understanding of basic information security concepts. This is a Fortune 100 mind you.
View Quote


Yep, like navvet89 says, there is a serious gap in skilled individuals vs demand. The upside for us security professionals is very good compensation. The downside is companies never focus on the right things because of the difficulty in execs understanding the value of securing their shit.
Link Posted: 12/18/2020 11:55:30 PM EST
[#8]
Hillary, Obama and Kerry sold the Chinese back door access to every server the US government owns.
Link Posted: 12/18/2020 11:57:15 PM EST
[#9]
A shame they aren't targeting Facebook, Twitter, Alphabet, ABC, CBS, NBC, CNN....
Link Posted: 12/18/2020 11:57:25 PM EST
[#10]
Link Posted: 12/18/2020 11:59:39 PM EST
[#11]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
This has been going on since March 2020.  They just found it recently.
This is the tip of the iceberg.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Catherine Herridge (@CBS_Herridge) Tweeted:Microsoft's president tells @CBSNews "this attack is still taking place, the industry is scrambling, people in government are scrambling to get it under control, but it's not under control yet"

Link


Apparently this has been going on for over a month. Yeah, most secure election ever!

Here is a list so far of what agencies have been attacked

https://www.AR15.Com/media/mediaFiles/288245/a632ed55-e779-4482-aea3-c100b8589aa6_jpg-1737681.JPG
This has been going on since March 2020.  They just found it recently.
This is the tip of the iceberg.


Access cost money.

Someone paid a lot.

Someone else copied and pasted.

Now it's a convenient excuse.

Link Posted: 12/19/2020 12:01:32 AM EST
[#12]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

DOE is saying that their business networks are impacted, but they maintain pretty tight controls on access to the internal networks used with powerplants, particularly the nuke plants.  I briefly worked on a DOE contract and the restrictions were pretty strict (such as no USB devices that had not been certified through their security group, with immediate reporting requirements if you see anybody using one that does not have the appropriate clearance markings).
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Sorry citizens we are going to have to shut down the power grid for 2 weeks.... You know, too slow the curve.

DOE is saying that their business networks are impacted, but they maintain pretty tight controls on access to the internal networks used with powerplants, particularly the nuke plants.  I briefly worked on a DOE contract and the restrictions were pretty strict (such as no USB devices that had not been certified through their security group, with immediate reporting requirements if you see anybody using one that does not have the appropriate clearance markings).
Should be pretty easy to come up with a usb connection that uses the same coding standard but the physical connection is different. That way there is no relying on markings. A common store bought usb would simply not be able to fit then.
Link Posted: 12/19/2020 12:01:54 AM EST
[#13]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
A shame they aren't targeting Facebook, Twitter, Alphabet, ABC, CBS, NBC, CNN....
View Quote
I am sure some of those are on the list.
Link Posted: 12/19/2020 12:05:44 AM EST
[#14]
Whomever is doing it has full knowledge that there won't be any consequences from this current admin or the potential next admin.
Link Posted: 12/19/2020 12:05:57 AM EST
[#15]
Link Posted: 12/19/2020 12:07:11 AM EST
[#16]
We need a strong leader like biden or Harris to handle stuff like this
Link Posted: 12/19/2020 12:07:20 AM EST
[#17]
Discussion ForumsJump to Quoted PostQuote History
View Quote



This is why Arfcom should have a "like" button.
Link Posted: 12/19/2020 12:07:38 AM EST
[#18]
Discussion ForumsJump to Quoted PostQuote History
Quoted:



You two don't have a fucking clue what you're talking about. This is, quite possibly, the biggest cyber attack in history. Certainly the most sophisticated.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Nothing is happening. This is all just another 'breaking news' story to distract people from reality.
Another red herring...another nothing burger.

Wake me up when there is a single, tangible outcome that impacts any of us directly.

Quoted:
Government networks get attacked every day multiple times a day.

They got more at the link? Otherwise I'm going with sensational nothing burger.


You two don't have a fucking clue what you're talking about. This is, quite possibly, the biggest cyber attack in history. Certainly the most sophisticated.
It is pretty much Chernobyl for Solarwinds and future of IT management and monitoring.
Link Posted: 12/19/2020 12:08:22 AM EST
[#19]
Link Posted: 12/19/2020 12:11:29 AM EST
[#20]
Huh, interesting.

My company had some network issues for a few hours the other day due to getting DDoS'd.

Link Posted: 12/19/2020 12:12:28 AM EST
[#21]
Link Posted: 12/19/2020 12:14:46 AM EST
[#22]
Link Posted: 12/19/2020 12:14:58 AM EST
[#23]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

I've had to touch two of the three within the past two years, and got contacted by a recruiter about one of them today.  Thankfully, VMS is nowhere on my resume, I barely remember having to do some class assignments on it in the early '90's.
View Quote

Which VMS are you guys referring to?

