I mostly just rage-tweet, if that doesn't sound like fun, go be social elsewhere. Some tech-finance-infosec stuff. tweets are my own, no relation to $dayjob.
@BillAckman@HiltonHotels How is a hotel operator denying service to someone (let's say rando with a firearm) different than a baker refusing to make a cake for a gay couple?
Ivanti just disclosed CVE-2025-22457 - a critical RCE vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways. And it’s a mess.
The vuln (CVSS 9.0) was quietly patched back in February, mislabeled as a “product bug.” No mention of remote code execution, no hint that this was a zero-day actively exploited by Chinese threat actors (per Mandiant). If you read the patch notes at the time, you wouldn’t have seen any reason to panic or schedule urgent maintenance.
Now, in April, Ivanti confirms it was a critical security issue - and the “fix” is just:
Use the latest version.
Cool. But patching a device that was already compromised doesn’t exactly help, does it?
They also claim customers can “check for compromise” using something called ICT - their Integrity Checker Tool. A tool you can run on the device to look for signs of tampering.
And what are the signs?
“Look for web server crashes.”
That’s it. That’s their IOC.
No log samples.
No technical details.
No public indicators from the Mandiant investigation.
Just… “monitor for web server crashes.”
Are we supposed to treat any crash as proof of compromise now? What kind of guidance is that? These devices are black boxes. You can’t run third-party tools, no shell access, no EDR, nothing. So if ICT is the only option for detection, then the vendor should damn well provide proper detection material.
They must have more indicators from Mandiant. So why aren’t those included in the advisory? Are they hiding them in some gated customer support portal? Hoping customers will just open a ticket and figure it out later?
This isn’t transparency. This is abdication of responsibility.
Telling customers to “just patch” isn’t good enough when a zero-day has been exploited in the wild.
Telling them to “check for web server crashes” is laughable.
And pretending like running a supported version magically protects you after the fact is insulting.
Until vendors take post-exploitation guidance seriously, we’re just patching already-compromised systems and calling it a day. And threat actors love that.
https://t.co/zPoNyi94St
Brussels is watching amazed, as Trump destroys the US economy. "Nobody in the Commission thought that the US government would be this stupid and self-destructive," an EU official tells me. "That they would blow up their own country by letting ChatGPT make their trade policy." 🧵
Sounds reasonable to bring manufacturing back for important products (pharmaceuticals, weapons, chips, etc).
However, we have the lowest unemployment of our lifetimes, most Americans don’t seem to want to work in a factory and if you do build factories in 2025 you would do so with mostly robots — not humans.