HACKED! Multiple Federal Agencies Including Treasury.

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

blackangst1

Lifer
Feb 23, 2005
22,914
2,359
126
Yeah the FireEye breach is a big deal. We have FireEye appliances as well as use Solarwinds. We have physically turned off our FireEyes, and the patch for Solarwinds came out today. So we're safe.
 
Reactions: Burpo

TheVrolok

Lifer
Dec 11, 2000
24,254
4,076
136
If hackers could break into the commerce department, don't you think they could break into the election computers? Is it just a coincidence that that this happened right after the election fraud issue?
Which election computers, specifically?
 

Meghan54

Lifer
Oct 18, 2009
11,573
5,095
136
Which election computers, specifically?


That's what I'd like to know, too. In GA, at least, the voting machines are not internet connected and neither are the ballot counting machines. Those put their results on portable storage media, like thumb drives. And this doesn't even count the fact the ballot machines in GA produce a paper record, so there's that, too.

Don't know whose actual balloting machines are internet connected....can't imagine anyone with a lick of sense would set it up that way.
 

HomerJS

Lifer
Feb 6, 2002
36,277
28,135
136
Yeah the FireEye breach is a big deal. We have FireEye appliances as well as use Solarwinds. We have physically turned off our FireEyes, and the patch for Solarwinds came out today. So we're safe.
The patch for SolarWinds is out? We are waiting for directives from DHS to apply. We had to turn ours off as well.
 

HomerJS

Lifer
Feb 6, 2002
36,277
28,135
136
Now the we know Russia is behind the hacks anyone notice the silence coming from the White House?

Remember when everyone was accusing Biden of hiding during the election? Where the hell is Trump? He's still supposed to do his job and I don't mean regulating showerheads.
 

blackangst1

Lifer
Feb 23, 2005
22,914
2,359
126
The patch for SolarWinds is out? We are waiting for directives from DHS to apply. We had to turn ours off as well.

Yeah we patched last night; however, I was in a SANS meeting yesterday, and they explained how the vulnerability works, the payload actions, etc. In SANS opinion, ANY version of SolarWinds is venerable.
 

hal2kilo

Lifer
Feb 24, 2009
23,647
10,507
136
Now the we know Russia is behind the hacks anyone notice the silence coming from the White House?

Remember when everyone was accusing Biden of hiding during the election? Where the hell is Trump? He's still supposed to do his job and I don't mean regulating showerheads.
Didn't care about bounties being paid by Russian to have American soldiers killed. Why change.
 
Feb 4, 2009
34,699
15,941
136
Ya’ll know in about six month there will be some kind of deep state Wikileaks type thing released. Like every current federal agency wanted the God Emperor gone so they made shit up and fiddled with the vote totals.
I predict it will happen.
 

hal2kilo

Lifer
Feb 24, 2009
23,647
10,507
136
Ya’ll know in about six month there will be some kind of deep state Wikileaks type thing released. Like every current federal agency wanted the God Emperor gone so they made shit up and fiddled with the vote totals.
I predict it will happen.
So the government will still be paying for my coverage. I guess the OMB, the Blue Cross, and I forget what else has probably run out already, time for renewal.
Just the cost of doing business.
 

hal2kilo

Lifer
Feb 24, 2009
23,647
10,507
136
Did everyone see that SolarWinds was told last year that their update server password of "solarwinds123" left them, uh, kinda vulnerable?
Their standards suck bigly. In my old job, I wouldn't have been able to use a password like that for at least the last 8 years or so.
 
Reactions: DarthKyrie

hal2kilo

Lifer
Feb 24, 2009
23,647
10,507
136
This is really, really bad folks.

Nuclear weapons agency breached amid massive cyber onslaught - POLITICO

The Energy Department and National Nuclear Security Administration, which maintains the U.S. nuclear weapons stockpile, have evidence that hackers accessed their networks as part of an extensive espionage operation that has affected at least half a dozen federal agencies, officials directly familiar with the matter said.

On Thursday, DOE and NNSA officials began coordinating notifications about the breach to their congressional oversight bodies after being briefed by Rocky Campione, the chief information officer at DOE.
 
Reactions: DarthKyrie

MrSquished

Lifer
Jan 14, 2013
21,860
20,184
136
Oh how nice of him to locate his qualms all of a sudden. Fuck off collaborator
I think he said something else about the white house not commenting on it was kinda crazy. I thought it was in that tweet but I was wrong
 

BUTCH1

Lifer
Jul 15, 2000
20,433
1,769
126
Oh how nice of him to locate his qualms all of a sudden. Fuck off collaborator
to be fair, he has been openly critical of trump, (one of few) and congratulated Biden some time ago, one of the few
Rep's I respect.
 
Reactions: Zorba

Dave_5k

Golden Member
May 23, 2017
1,650
3,200
136
CISA is now publicly admitting to the severity and ongoing difficulty in getting the hackers out of systems. This is not simply shut down/patch solarwinds and be home free, but is an advanced and persistent threat. This deep level intrusion can't be easily rooted out (if you were even a moderately high priority target that was exploited).

"CISA expects that removing this threat actor from compromised environments will be highly complex and challenging for organizations."
Compromise Mitigations
If the adversary has compromised administrative level credentials in an environment—or if organizations identify SAML abuse in the environment, simply mitigating individual issues, systems, servers, or specific user accounts will likely not lead to the adversary’s removal from the network. In such cases, organizations should consider the entire identity trust store as compromised. In the event of a total identity compromise, a full reconstitution of identity and trust services is required to successfully remediate. In this reconstitution, it bears repeating that this threat actor is among the most capable, and in many cases, a full rebuild of the environment is the safest action.

Operational Security
Due to the nature of this pattern of adversary activity—and the targeting of key personnel, incident response staff, and IT email accounts—discussion of findings and mitigations should be considered very sensitive, and should be protected by operational security measures. An operational security plan needs to be developed and socialized, via out-of-band communications, to ensure all staff are aware of the applicable handling caveats.
 

cytg111

Lifer
Mar 17, 2008
23,517
13,090
136
Add a pinch of salt :


"The Russian infiltrators could have had complete access to many important and sensitive networks for six to nine months, Bossert warns, adding that Russia’s Foreign Intelligence Service (SVR) could have used this to gain high-level control over priority networks and then covered its tracks. "

One last kick in the nuts before the puppet leaves?

AH...

"Bossert wrote that the National Defense Authorization Act (NDAA) — which Trump has threatened to veto — is essential as it would authorize the Department of Homeland Security to hunt for infiltrations in federal government networks. "

He's gonna veto it ... wait for it.

add this

"and allow for removal of military from far away, and very unappreciative, lands."
- Another stab at NATO?

He is fluffing Putin so hard right now he is either way overdue or about to go limb (Putin ed).
 
Last edited:
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |