Whistleblower: Ubiquiti Breach “Catastrophic”
krebsonsecurity.com
Whistleblower: Ubiquiti Breach “Catastrophic”
1–10 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#2Not good!
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#3Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#4Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#5What legal reason would exist for that? I thought legal would instead force them to save their users, since otherwise they would risk getting sued by all of them by all the damages caused or something.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#6But the routers have a nice user interface!
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#7> “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,”
Maybe putting your network control plane in 'the cloud' isn't such a good idea after all...
Edit: Just re-read the article, this part stood out:
> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies.
> Adam says Ubiquiti’s security team picked up signals in late December 2020 that someone with administrative access had set up several Linux virtual machines that weren’t accounted for.
If this is true, and whoever breached them had full access to their AWS account, can we really trust them to clean up all their tokens and fully eradicate all forms of persistence the hackers may have gotten?
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#8Well, guess I won't be about to drop a few thousand on Ubiquiti gear anymore until we get some more details. Hopefully this account isn't fully truthful, otherwise Ubiquiti has really screwed up.
Probably why they got into this mess. Lots of successful product people deferring 'non product' stuff.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#9I wonder why their legal department would PREVENT them from saving their users. What legal reason would exist for that? I thought legal would instead force them to save their users, since otherwise they would risk getting sued by all of them by all the damages caused or something.
Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#10Well, guess I won't be about to drop a few thousand on Ubiquiti gear anymore until we get some more details. Hopefully this account isn't fully truthful, otherwise Ubiquiti has really screwed up.
Brian Krebs is a reputable source who has a lot to lose if he makes unsubstantiated claims.