If it’s “Russia” why are they investigating if the execs were in on it?

“HAGENS BERMAN, NATIONAL TRIAL ATTORNEYS, Investigating SolarWinds (SWI) $285 Million Insider Stock Sales, Knowledge of Hack in Orion Products, Encourages SWI Investors with Losses to Contact Firm Now” https://t.co/n7AHw51r4m
SolarWinds report (Feb 2020): “2020 Key Findings
For the fifth year in a row, careless and untrained insiders are the leading source of security threats for public sector organizations”

https://t.co/TjgcuaBzUb
“‘Security is everyone’s job, but holding the team accountable is lacking. Until there are real individual accountability regimens in place, the network will remain at risk.’
- Division Chief, Federal Civilian”
Again insiders are the top threat, why ignoring in public rhetoric?

https://t.co/603WejHoYG
It doesn’t add up https://t.co/1MNMdHqyH6
Why would SolarWinds ignore this warning?

https://t.co/VVQ7TqlUzW
Important article

“The SolarWinds Perfect Storm: Default Password, Access Sales and More” https://t.co/a1xHU46nON via @threatpost
“Orion is a product with such market dominance that company CEO Kevin Thompson bragged on an October earnings call that “.....We manage everyone’s network gear.”
“In addition to its overall footprint, perhaps what made SolarWinds the most attractive vector for the attackers however is its sheer reach into customer networks.”
“access to the full network....Compromising SolarWinds makes sure an attacker does not have to worry about firewalls and other preventative security solutions.... It knows EVERYTHING on your network.”

- Marcus Hartwig, manager of security analytics, Vectra
“users of SolarWinds are IT/network admins with privileged access accounts”
“cybercriminals were spotted hawking access to SolarWinds’ infrastructure in underground forums, as far back as 2017”
“One of the access-dealers, they said, was the notorious Kazakh native known as ‘fxmsp’”
“German newspaper flagged the fact that SolarWinds has a support page advising users to disable antivirus scanning” (!) in Orion folders
“authorities have identified fxmsp as a 37-year-old Kazakhstan citizen named Andrey Turchin” https://t.co/TH0AnXfREl
“established backdoors to corporate networks and then sold them in cybercrime forums for thousands to hundreds of thousands of dollars”
“Think of almost any kind of company and there’s a good chance a prolific, financially-motivated hacker known as Fxmsp has broken into it, or attempted to” https://t.co/WpOWvufeHF
“starts by scanning for open Remote Desktop Protocol ports and then brute-forcing their way into networks. They then steal administrative credentials and modify antivirus software settings to make sure their malware remains undetected.” https://t.co/TH0AnXfREl
“sold backdoor access to hundreds of corporate networks in 44 countries via Russian-language underground forums” https://t.co/pRU52RSMy1
https://t.co/6Ex9IpsZPu
Remember the Equifax hack

https://t.co/m7yWUOxHFH
“On March 7, 2017, the Apache Software Foundation announced that some versions of its Apache Struts software had a vulnerability that could allow attackers to remotely execute code on a targeted web application.”

More from Dannielle (Dossy) Blumenthal PhD

SolarWinds follow up. Very good tweet explaining what happened.


Basically what this means is that SolarWinds itself was exploited. Someone posted an infected update as legitimate (digitally signed), leading customers to download a bad update.

“Multiple trojanized updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website” https://t.co/8e3bMFWXYu


FireEye then explains that infected organizations were approached and exploited. This is a separate Step 2.

At this point, information is already going to “malicious domains” without extra intervention, after the malware does nothing for “up to two weeks”

More from For later read

Wow, Morgan McSweeney again, Rachel Riley, SFFN, Center for Countering Digital Hate, Imran Ahmed, JLM, BoD, Angela Eagle, Tracy-Ann Oberman, Lisa Nandy, Steve Reed, Jon Cruddas, Trevor Chinn, Martin Taylor, Lord Ian Austin and Mark Lewis. #LabourLeaks #StarmerOut 24 tweet🧵

Morgan McSweeney, Keir Starmer’s chief of staff, launched the organisation that now runs SFFN.
The CEO Imran Ahmed worked closely with a number of Labour figures involved in the campaign to remove Jeremy as leader.

