@GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social avatar

GossiTheDog

@GossiTheDog@cyberplace.social

Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.

I have Direct Messages disabled - you can send them, but I will never receive them.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

The Guardian (who are themselves working out of a pub still due to a ransomware attack in December 2022) are reporting #Capita (a major IT supplier) have a "IT incident", staff have been told to not use VPN, and they are working with pen and paper since this morning. Thread follows. https://www.theguardian.com/business/2023/mar/31/capita-it-systems-fail-cyber-attack-nhs-fears?CMP=share_btn_tw

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

I had forgot how big Capita are. It's like 492304932 different business units. Shodan Safari is like looking into the sun.

It looks like some of the plc centrally use Okta for authentication.. I hope they enabled Number Verification.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The Times just filed a piece saying the outage is ongoing and hitting "every division" (only one source, not sure I buy it), with staff getting verbal 'round robin' updates. https://www.thetimes.co.uk/article/2a6270b8-cfbd-11ed-9a00-73fd2b90e22e?shareToken=1df09835bc32a38e9b8ae2b0e7556097

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The Times reporter is being verbally briefed as still don't have email (almost 10 hours in).

They're told: 'There appears to be no risk to personal data processed by the business. The outage seems to be is hitting Office365 programmes including Outlook, Excel and Teams rather than client systems...'

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Financial Times have a new article up about , saying two people familiar with the matter say cyber incident cannot be ruled out.

Curiously all the media articles about it this evening talk about the IT incident in the past tense - but it is still ongoing, it hasn't been resolved.
https://www.ft.com/content/00f9591f-e07a-4339-ba3e-413818602515

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

are still working to restore service.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Verbal update from - they’re still restoring internal service, “there is no evidence that any data has been compromised."

They won’t discuss what is happening.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

has been in contact with people at the NCSC and NCA. Interesting an IT supplier would rather talk about a 3 day ongoing IT incident than mention the cyber word.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Latest statement from - 3 days in they have restored their Office 365 access, and are now trying to restore their customer’s services. “Working in collaboration with our specialist technical partners, we have restored Capita colleague access to Microsoft Office 365 and we are making good progress restoring remaining client services in a secure and controlled manner.”

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

3CX got breached and used for supply chain delivery. I don’t know if anybody remembers my thread on Twitter last year but.. uh.. it got fun. https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Cool find by @nieldk - if you isolate an asset in MDE (Microsoft Defender), Windows Subsystem for Linux still allows all network traffic (including internally!). So if you're a threat actor, just install WSL, setup SSH or some such and persist access post isolation.

I suspect MS probably need to revisit this one as the attack surface looks rich and unconsidered. E.g. network connections in WSL aren't even logged by Defender.

https://sec1.dk/blog.html

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

I had a quick look at the Defender/WSL (Windows Subsystem for Linux) thing at lunch.

It's pretty comical, it looks like the WSL team have unfortunately undercut Defender. E.g. you don't even need to port a backdoor to Linux to maintain access on isolation -- you can just run a Windows trojan in Wine (works in WSL) & the network traffic isn't inspected, logged in Advanced Hunting Query or blocked on isolation. Also WSL can access any local or network files. And it ships built into Windows OS.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Found the 2020’s decade book

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

PSA: If you use Backup & Replication (very common), upgrade. Especially if you face server to internet.

Screenshot from Code White, the API lets you remotely request Windows admin credentials for some reason, no auth request.

In their advisory Veeam claimed these are encrypted... it's base64 (lololol)

https://www.veeam.com/kb4424

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

lol, a way to bypass the Microsoft account requirement in Windows 11 - type username no@thankyou.com, any password, and it bumps you to local account creation.

image/png

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar
GossiTheDog,
@GossiTheDog@cyberplace.social avatar

- everything in dishnetwork.com doesn’t exist DNS wise. They have the name servers pointed at ns-01.dish.com, ns-02.dish.com which also don’t exist.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The evidence with points less towards ransomware and more towards this.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

I’ve been looking at the situation some more. Based on network boundary, domain name changes and various other artefacts, it appears they may have experienced a destructive attack. Even their business services are MIA. They have a series of sites hosted directly by Wordpress.com, and even those have been deleted.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

I would highly recommend Okta customers enable Number Challenge via Okta support on their accounts (similar to Number Matching in Azure MFA, see also LAPSUS$, NewGen, WorstGen, SS etc attacks). https://support.okta.com/help/s/article/Number-Challenge-for-Okta-Verify?language=en_US

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The situation looks bad. They haven’t recovered services 5 days later, and haven’t provided any transparency at all around what has happened. Their share price dropped 8% yesterday.

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

The “internal system outage”, as they described to shareholders on results day, turns out to be due to a attack they’re still recovering from, with data exfiltrated. We only know as they were legally required to disclose to regulators.

https://techcrunch.com/2023/02/28/dish-cyberattack-personal-data-theft/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

are still trying to recover from their ransomware/destruction incident. Their share price has not recovered either.

image/jpeg

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

did have a webpage up about their “system issues” (read: NotLapsus style destructive attack), but now it has basically replaced its front page banner with ‘we fucked, yo’. Nightmare fuel incident clearly, most of their boundary systems appear to still to be missing.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

A judge used ChatGPT AI chatbot to write a decision in a court case about an autistic child’s healthcare, including to write the arguments about the legal technicalities, as they said deciding takes too long. Jesus fucking christ. https://www.vice.com/en/article/k7bdmv/judge-used-chatgpt-to-make-court-decision

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • cubers
  • cisconetworking
  • osvaldo12
  • magazineikmin
  • Youngstown
  • thenastyranch
  • rosin
  • slotface
  • Durango
  • mdbf
  • khanakhh
  • megavids
  • tacticalgear
  • InstantRegret
  • normalnudes
  • modclub
  • ngwrru68w68
  • everett
  • GTA5RPClips
  • ethstaker
  • anitta
  • Leos
  • tester
  • provamag3
  • lostlight
  • All magazines