#labscon23 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #labscon23, aggregated by home.social.
-
On Friday at #LABScon23, I shared some research on the state of #MFT tool hacks. In particular, I talked about how #MOVEit has become a supply chain issue at this point, and that I strongly suspect we’ll see a long tail of breach disclosures as a result. You may not use it, but if you contract with a vendor who does (and do you even know?), your users’ data is at risk.
Last month, the Colorado Department of Health Care Policy and Financing disclosed that health data for 4 million people was stolen through the #MOVEit campaign—not because they used the tool, but because they contracted with IBM, who used it. (https://hcpf.colorado.gov/moveit)
Just this morning, I saw the news that the National Student Clearinghouse has filed a breach notification indicating that the data for more than 900 universities has been affected by #MOVEit. (https://www.helpnetsecurity.com/2023/09/25/clearinghouse-moveit-breach/)
It's been about 4 months since the initial MOVEit vulnerability disclosure, and I think we may be seeing fallout—especially from a supply chain angle, as vendors complete investigations and notify affected customers—for months to come.
-
On Friday at #LABScon23, I shared some research on the state of #MFT tool hacks. In particular, I talked about how #MOVEit has become a supply chain issue at this point, and that I strongly suspect we’ll see a long tail of breach disclosures as a result. You may not use it, but if you contract with a vendor who does (and do you even know?), your users’ data is at risk.
Last month, the Colorado Department of Health Care Policy and Financing disclosed that health data for 4 million people was stolen through the #MOVEit campaign—not because they used the tool, but because they contracted with IBM, who used it. (https://hcpf.colorado.gov/moveit)
Just this morning, I saw the news that the National Student Clearinghouse has filed a breach notification indicating that the data for more than 900 universities has been affected by #MOVEit. (https://www.helpnetsecurity.com/2023/09/25/clearinghouse-moveit-breach/)
It's been about 4 months since the initial MOVEit vulnerability disclosure, and I think we may be seeing fallout—especially from a supply chain angle, as vendors complete investigations and notify affected customers—for months to come.
-
Home from #LABScon23 and I know I’ll be thinking about many of these talks and the great conversations for days to come. Getting to talk a bit about the Internet presence and security of #MFT tools like #MOVEit and #GoAnywhere was an added bonus 📂☺️🗄️
-
Home from #LABScon23 and I know I’ll be thinking about many of these talks and the great conversations for days to come. Getting to talk a bit about the Internet presence and security of #MFT tools like #MOVEit and #GoAnywhere was an added bonus 📂☺️🗄️
-
-