You guys are thinking about this in a very cloudy kind of way. Assuming that Ubiquiti was being blackmailed, they have a security problem in who they hire (Who held user data for ransom). Assuming they were not being blackmailed, but had a security hole in their software, Ubiquiti has a security problem. Krebs reporting comes from a potential conflict of interest in that the person who might have been trying to black…
This turned out to be untrue on three levels: 1) There was no cover-up. Ubiquiti disclosed the attack, and was working with the FBI, working to identify what had happened, and in fact where already onto Sharp as a insider attack. 2) There was no large scale data breach. 3) The claim that there was a huge cover up was part of a extortion scheme, that Krebs was (unwittingly) assisting in.
Yes, this is a standard insider attack - and Ubiquti's security needed to be significantly better - but it doesn't change the fact that Brian Krebs reported false information - including information that he should have been in a position to know was untrue at the very least in the second article, if not the first.
Ironically enough, the person at Ubiquiti that introduced the wider GITHUB access to production secrets and new policies that allowed Nick Sharp to get production access was - according to former Ubiquiti employees - Nick Sharp.
Who watches the watchers?