Whistleblower: Ubiquiti Breach “Catastrophic”
11–20 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#12tsk.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#13> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#14Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#15> Adam wrote in his letter. “Legal overrode the repeated requests to force rotation of all customer credentials, and to revert any device access permission changes within the relevant period.” tsk.
Crazy.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#16Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#17This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#18Perversely, this is exactly the logging that you want to have in place in case of a breach.
You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#19Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#20A root user user breach, seemingly on the organization main account. Ouch.
I wonder if MFA was set up, with the TOTP creds also kept in LastPass.