We have confirmed that the threat actor exploited a 0-day in VSA servers to deliver files and scripts for the next stage. We are sharing the source IP address of the threat actor. Response teams can use this to identify possible exploitation. https://t.co/Z1ahYFgiUK
Cisco is on the list of targeted systems from the Solarwinds breach!
ggsg-us[.]cisco
GGSG is the Cisco former "Global Government Solutions Group" that has now become the Cisco Threat Response, Intelligence, and Development (TRIAD) organization.
Finalizing the report for a recent incident response.
Almost 13 days from initial breach to fully encrypted. That's longer than most. But still, if you are not able to detect, that could take months, it doesn't matter.
Yet another great example of why detection is CRITICAL!