FireEye Shares Details of Recent Cyber Attack
1–10 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#2Re: FireEye Shares Details of Recent Cyber Attack
#3The first is that anyone -- really, anyone -- can get hacked. I often joke with our CIO that security would be a lot easier if he just powered down our production infrastructure. Security is a game played in layers (often called "defense in depth"), but at the end of the day, it's almost impossible to prevent a breach with any high degree of certainty.
The second is that bad actors (of wildly varying skill) are very active on the Internet. The threat of hackers used to be curious teenagers trying to learn more about computer systems; it didn't take long for that to devolve into criminal activity and "hacktivism." Now, the intelligence services of major nations regularly attack public and private organizations across the Internet.
It's the job of contemporary security teams to defend against any and all threats -- but many (if not all) private organizations are ill equipped to defend against a well-organized intelligence agency in an attack such as this.
I didn't see any what the attack vector used against FireEye might have been, but those same attackers are now very well "armed" with FireEye's red team arsenal. It's going to be an interesting future for security teams as we learn what and whom these adversaries will attack next.
Re: FireEye Shares Details of Recent Cyber Attack
#4> In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts.
What does it mean to "create an internet protocol address," in this context? Did they use VPNs? VMs on cloud services? Residential proxies, luminati-style? Something else?
Re: FireEye Shares Details of Recent Cyber Attack
#5This part of the story is intriguing: > In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts. What does it mean to "create an internet protocol…
Re: FireEye Shares Details of Recent Cyber Attack
#6This part of the story is intriguing: > In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts. What does it mean to "create an internet protocol…
More: https://www.ripe.net/participate/policies/proposals/2019-08, https://www.manrs.org/2020/12/whats-the-as0-roa-policy-and-w..., https://blog.cloudflare.com/rpki-details/
Re: FireEye Shares Details of Recent Cyber Attack
#7This part of the story is intriguing: > In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts. What does it mean to "create an internet protocol…
Also how do you validate an address has never been used in an attack?
Re: FireEye Shares Details of Recent Cyber Attack
#8This part of the story is intriguing: > In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts. What does it mean to "create an internet protocol…
Also how do you validate an address has never been used in an attack?
Re: FireEye Shares Details of Recent Cyber Attack
#9As is the GitHub repo with their red team tool countermeasures, which they admirably released immediately: https://github.com/fireeye/red_team_tool_countermeasures/
Re: FireEye Shares Details of Recent Cyber Attack
#10While not necessarily the case here, every big tech company puts blame on an APT aka a nation state actor.
In fact, the very same FireEye attributed the Sony Pictures hack to North Korea on extremely flimsy grounds. By those same measures one could have implicated East Palo Alto High School.
You never regain your credibility for attribution and provenance once you have committed such a public blunder.
https://en.wikipedia.org/wiki/Sony_Pictures_hack#Doubts_abou...
It is the same as Crowdstrike going back on their wild claims while their CEO testified under oath.
https://www.realclearinvestigations.com/articles/2020/05/13/...
Is sworn testimony the only way we will get them to tell the truth?