Cyber attack?

I work in sales for a tech company providing backup and disaster recovery (business continuity) solutions, think of this as a "last line of defense." If your shit gets deleted or locked, your last resort is to revert to your backup copies. My customers sell our solution to their clients, SMBs and MM.

This past Sunday there was a targeted stealth attack on SolarWinds Orion platform, a solution used primarily by large government entities like the Treasury Department and Nuclear Council or some shit, big fucking deal organizations that have crazy compliance standards. Only a handful of vendors can even serve them properly. Realistically this backdoor was exploited on millions of machines but only activated on select targets that would prove useful.

A few days prior to that attack, there was a theft of code owned by a company called FireEye which is a red team penetration testor (you hire them to hack and tell you about exploits). Their core set of penetration tools were stolen out of their system by Russian hackers. Likely FireEye was then used to execute the SolarWinds attack and most recently an attack on Microsoft 365 accounts.

The real concern is that Russian and State agencies are building very specific attacks on the developer level that are nearly impossible to detect until something is seriously compromised on a major system. The backdoor could be opened on millions of machines nationwide and not activated yet.

Basically, SolarWinds is reeling, their stock is about to get railed, their sales team across business segments is fucked, etc. FireEye is in a similar boat. Microsoft is the only one that likely won't take a serious hit because they do what the fuck they want amongst IT solution providers small to large and the government needs their help to shut this down anyway.
 
UVM Medical center got hacked weeks ago, saying it was the Russians. Ransomware. Had to send patients to neighboring hospitals because they were locked out of all patient information.
 
14214673:Charlie_Kelly said:
UVM Medical center got hacked weeks ago, saying it was the Russians. Ransomware. Had to send patients to neighboring hospitals because they were locked out of all patient information.

Why would you hack a hospital? That just seems evil
 
14214812:little1337 said:
Why would you hack a hospital? That just seems evil

Next step in global terrorism. No better way to attack a population than shutting down the medical system during a global pandemic.
 
Yeah apparently Russia has been hacking the US's most secure and sensitive data for months and Trump has yet to mention it because he's a stupid fat fuck with lockjaw for Puti's dick.

Yet another reason why Trump and his supporters are traitors to this country and should be deported to Siberia.
 
14214656:edai said:
I work in sales for a tech company providing backup and disaster recovery (business continuity) solutions, think of this as a "last line of defense." If your shit gets deleted or locked, your last resort is to revert to your backup copies. My customers sell our solution to their clients, SMBs and MM.

This past Sunday there was a targeted stealth attack on SolarWinds Orion platform, a solution used primarily by large government entities like the Treasury Department and Nuclear Council or some shit, big fucking deal organizations that have crazy compliance standards. Only a handful of vendors can even serve them properly. Realistically this backdoor was exploited on millions of machines but only activated on select targets that would prove useful.

A few days prior to that attack, there was a theft of code owned by a company called FireEye which is a red team penetration testor (you hire them to hack and tell you about exploits). Their core set of penetration tools were stolen out of their system by Russian hackers. Likely FireEye was then used to execute the SolarWinds attack and most recently an attack on Microsoft 365 accounts.

The real concern is that Russian and State agencies are building very specific attacks on the developer level that are nearly impossible to detect until something is seriously compromised on a major system. The backdoor could be opened on millions of machines nationwide and not activated yet.

Basically, SolarWinds is reeling, their stock is about to get railed, their sales team across business segments is fucked, etc. FireEye is in a similar boat. Microsoft is the only one that likely won't take a serious hit because they do what the fuck they want amongst IT solution providers small to large and the government needs their help to shut this down anyway.

Thanks for this info, seems like a less than ideal situation
 
Back
Top