Rachel Riley is listed as patron.
https://t.co/nGY5QrwBD0


SFFN claims that it has been “a project of the Center For Countering Digital Hate” since 4 May 2020. The relationship between the two organisations, however, appears to date back far longer. And crucially, CCDH is linked to a number of figures on the Labour right. #LabourLeaks

Center for Countering Digital Hate registered at Companies House on 19 Oct 2018, the organisation’s only director was Morgan McSweeney – Labour leader Keir Starmer’s chief of staff. McSweeney was also the campaign manager for Liz Kendall’s leadership bid. #LabourLeaks #StarmerOut

Sir Keir - along with his chief of staff, Morgan McSweeney - held his first meeting with the Jewish Labour Movement (JLM). Deliberately used the “anti-Semitism” crisis as a pretext to vilify and then expel a leading pro-Corbyn activist in Brighton and Hove

You May Also Like

॥ॐ॥
अस्य श्री गायत्री ध्यान श्लोक:
(gAyatri dhyAna shlOka)
• This shloka to meditate personified form of वेदमाता गायत्री was given by Bhagwaan Brahma to Sage yAgnavalkya (याज्ञवल्क्य).

• 14th shloka of गायत्री कवचम् which is taken from वशिष्ठ संहिता, goes as follows..


• मुक्ता-विद्रुम-हेम-नील धवलच्छायैर्मुखस्त्रीक्षणै:।
muktA vidruma hEma nIla dhavalachhAyaiH mukhaistrlkShaNaiH.

• युक्तामिन्दुकला-निबद्धमुकुटां तत्वार्थवर्णात्मिकाम्॥
yuktAmindukalA nibaddha makutAm tatvArtha varNAtmikam.

• गायत्रीं वरदाभयाङ्कुश कशां शुभ्रं कपालं गदाम्।
gAyatrIm vardAbhayANkusha kashAm shubhram kapAlam gadAm.

• शंखं चक्रमथारविन्दयुगलं हस्तैर्वहन्ती भजै॥
shankham chakramathArvinda yugalam hastairvahantIm bhajE.

This shloka describes the form of वेदमाता गायत्री.

• It says, "She has five faces which shine with the colours of a Pearl 'मुक्ता', Coral 'विद्रुम', Gold 'हेम्', Sapphire 'नील्', & a Diamond 'धवलम्'.

• These five faces are symbolic of the five primordial elements called पञ्चमहाभूत:' which makes up the entire existence.

• These are the elements of SPACE, FIRE, WIND, EARTH & WATER.

• All these five faces shine with three eyes 'त्रिक्षणै:'.
Recently, the @CNIL issued a decision regarding the GDPR compliance of an unknown French adtech company named "Vectaury". It may seem like small fry, but the decision has potential wide-ranging impacts for Google, the IAB framework, and today's adtech. It's thread time! 👇

It's all in French, but if you're up for it you can read:
• Their blog post (lacks the most interesting details):
https://t.co/PHkDcOT1hy
• Their high-level legal decision: https://t.co/hwpiEvjodt
• The full notification: https://t.co/QQB7rfynha

I've read it so you needn't!

Vectaury was collecting geolocation data in order to create profiles (eg. people who often go to this or that type of shop) so as to power ad targeting. They operate through embedded SDKs and ad bidding, making them invisible to users.

The @CNIL notes that profiling based off of geolocation presents particular risks since it reveals people's movements and habits. As risky, the processing requires consent — this will be the heart of their assessment.

Interesting point: they justify the decision in part because of how many people COULD be targeted in this way (rather than how many have — though they note that too). Because it's on a phone, and many have phones, it is considered large-scale processing no matter what.