CyberSecurity Instructor and Educational Technologist educating the next generation of #Cybersecurity professionals. Also tweeting about Gadgets and Animals!
It's that time of the year again - time to block off a weekend or two and watch videos from #defcon31 on #YouTube!
https://t.co/hnfvroP2tq
We've got all the main stage talks, a bunch of Village Stage talks, War Stories and the Policy series, all waiting to entertain and enlighten you. If this is somehow not enough, There's even more to choose from on https://t.co/zBJwAuObaw.
Please bingewatch responsibly, and pass it on.
All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk.
A company valued at $33,900,000,000 was defeated by a 10-minute conversation.
Let's talk about ransomware for a second.
Ransomware Threat Actors are opportunity driven. They do not have specific targets in mind. If you've got a dollar, they want it.
The reality of the matter, in the ransomware ecosystem, is initial access brokering is cheap and affordable, it is a worthwhile investment for ransomware affiliates to establish a good relationship with an initial access broker.
There is an initial access broker who will sell you roughly 1,000,000 misconfigured VPN's for $1,500. These 'misconfigured' VPNs typically will be companies which have accidentally set a VPN user login to something like 'test' as the username AND password. Although this may sound absurd, or unlikely, these are extremely common as companies may simply overlook small errors. However, these misconfigured VPNs are not curated. Ransomware affiliates might have to spend weeks, or months, sorting through the list determing which companies discovered have:
1. Money
2. Do not violate the rules of the ransomware group
3. Have insufficient security posture
4. Are outside with CIS (ex-soviet countries).
This is often how ransomware groups collide with each other. Two different initial access brokers may have identified (or gotten access) to the exact same organization and then sold this identified vulnerable organization, or access, to two different ransomware groups. There have been stories where ransomware affiliates gain access, only to discover upon entry the organization has already been ransomed!
Companies that have correctly configured EDRs (a detected blue team), a SOC, and have good policy and/or asset control will defeat most ransomware affiliates. More often than not, if an affiliate encounters a company that has a good EDR, or hardened machines, they may simply abandon the target all together (or sell it to a different ransomware operator) because it may not be worth their time. Metaphorically speaking, time is money to the Ransomware Threat Actor.
Regarding targets, there is another aspect often overlooked. Ransomware operators residing outside NATO often do not understand the culture or targets they have identified. For example, we have witnessed ransomware groups target public school systems, failing to understand how the United States allocates money for schools. They mistakenly believe tax-funded schools are ripe with cash and simply do not believe negotiators when they say the victim doesn't have the money. They rely on publicly available information (often wrong information) from places like Wikipedia or ZoomInfo. They see big numbers and believe that this is the profit margins.
tl;dr if you very seriously want to defeat ransomware, security companies need to understand the financial limitations many organizations face. They do not have the money, or man power, larger companies have to combat an ever evolving threat landscape.
NOTE: There are some caveats to this rant. Every ransomware affiliate will seek different avenues of gaining access. Blah, blah, blah.
Thanks for reading. Have a goodnight (or morning).
🚨 Wow. Imagine waking up, and your entire company's online presence is erased.
Email. Domain. Documents. Databases. Gone
Poof.
Well, that's what happened to customers of two hosting providers this week. 👇
After a decade of #CSGO, how do you prepare for the next phase of gaming’s most legendary FPS?
@fl0m & @GeT_RiGhT give us the goods on their #CS2 beta experience and share what's in store for seasoned veterans and newcomers alike in this exclusive!
https://t.co/7fQYh94DoG
Young ⚡ Talented 🏆 LIVE from #IEM Cologne!
Catch @fl0m & @GeT_RiGhT straight from the Cathedral of Counter-Strike, starting soon...
▶️ https://t.co/8oqN0o1wyk
▶️ https://t.co/pNirYk4l2G
Packing my gear and getting ready to go to #defcon31 in Las Vegas next week. It is going to be a great experience. I am looking forward to hanging out in the Hardware Hacking Village, Voting Village, AI Village and the Red Team Village.
In 1972, Bob Metcalfe presented a thesis about connecting MIT’s mainframe computer to a precursor of the internet called Arpanet. The dissertation committee failed him, saying the topic wasn’t theoretical enough. This year, he received the Turing award. https://t.co/UJnflSj0gk
OMG EXCLUSIVE FOX INSIDER TELL ALL; Says Tucker Termination was Part of Dominion Settlement
Discusses "shady" work of "friend," former Biden operative Mike LaRosa now working for Dominion
“When it’s corporate media you’re beholden to advertisers...
we take money from Pfizer"
2014: Extended support for Windows XP Service Pack 3 ended, nearly 9 years after SP3's release.
Take a seat (or stay seated) before reading below.
SP3 extended support ended:
3,287 days ago
General availability of XP:
7,835 days ago
https://t.co/p8ANnZuqAJ
Big news for the right to repair movement...this will also help in securing farm equipment and our food supply chain.
#supplychain#cybersecurity#johndeere https://t.co/1t7G3bRB0n