HHS-OIG occasionally uses VMS and that shit is like Oregon Trail old.
Link Posted: 12/19/2020 12:21:04 AM EST
[#24]
My direct source is that the FBI asked CrowdStrike to stop announcing all the companies they are repairing.  No idea why.

Also same person said that many agencies are hit very hard with this.  I know mine is clean for now....but the bad thing is we are 100% Azure so that worries me now.

I am getting very interesting updates every 8 hours with new things to search for....this is far from over.
Link Posted: 12/19/2020 12:22:21 AM EST
[#25]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Sorry citizens we are going to have to shut down the power grid for 2 weeks.... You know, too slow the curve.
View Quote


You kid, they did in California.
Link Posted: 12/19/2020 12:40:18 AM EST
[#26]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
i wonder what the actual fallout from this will wind up looking like.

it's incredible.
View Quote



The impact in terms of data breaches could be massive.  Potentially an act of war.
Link Posted: 12/19/2020 12:42:50 AM EST
[#27]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
My direct source is that the FBI asked CrowdStrike to stop announcing all the companies they are repairing.  No idea why.

Also same person said that many agencies are hit very hard with this.  I know mine is clean for now....but the bad thing is we are 100% Azure so that worries me now.

I am getting very interesting updates every 8 hours with new things to search for....this is far from over.
View Quote
@Fourman - Can you PM me your latest CISA update?

Link Posted: 12/19/2020 12:44:34 AM EST
[#28]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
You read that right. It's been underway since roughly March.
View Quote
Right about the time the China virus was getting going here.
Link Posted: 12/19/2020 12:45:01 AM EST
[#29]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Could the “tools” recently stolen from that cyber security company be aiding “these” hackers?
View Quote

Lol, most of the CIA’s in house hacking tools were already leaked in the “Vault 7” leaks.  Just a tip, don’t open source your sensitive software to government contractors....
Link Posted: 12/19/2020 12:47:25 AM EST
[#30]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


You misspelled "most responsible SES employees will take positions at IT services companies that sell solutions to government organizations".
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:

The fallout:


The taxpayers will fund a multi-year, multi-million dollar study that will say mistakes were made but overall everybody involved was great and did the best they could, and More money needs to be spent on cyber security, but spent in the exact same manner as before the attack.

No .gov employees will be fired or reprimanded.

The most responsible SES employees will be promoted.




You misspelled "most responsible SES employees will take positions at IT services companies that sell solutions to government organizations".



You are correct.  I did misspell that one.

Link Posted: 12/19/2020 1:08:19 AM EST
[#31]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

Lol, most of the CIA’s in house hacking tools were already leaked in the “Vault 7” leaks.  Just a tip, don’t open source your sensitive software to government contractors....
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Could the “tools” recently stolen from that cyber security company be aiding “these” hackers?

Lol, most of the CIA’s in house hacking tools were already leaked in the “Vault 7” leaks.  Just a tip, don’t open source your sensitive software to government contractors....


FireEye said everything was standard red team stuff.  They were just a victim but I believe with a twist.

I wish I was more plugged into the vulnerability market this week, just to see what happened to prices.
Link Posted: 12/19/2020 1:26:58 AM EST
[#32]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

Catherine Herridge has always seemed to me to be  a no nonsense,no  bullshit reporter.....
I wonder why she left Fox?
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:

Yeah, I was kinda shocked CBS is reporting this. Heritage has been pretty solid on her reporting considering.

Catherine Herridge has always seemed to me to be  a no nonsense,no  bullshit reporter.....
I wonder why she left Fox?



They screwed her on her contract and she had been suing for years. Her contract ran out  and instead of paying her what she was asking they watched her walk out the door.
Link Posted: 12/19/2020 1:28:49 AM EST
[#33]
In a lot of ways, I am glad I got out of this shit.  I managed the company's network for about 20 years.  No love lost on any time I spent on that side job.  Eventually it was outsourced and everything was done remotely.  Gone were the days of airgaped backups stored offsite and off line.  I wish them well - well not really.
Link Posted: 12/19/2020 1:38:00 AM EST
[#34]
Link Posted: 12/19/2020 3:09:13 AM EST
[#35]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Government networks get attacked every day multiple times a day.

They got more at the link? Otherwise I'm going with sensational nothing burger.
View Quote
Right cause altering a Presidential election is a "nothing burger"
Link Posted: 12/19/2020 3:15:15 AM EST
[#36]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Right cause altering a Presidential election is a "nothing burger"
View Quote
I will admit, his first sentence is correct.
But his 2nd is willful ignorance and nothing more.

