Earlier quoted context omitted.
> They provide enough information (unfortunately) to identify the employee whose credentials were stolen, and she's a Sales Engineer. I'm not previously familiar with Hudson Rock, nor how "standard" disclosures around this work, but identifying the breached employee felt like an extremely shitty move to me. If a single infected laptop of a sales engineer (i.e. not even an admin with extensive access rights) resulted…
Exactly, how is an SE privileged enough to cause a problem? Or for the activities to go unnoticed? Like I would be very humiliated to have a system under my care that had this problem.
Hacker confirms access through infostealer infection [withdrawn]
191–200 of 235 posts
Re: Hacker confirms access through infostealer infection [withdrawn]
#192If data gets out, especially financial data being reported to investors, that spells curtains for a company generally.
Re: Hacker confirms access through infostealer infection [withdrawn]
#193Re: Hacker confirms access through infostealer infection [withdrawn]
#194Earlier quoted context omitted.
So the customer data is actually stored on Snowflakes AWS accounts? What difference does it make what underlying storage / provider it uses then? Also does that mean every data query to snowflake goes out/in to/from internet at egress/Ingress costs?
> So the customer data is actually stored on Snowflakes AWS accounts? Yes. > Also does that mean every data query to snowflake goes out/in to/from internet at egress/Ingress costs? Yes. It's covered comprehensively in their docs, along with the caveats. > What difference does it make what underlying storage / provider it uses then? "Snowflake does not charge data ingress fees. However, a cloud storage provider might…
Re: Hacker confirms access through infostealer infection [withdrawn]
#195Re: Hacker confirms access through infostealer infection [withdrawn]
#196Earlier quoted context omitted.
Doing some more digging, this is where the data is sourced "Hudson Rock acquires and purchases compromised data directly from top-tier threat actors operating in closed circle hacking groups. What sets our data apart is its quality in providing high accessibility to hacker groups looking for potential targets, and the speed in which we make it available to clients compared to other threat intelligence companies. Our…
About as ethical as those other 8200 alums, NSO. The ethics of the IDF on full display.
Re: Hacker confirms access through infostealer infection [withdrawn]
#197Re: Hacker confirms access through infostealer infection [withdrawn]
#198So, I was reading the comments and then in my mind I said to myself, this sounds like something connected with a Pegasus type company. The very next line in the comment I was reading was: "our boots-on-the-ground approach to cybercrime originates from the IDF's 8200 Cybercrime division"!
As others have noted, doxing the SE seems unnecessary...unless, that was part of the threat/proposal to Snowflake. You can imagine companies that had worked with that SE being concerned/need reassuring they're not affected.
I wouldn't at all be surprised if someone had bet against Snowflake stock before this story broke, if the story was hyped up enough or it was bad enough to spook the market.
Snowflake "strongly recommends" using 2FA for the admin account role, but users are free to decide whether to use it or not. Snowflake's website states: "MFA is enabled on a per-user basis; however, at this time, users are not automatically enrolled in MFA. To use MFA, users must enrol themselves." - I assume a future update will change that so they can enable it by default. MFA related questions always appear in lower-level Snowflake certs.
I'd assume (as a consultant) It would be against company policy to use a username/password for client work. Sometimes that's one of the first bad practices we see working with new clients. Perhaps that's why the SE is an ex-employee.
Re: Hacker confirms access through infostealer infection [withdrawn]
#199Earlier quoted context omitted.
Doing some more digging, this is where the data is sourced "Hudson Rock acquires and purchases compromised data directly from top-tier threat actors operating in closed circle hacking groups. What sets our data apart is its quality in providing high accessibility to hacker groups looking for potential targets, and the speed in which we make it available to clients compared to other threat intelligence companies. Our…
About as ethical as those other 8200 alums, NSO. The ethics of the IDF on full display.
* Checkpoint
* Palo Alto Networks
* Waze
* Wiz
* Cybereason
Does your theory hold up? no, but why not generalize
Re: Hacker confirms access through infostealer infection [withdrawn]
#200Earlier quoted context omitted.
About as ethical as those other 8200 alums, NSO. The ethics of the IDF on full display.
Just a side effect of any apartheid regime, it is a deeply morally corrupted nation to the very core.