Live data from Hacker News

iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

isightpartners.com

41–50 of 78 posts

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#41
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

Yeah, I think they do this because if they can make a catchy name and logo, it becomes the focus of the media and I think they must pull in like a million hits or more to these articles. That is valuable if you have something to sell.

I think that soon there will be multiple names for each new vulerability with multiple logo-ed/brand-ed info pages. And then this trend will start to die out.

But for now, you should be worried about the latest Vulnerability[tm].

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#43
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

It looks like a sandworm from the computer games and shitty [1] film adaption of the Dune series by Frank Herbert [2].

[1] The games were great, if unrelated to the story. The film is ridiculous and uses the books merely as backdrop.

[2] Pedantic I know, but the books had pictures on the covers that showed exactly what a sandworm should look like – e.g. visible crystal teeth of a size that could be made into a dagger (a crysknife) and a hot furnace behind – not three weird flaps around a dark mouth.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#44
post #12

This exploit is delivered with a PowerPoint document, so no remote hole. It's a bit strange, that the reference a CVE (for which no information is available) and just generically describe the campaign and whatnot. The real report though is only available after a registration? That's not really the way things should be done. If there is a threat, inform people about it and don't hide all the stuff.

To get the real report you have to give them your work email address and work phone number. The context of why they are asking for that is to make sure you're qualified to receive the information but you can be darned sure that list will make its way to the marketing department.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#45
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

In defense of "branding" vulnerabilities ... Heartbleed was the first instance where "normal" people were asking me if I had heard about it and if it effected me/my business.

Attribution and PR aside, branding these helps educate the public and give them something tangible to call it/discuss.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#46

but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it What's next, "Zero-day Impacting All Versions of All Operating Systems - allows users to download and execute arbitrary code"? I suppose if you're a fan of user-hostile walled-garden trusted-computing models you might consider that a vulnerability, but I think it's safe to assume that…

XP Embedded is still a supported operating system. This CVE applies to all of those. So, yes.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#47
post #35
post #34

Earlier quoted context omitted.

Pretty sure this is about this CVE.

But I expect most servers don't have any software on them related to opening emails or Office files. I would've thought that Rackspace reserves mandatory server hotfixes for only the most serious vulnerabilities (E.G. shellshock).

While ppt's are the vector in the wild it seems the core vulnerability is in packager.dll, so possibly other ways of abusing it exist.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#48
post #7

How does > When exploited, the vulnerability allows an attacker to remotely execute arbitrary code go along with > [...] will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it [...] Is this a fucking joke? Looks like some company just want to push their name out there and get some free media exposure.

Calling it remotely exploitable indeed seems misleading. A lot of the article is just fluf without real content.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#49
post #10
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.

It was never quite this overt, but giving cute names to viruses goes back a long way.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#50
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

I wonder if it's someone's job to come up with these titles and logos?

And could you imagine putting the announcement on hold because the designer isn't 100% happy with his work... ?
Post reply on HN