Link Posted: 12/19/2020 3:39:45 AM EST
[#37]
cyber security in the USA is a fucking joke.

inherent vulnerability built right in, plus the lax policies about the use of handheld data gathering devices and people of suspect origin..

keep all that sensitive shit connected to the www
Link Posted: 12/19/2020 8:38:05 AM EST
[#38]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


Public/private entities spend more money, time and effort on compliance. This is because the auditors are more visible than the attackers.

I also have been in cybersecurity for 20 years and the money spent on compliance blows away the true defensive measures investment.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
@navvet89

My exposure to .gov IT is much more limited than yours (3 years here), but I'm utterly fucking astounded and how much 'zero fucks given' is taken to IT security where I work.  It wasn't until we got hit with a virus that my boss went "how did this happen?!" like it was some fucking surprise.

I won't list the details, but guessable passwords, deprecated unpatched OS's running in the LE side of things, passwords written on post it notes, you name it were abound.  Hell we still have an ASA running code from 10 years ago that has never been patched, and that's our primary firewall.



Public/private entities spend more money, time and effort on compliance. This is because the auditors are more visible than the attackers.

I also have been in cybersecurity for 20 years and the money spent on compliance blows away the true defensive measures investment.
absolutely, the audit box is meant to be checked and it will be checked with the least amount of effort and at the lowest cost possible, no attention shall be paid to what happens afterward.
Link Posted: 12/19/2020 8:43:08 AM EST
[#39]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Government networks get attacked every day multiple times a day.

They got more at the link? Otherwise I'm going with sensational nothing burger.
View Quote


Attachment Attached File
Link Posted: 12/19/2020 8:45:51 AM EST
[#40]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Whoever os responsible be it China or Russia we should cripple them
View Quote


Cooridinated attack by both of them...
Link Posted: 12/19/2020 8:47:44 AM EST
[#41]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Ya think?  I putty'd into it one day about 3 years ago to look at some logs.
I discovered the last reboot was 2012.

I brought it up to my supervisor.  He said "yeah, I know.  I'm afraid if we reboot it, it won't come back up."
My response "Why the fuck is it in production then?!"

It's still in production.  Still unpatched and still not rebooted since 12.
View Quote

This is awesome.
Link Posted: 12/19/2020 8:47:50 AM EST
[#42]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I thought I’d read somewhere today that the attack has been going on for 8-9 months and it’s just in the last month that it was discovered.
View Quote


That is a great cyber team Trump created. So much funding and good leadership!
Link Posted: 12/19/2020 8:48:34 AM EST
[#43]
Have they tried rebooting the computers?

A great reset if you will.
Link Posted: 12/19/2020 8:49:43 AM EST
[#44]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
The one I think where President Trump fired the guy.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
What department is responsible for sounding the purge siren?
The one I think where President Trump fired the guy.
Well that narrows it down.
Link Posted: 12/19/2020 8:49:59 AM EST
[#45]
Link Posted: 12/19/2020 8:53:56 AM EST
[#46]
Discussion ForumsJump to Quoted PostQuote History
View Quote


You just took me back to my teenage years!  Thank you
Link Posted: 12/19/2020 9:14:15 AM EST
[#47]
User friendly and cost driven decisions undercut security everyday in IT.
Link Posted: 12/19/2020 9:14:58 AM EST
[#48]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Well that narrows it down.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Quoted:
What department is responsible for sounding the purge siren?
The one I think where President Trump fired the guy.
Well that narrows it down.


WASHINGTON (AP)  President Donald Trump on Tuesday fired the director of the federal agency that vouched for the reliability of the 2020 election.

President Trump fired Christopher Krebs in a tweet, saying his recent statement defending the security of the election was "highly inaccurate."
Link Posted: 12/19/2020 9:21:08 AM EST
[#49]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
...
Hell we still have an ASA running code from 10 years ago that has never been patched, and that's our primary firewall.

View Quote
That's like having a security guard sitting at the desk who died 10 years ago.
Link Posted: 12/19/2020 9:28:57 AM EST
[#50]
Least we forget the enemy is gainfully employed the US Government and has been for quite awhile..

https://www.forbes.com/sites/frankminiter/2017/07/26/this-exploding-dnc-story-is-crazier-than-fiction-maybe-rep-wasserman-schultz-can-explain/?sh=e259e8344144
Page / 5
Close Join Our Mail List to Stay Up To Date! Win a FREE Membership!

Sign up for the ARFCOM weekly newsletter and be entered to win a free ARFCOM membership. One new winner* is announced every week!

You will receive an email every Friday morning featuring the latest chatter from the hottest topics, breaking news surrounding legislation, as well as exclusive deals only available to ARFCOM email subscribers.


By signing up you agree to our User Agreement. *Must have a registered ARFCOM account to win.
Top Top