Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
1–10 of 24 posts
Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
#2CVE-2022-47966 is a Zoho vulnerability, while the other is a fortigate one, both are RCEs Both have had public PoCs published at least early this year, there's a bunch more of publicly known RCEs that are still unpatched and used by some tens of thousands of machines, according to Shodan
Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
#3Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
#4It'd be useful if someone at State could inform CISA of the meaning of the term "nation-state", unless CISA is very subtly trying to signal which particular countries these attacks are coming from, since nation-states are a small subset of all countries.
Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
#5It'd be useful if someone at State could inform CISA of the meaning of the term "nation-state", unless CISA is very subtly trying to signal which particular countries these attacks are coming from, since nation-states are a small subset of all countries.
Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
#6It'd be useful if someone at State could inform CISA of the meaning of the term "nation-state", unless CISA is very subtly trying to signal which particular countries these attacks are coming from, since nation-states are a small subset of all countries.
You can't get on the 'nation state' train with that fake 'begs the question' ticket, sorry! https://news.ycombinator.com/item?id=37367891
Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
#7Earlier quoted context omitted.
You can't get on the 'nation state' train with that fake 'begs the question' ticket, sorry! https://news.ycombinator.com/item?id=37367891
I'm not in general (though I've tried to scourge it from my vocabulary) but I think it's reasonable to set the bar higher for government agencies. :)
You don't need money, don't take fame
Don't need no credit card to ride this train
Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
#8Earlier quoted context omitted.
I'm not in general (though I've tried to scourge it from my vocabulary) but I think it's reasonable to set the bar higher for government agencies. :)
Would have also accepted You don't need money, don't take fame Don't need no credit card to ride this train
Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
#9It'd be useful if someone at State could inform CISA of the meaning of the term "nation-state", unless CISA is very subtly trying to signal which particular countries these attacks are coming from, since nation-states are a small subset of all countries.
Weird pedants want to insist that the only proper use of the term is for states in the international law sense whuch are coextensive with nations in the sociological sense, which was somewhat normalized as an ideal, particularly in Europe, compared to the status quo ante by the Westphalian system, which both sonewhat aligned states with nations and resulted in states where working to reshape national identity around their own citizenry. But this sense is a pure unrealized ideal: there is essentially nothing which is actually a nation-state in this sense, though its a common aspirations, with nations without states seeking to form states and states without nations seeking to build national identities, and nations that roughly correspond to states, or vice versa, trying to round out the edges (sometimes via building more inclusive national identities, sometimes via ethnic cleansing) — but its only ever at best aoproximate and always in flux.