FireEye Shares Details of Recent Cyber Attack
21–30 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#22https://sec.report/Document/0001370880-20-000037/ I hope to see these tools on Github soon.
Re: FireEye Shares Details of Recent Cyber Attack
#23what does "None of the tools contain zero-day exploits" exactly mean? Does the tools contain knows zero-days but not non public zero days?
EDIT: Nevermind they added something to the countermeasures repo that goes against that.
Re: FireEye Shares Details of Recent Cyber Attack
#24Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.
Re: FireEye Shares Details of Recent Cyber Attack
#25what does "None of the tools contain zero-day exploits" exactly mean? Does the tools contain knows zero-days but not non public zero days?
Re: FireEye Shares Details of Recent Cyber Attack
#26what does "None of the tools contain zero-day exploits" exactly mean? Does the tools contain knows zero-days but not non public zero days?
Re: FireEye Shares Details of Recent Cyber Attack
#27Re: FireEye Shares Details of Recent Cyber Attack
#28what does "None of the tools contain zero-day exploits" exactly mean? Does the tools contain knows zero-days but not non public zero days?
Re: FireEye Shares Details of Recent Cyber Attack
#29This is where it does not pay to be a public company. If they weren't a public company they wouldn't have to disclose this or acknowledge it and there most likely would not be a credibility damaging story which is easy to find. Sure the story could have gotten out but it would not be easy findable and would not be broadcast widely. An event like this makes major papers and nightly news.
Read that again. There is nothing that says you need to air your dirty laundry. That's not a business or legal principal (other than whatever the public company requirements might be and I am not even 100% certain this was needed but I don't know).
Also as others have pointed out indicating that it was a state sponsored actor is to me (for lack of an elegant way to put it) is 'chicken shit'. Why say that? Why not just say you were attacked and going to try and determine why and make any changes. All it does it sound like an excuse and further to say 'well others are not attacked like this and we can protect against them fine' doesn't fly.
Re: FireEye Shares Details of Recent Cyber Attack
#30I wonder if the attackers could use what they stole to impersonate FireEye. As in, some org thinks they're contracted/working with FireEye, but they're actually working with this nation state doing intelligence against the org.