Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

401–410 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#402
post #374

Earlier quoted context omitted.

Holy hell... no wonder they snuffed it out in the media. I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin. The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!" I sometime find wisdom in the approach from olden times…

> Holy hell... no wonder they snuffed it out in the media. The OPM hack wasn’t ‘snuffed out’ by any means - it was fairly well covered for a cyber attack of it’s era. Perhaps it wasn’t covered much in your part of Eastern Europe, but it was definitely not covered up. The fact that some people have forgotten about it is a completely different issue.

I do watch major networks in US and the coverage on CNN and FOX amounted to 'Russia did it' or 'Russia prolly did it'. There was no meaningful coverage of impact or what the Solarwinds hack amounted to. To be frank, compared to coverage of a hurricane, it got minimal necessary coverage. I agree with parent's assertion that it was snuffed out.

Re: US companies hit by 'colossal' cyber-attack

#403

This really seems like a deliberate provocation testing the "16 sectors" considered off limits, delivered to Putin from the Biden Administration. And now waiting to see what the response is going to be, whether it was an indelible line or one drawn in sand. I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware…

There is also allegedly a reciprocal agreement to allow extradition and prosecution for cyber attacks. So we'll see if that comes to pass or if it's just a little fake glad handing until you actually try to take them up on it.

No, there was no agreement. Putin offered it up knowing the US Gov’t could never accept it.

Re: US companies hit by 'colossal' cyber-attack

#404
post #390

What are those VSA tools used for in practice? Can anyone in IT who uses them tell us. I don't mean what is sold as I mean what it is used in reality, actual operations performed.

Basically they give you mechanisms to run nearly the full gamut of IT operations remotely. Managed service providers will use these products as the foundation for their offerings...some of which are compete IT outsourcing, others are domain specific and some package it with turnkey products in which they retain responsibility to maintain the hardware.

I used to run a small security consultancy and nearly got into this business to expand our operations and get some of that sweet sweet recurring revenue. The problem I found at the time was that none of the software companies selling products that I would use were building in a security posture that I was even remotely (hur dur) comfortable with.

Re: US companies hit by 'colossal' cyber-attack

#405

Working through the IoC, I see these lines copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe Why append a random number to a copy of certutil.exe other than to change the file signature?

Because these aren't big brain operations.

Re: US companies hit by 'colossal' cyber-attack

#406

Oddly explosive headline, considering: > It is not clear what specific companies have been affected - a Kaseya representative contacted by the BBC declined to give details. So why "colossal"? > "This is a colossal and devastating supply chain attack," Huntress Labs' senior security researcher John Hammond said in an email to Reuters news agency. The BBC is going with "colossal" in their headline simply because the gu…

The BBC headline uses 'colossal' in quotation marks. So yes, it's a quote.

Re: US companies hit by 'colossal' cyber-attack

#407
post #52

Earlier quoted context omitted.

I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)

That's an accurate interpretation of what I'm saying. I don't think it's particularly bold. I don't have any hard evidence but I'm sure you could find some. I certainly don't remember ransomware attacks being very prevalent prior to last decade. They all seem to request cryptocurrencies (I can tell you're a coin head because you refer to them simply as crypto). Without cryptocurrencies ransomeware would largely go aw…

We paid a ransom with something you could buy from Walmart, I think they were called green cards or something (not to be confused with work permits). That was before crypto got huge but I think Bitcoin was around just not big yet. The cards at Walmart were preferred because at the time they were as good as anonymous cash and very easy for businesses to access.

I remember that Walmart or the govt or both made some change where these didn’t work the same way and lost their shine for ransom payments.

Thin on details but the as I recall the options for paying ransoms easily prior to crypto were tightening up.

That said, I’m 100% against the idea of fighting crypto to solve this problem. The liberty of humanity needs anonymous cash despite the risks that come with it. Better to address these problems on the data security and resiliency front.

Re: US companies hit by 'colossal' cyber-attack

#408

Working through the IoC, I see these lines copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe Why append a random number to a copy of certutil.exe other than to change the file signature?

Because a lot of EDR detections are purely string based and will be closely watching for certutil doing things that attackers like to use it for.

Making a copy with a new random name defeats this detection logic.

Re: US companies hit by 'colossal' cyber-attack

#409
post #52

Earlier quoted context omitted.

I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)

These attacks didn't exist before crypto.

That’s demonstrably not true.

Re: US companies hit by 'colossal' cyber-attack

#410
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

The insurance is a joke. I’ve seen requirements from companies that we want to do professional services for that require us to carry $5mil in cyber insurance, but nothing at all mentioned as to requirements on security governance and or policies/procedures.

Nothing will change until government regulates it. Same with auto, airlines and rail. They did not make their products and services safer by choice, they were regulated to do so.

Post reply on HN