Live data from Hacker News

iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

isightpartners.com

71–78 of 78 posts

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#71
post #10

Earlier quoted context omitted.

This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.

Yes. This absolutely fucking sickens me. It instantly gives news agencies an excuse to pick up every little hole and scare all the mortals into submission. Security has become a marketing and media circus now which in turn desensitizes people to real concerns and rational thought.

By labeling a bug with a catchy name it enables conversation. If there is one thing the world of security needs it more conversation. More talk == more $$$.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#72

TL;DR: Don't open attachments. Didn't we all learn this 15 years ago?

Obviously I can't confirm if this works but: > How to embed PowerPoint presentations in your web pages. > Once you've created the PowerPoint presentation, embedding it on a Web page is as easy as saving it to the Web, grabbing the embed code and pasting it onto your page - no code required. Visitors to your site will then be able to page through the presentation and interact with it directly on your Web page, from wi…

That's Powerpoint "Online" which is just a webapp and doesn't actually use the Windows version of Powerpoint with the vulnerability.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#73
post #62

"On Tuesday, October 14, 2014, iSIGHT Partners – in close collaboration with Microsoft – announced the discovery of a zero-day vulnerability..." "Over the past 5 weeks, iSIGHT Partners worked closely with Microsoft to track and monitor the exploitation of this vulnerability..." I'm sorry, I feel you should lose the right to call this a zero day when both you and Microsoft have known not only its existence, but the fa…

You are right that the usage of the term is confusing in this context. I think it still communicates two critical aspects: First, this is being exploited right now in the wild (and was when it was discovered it sounds like). Second, your windows machines are almost certainly vulnerable right this moment, and you should update immediately.

Perhaps they could have phrased it more clearly, but considering that it sounds like a full exploit on opening a powerpoint document, some alarm is appropriate.

I also think it was a little brash to name it "Sandworm" when it is not, as far as we know, a worm. It certainly has the potential to be used as the key exploit in a worm though.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#74
post #39

Earlier quoted context omitted.

Yes. This absolutely fucking sickens me. It instantly gives news agencies an excuse to pick up every little hole and scare all the mortals into submission. Security has become a marketing and media circus now which in turn desensitizes people to real concerns and rational thought.

I do see your point, however sometimes it is a good thing to let everyone know about it, so they're able to do something about it. For example, my manager even heard about "shell shock" and prompted me to do something about it. Although, it was over a week after the outbreak, and we'd already established we weren't vulnerable (applied the patch anyway) - but even so!

Yes at least 20 of our clients phoned up about this as well which is funny because we don't have any Linux machines at all.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#75

The article is filled with fluff about iSIGHT and they buried the lead. Here are the high level details they posted: * An exposed dangerous method vulnerability exists in the OLE package manager in Microsoft Windows and Server (Vista SP2 to Windows 8.1, Windows Server versions 2008 and 2012) * When exploited, the vulnerability allows an attacker to remotely execute arbitrary code * The vulnerability exists because Wi…

honestly, there needs to be a blacklist for companies that do these sort of things and iSIGHT needs to be on it.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#76

The article is filled with fluff about iSIGHT and they buried the lead. Here are the high level details they posted: * An exposed dangerous method vulnerability exists in the OLE package manager in Microsoft Windows and Server (Vista SP2 to Windows 8.1, Windows Server versions 2008 and 2012) * When exploited, the vulnerability allows an attacker to remotely execute arbitrary code * The vulnerability exists because Wi…

If someone can suggest a more neutral and accurate version of the story, we can change the URL.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#77

The article is filled with fluff about iSIGHT and they buried the lead. Here are the high level details they posted: * An exposed dangerous method vulnerability exists in the OLE package manager in Microsoft Windows and Server (Vista SP2 to Windows 8.1, Windows Server versions 2008 and 2012) * When exploited, the vulnerability allows an attacker to remotely execute arbitrary code * The vulnerability exists because Wi…

Hijacking the top comment for relevance and visibility.

Seeing how all of the other articles about this exploit are basically regurgitating iSight's announcement, I thought I'd provide something a little bit more useful.

https://www.virustotal.com/en/file/70b8d220469c8071029795d32...

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#78

Earlier quoted context omitted.

This might just be anti-microsoft bias but I think the thing here is that with a Windows vuln you can't see the source code so you really have no idea how severe the vuln is, the people who find it can simply make shit up with no one able to call them out other than Microsoft. Also maybe the average windows user will be less tech savy than a linux user and fall prey to scare tactics like these.

The "average windows user" will not even read this. Nevertheless there are many tech savvy windows users in absolute numbers.

This is exactly the type of FUD story that cable news networks love to run.
Post reply on HN