Aida Akl · @AAKL
398 followers · 677 posts · Server noc.social

Opinion by . 🤣

And they've got nerve: "The government should further incentivize companies for responsible disclosure and information-sharing."

Paving a Path to Security by Design Across the Industry infosecurity-magazine.com/opin

#infosec #cybersecurity #solarwinds

Last updated 1 year ago

Paul Sochacki, MS · @RebelGeek99
24 followers · 65 posts · Server mstdn.science
Tomas Karban · @tomaskarban
3 followers · 23 posts · Server techhub.social

The article about by WIRED reads like a Jeff Aiken novel by Mark Russinovich. As a software engineer, I wonder about the complexity of our build system, which is reasonably proportional to the complexity of the product. How can I simplify it? How can I ensure that every step of the way is safe and building my lines of code and not trojan horses?

wired.com/story/the-untold-sto

#solarwinds #supplychain #attack #orionsoftware #svr #hacker

Last updated 1 year ago

Jim · @N4JAW
786 followers · 874 posts · Server mastodon.radio
BobGourley · @BobGourley
571 followers · 268 posts · Server defcon.social

Solar Winds, the enterprise technology company made famous after suffering a nation state directed cyber attack in 2020, has been served notice by the SEC that further action is coming. Not only did they receive their own Wells Notice in October, but now two individuals, their CFO and CISO, have as well.

This is the first time a CISO has received a Wells Notice.

What should corporate directors know and do about this? To shed some light on the practical implications for business leaders we will ask for insights from two of our OODA network experts, Bob Flores and Junaid Islam.

See the video at:

youtu.be/qyVasswen4E

#solarwinds #sec #wellsnotice #cybersecurity #defcon #ciso #ooda

Last updated 1 year ago

True boyscouts.

#wired #solarwinds

Last updated 1 year ago

Jim · @N4JAW
729 followers · 784 posts · Server mastodon.radio

What a morning. & an FT8 mini pileup. What more can one ask for from such a great hobby

#ParksOnTheAir #pota #hamradio #amateurradio #solarwinds #solarflares

Last updated 1 year ago

Luny · @luny
26 followers · 205 posts · Server mstdn.games

@ZXVintage The advert on the left for is an original artwork by Peter Andrew Jones, used on the cover of the brilliant book by Larry Niven. Jones' artwork was one of the outstanding designs in sci-fi, really giving a feel for out-worldly things.

#bloodymoney #protector #scifi #gameart #solarwinds

Last updated 1 year ago

Max Legroom ☕ · @maxmm77
69 followers · 371 posts · Server toot.community
Adam ♿ · @voltagex
397 followers · 1120 posts · Server aus.social

wired.com/story/the-untold-sto is an absolutely fantastic article that will definitely be turned into a 6 part podcast with far too many ads and filler.

#infosec #solarwinds #wiredmagazine

Last updated 1 year ago

Nicolas Ward · @ultranurd
533 followers · 2645 posts · Server tacobelllabs.net

: The Untold Story of the Boldest Supply-Chain Hack — Fascinating deep dive wired.com/story/the-untold-sto

#solarwinds #cybersecurity

Last updated 1 year ago

Miguel Afonso Caetano · @remixtures
407 followers · 1416 posts · Server tldr.nettime.org

: "According to sources with knowledge of the incident, the DOJ discovered suspicious traffic passing from the server to the internet in late May, so they asked one of the foremost security and digital forensics firms in the world—Mandiant—to help them investigate. They also engaged Microsoft, though it’s not clear why. (A Justice Department spokesperson confirmed that this incident and investigation took place but declined to say whether Mandiant and Microsoft were involved. Neither company chose to comment on the investigation.)

According to the sources familiar with the incident, investigators suspected the hackers had breached the Justice Department server directly, possibly by exploiting a vulnerability in the SolarWinds software. The Justice Department team contacted the company, even referencing a specific file that they believed might be related to the issue, according to the sources, but SolarWinds’ engineers were unable to find a vulnerability in their code. After weeks of back and forth the mystery was still unresolved, and the communication between investigators and SolarWinds stopped. (SolarWinds declined to comment on this episode.) The department, of course, had no idea about Volexity’s uncannily similar hack."

wired.com/story/the-untold-sto

#usa #cybersecurity #supplychain #doj #solarwinds

Last updated 1 year ago

PrivacyDigest · @PrivacyDigest
310 followers · 1287 posts · Server mas.to

: The Untold Story of the Boldest Supply-Chain

The attackers were in thousands of corporate and government networks. They might still be there now. Behind the scenes of the SolarWinds investigation.

wired.com/story/the-untold-sto

#supplychain #hack #solarwinds

Last updated 1 year ago

Kevin Beaumont · @GossiTheDog
26850 followers · 1045 posts · Server cyberplace.social

Fantastic reporting by @kimzetter here - a year long report into what went down with .

I'd like to highlight this bit. Zero trust, my arse. Lots of new details in this report. wired.com/story/the-untold-sto

#solarwinds

Last updated 1 year ago

Miguel Afonso Caetano · @remixtures
397 followers · 1358 posts · Server tldr.nettime.org

: "WIRED can now confirm that the operation was actually discovered by the DOJ six months earlier, in late May 2020—but the scale and significance of the breach wasn’t immediately apparent. Suspicions were triggered when the department detected unusual traffic emanating from one of its servers that was running a trial version of the Orion software suite made by SolarWinds, according to sources familiar with the incident. The software, used by system administrators to manage and configure networks, was communicating externally with an unfamiliar system on the internet. The DOJ asked the security firm Mandiant to help determine whether the server had been hacked. It also engaged Microsoft, though it’s not clear why the software maker was also brought onto the investigation."

wired.com/story/solarwinds-hac

#usa #cybersecurity #doj #hacking #solarwinds

Last updated 2 years ago

Aida Akl · @AAKL
268 followers · 650 posts · Server noc.social
· @twitter
1 followers · 48989 posts · Server mstdn.skullb0x.io

Referenced link: darkreading.com/vulnerabilitie
Originally posted by Dark Reading / @DarkReading@twitter.com: twitter.com/DarkReading/status

The threat group behind the SolarWinds supply chain attacks is back with new tools for spying on officials in NATO countries and Africa. @nerdiegaga has the story. darkreading.com/vulnerabilitie

#solarwinds

Last updated 2 years ago

· @NaturalNews
6025 followers · 28526 posts · Server brighteon.social
· @twitter
1 followers · 45031 posts · Server mstdn.skullb0x.io

Referenced link: darkreading.com/endpoint/autom
Originally posted by Dark Reading / @DarkReading@twitter.com: twitter.com/DarkReading/status

Massive supply chain cyberattack via digitally signed & compromised 3CX DesktopApp causing some SolarWinds & Kaseya deja vu. @jaivijayan has the story: darkreading.com/endpoint/autom

#solarwinds #3CXDesktopApp #supplychain

Last updated 2 years ago

KaylinQ · @KaylinQ
158 followers · 590 posts · Server mstdn.science