home.social

#labscon23 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #labscon23, aggregated by home.social.

fetched live
  1. On Friday at #LABScon23, I shared some research on the state of #MFT tool hacks. In particular, I talked about how #MOVEit has become a supply chain issue at this point, and that I strongly suspect we’ll see a long tail of breach disclosures as a result. You may not use it, but if you contract with a vendor who does (and do you even know?), your users’ data is at risk.

    Last month, the Colorado Department of Health Care Policy and Financing disclosed that health data for 4 million people was stolen through the #MOVEit campaign—not because they used the tool, but because they contracted with IBM, who used it. (hcpf.colorado.gov/moveit)

    Just this morning, I saw the news that the National Student Clearinghouse has filed a breach notification indicating that the data for more than 900 universities has been affected by #MOVEit. (helpnetsecurity.com/2023/09/25)

    It's been about 4 months since the initial MOVEit vulnerability disclosure, and I think we may be seeing fallout—especially from a supply chain angle, as vendors complete investigations and notify affected customers—for months to come.

    #securityResearch #infosec #cybersecurity #CensysResearch

  2. On Friday at #LABScon23, I shared some research on the state of #MFT tool hacks. In particular, I talked about how #MOVEit has become a supply chain issue at this point, and that I strongly suspect we’ll see a long tail of breach disclosures as a result. You may not use it, but if you contract with a vendor who does (and do you even know?), your users’ data is at risk.

    Last month, the Colorado Department of Health Care Policy and Financing disclosed that health data for 4 million people was stolen through the #MOVEit campaign—not because they used the tool, but because they contracted with IBM, who used it. (hcpf.colorado.gov/moveit)

    Just this morning, I saw the news that the National Student Clearinghouse has filed a breach notification indicating that the data for more than 900 universities has been affected by #MOVEit. (helpnetsecurity.com/2023/09/25)

    It's been about 4 months since the initial MOVEit vulnerability disclosure, and I think we may be seeing fallout—especially from a supply chain angle, as vendors complete investigations and notify affected customers—for months to come.

    #securityResearch #infosec #cybersecurity #CensysResearch

  3. Home from #LABScon23 and I know I’ll be thinking about many of these talks and the great conversations for days to come. Getting to talk a bit about the Internet presence and security of #MFT tools like #MOVEit and #GoAnywhere was an added bonus 📂☺️🗄️

    #threatResearch #security #infosec

  4. Home from #LABScon23 and I know I’ll be thinking about many of these talks and the great conversations for days to come. Getting to talk a bit about the Internet presence and security of #MFT tools like #MOVEit and #GoAnywhere was an added bonus 📂☺️🗄️

    #threatResearch #security #infosec