Foreign hackers breach US Treasury Department

2

Comments

  • Reply 21 of 41
    Just great.

    Sounds like something that Putin would do, considering his pal (crony?) has been voted out of office.

    What I want to know is: Was this a zero-day, or was treasury behind on their maintenance?

    If behind, someone needs to pay with his career.

    Microsoft to DOJ: You should look in Apple's app store.

    Me: You should look into the vulnerabilities using Microsoft software exposes you to.
    Haha. Please. Do you really believe all hacking that goes on around the world is directed by the countries the hackers reside in? There are enclaves of workaday hackers all over the world, in addition to the high-level hacking work being done by people in government.
    The reports say that it was a sophisticated attack and likely state directed. And that Russia is the main suspect. But since everyone knows trump would never stand up to Putin, we should expect knee jerk denial by trump and his followers on those points. 
    Rayz2016muthuk_vanalingamGeorgeBMacfastasleep
  • Reply 22 of 41
    Nikon8 said:
    n2macs said:
    Kuyangkoh said:
    Govt should quit using office....where’s Word Perfect??
    How about Pages?
    Wordstar? 
    Pure genius software. 

    Word was a cheap, third-rate knockoff. 
    cornchip
  • Reply 23 of 41
    I also heard it was Russia and they got in through Solar Winds software. Or also through Solar Winds software. 
    GeorgeBMac
  • Reply 24 of 41
    seanj said:
    Nikon8 said:
    n2macs said:
    Kuyangkoh said:
    Govt should quit using office....where’s Word Perfect??
    How about Pages?
    Wordstar? 
    vi ?
    emacs? ;)
  • Reply 25 of 41
    dewmedewme Posts: 5,663member
    While this attack exploited Microsoft Office 365 what made it so much worse was that a centralized software management provider SolarWinds was breached, which allowed it to spread across multiple government organizations very effectively.  This is exactly what happens when a single point failure opportunity is exploited and fails. 

    Keep single point failure vulnerabilities in mind whenever you place your trust in any functional system. Defense in depth strategies, whether for security purposes or for safety purposes, always require heterogeneity, both in implementation and execution. 
    edited December 2020
  • Reply 26 of 41
    drdavid said:
    Just great.

    Sounds like something that Putin would do, considering his pal (crony?) has been voted out of office.

    What I want to know is: Was this a zero-day, or was treasury behind on their maintenance?

    If behind, someone needs to pay with his career.

    Microsoft to DOJ: You should look in Apple's app store.

    Me: You should look into the vulnerabilities using Microsoft software exposes you to.
    Haha. Please. Do you really believe all hacking that goes on around the world is directed by the countries the hackers reside in? There are enclaves of workaday hackers all over the world, in addition to the high-level hacking work being done by people in government.
    The reports say that it was a sophisticated attack and likely state directed. And that Russia is the main suspect. But since everyone knows trump would never stand up to Putin, we should expect knee jerk denial by trump and his followers on those points. 
    It's either China or Russia I'm guessing. Your Trump comment is ridiculous. Trump sold lethal aid to Ukraine, something that angered Putin and something Obama didn't have the balls to do. So is that not standing up to Putin? 
    OctoMonkeyrazorpit
  • Reply 27 of 41
    radarthekatradarthekat Posts: 3,898moderator
    Nikon8 said:
    n2macs said:
    Kuyangkoh said:
    Govt should quit using office....where’s Word Perfect??
    How about Pages?
    Wordstar? 
    AppleWorks?
  • Reply 28 of 41
    drdavid said:
    Just great.

    Sounds like something that Putin would do, considering his pal (crony?) has been voted out of office.

    What I want to know is: Was this a zero-day, or was treasury behind on their maintenance?

    If behind, someone needs to pay with his career.

    Microsoft to DOJ: You should look in Apple's app store.

    Me: You should look into the vulnerabilities using Microsoft software exposes you to.
    Haha. Please. Do you really believe all hacking that goes on around the world is directed by the countries the hackers reside in? There are enclaves of workaday hackers all over the world, in addition to the high-level hacking work being done by people in government.
    The reports say that it was a sophisticated attack and likely state directed. And that Russia is the main suspect. But since everyone knows trump would never stand up to Putin, we should expect knee jerk denial by trump and his followers on those points. 
    It's either China or Russia I'm guessing. Your Trump comment is ridiculous. Trump sold lethal aid to Ukraine, something that angered Putin and something Obama didn't have the balls to do. So is that not standing up to Putin? 
    That was the aid trump was holding up for political purposes, holding it up also helped Putin. The aid only got released when a whistleblower went public. So no that doesn’t sound like standing up to him. 
    AI_liasGeorgeBMaccornchip
  • Reply 29 of 41
    xiao-zhi said:
    Enquiring minds want to know if the hackers used Office365 zero day vulnerabilities stolen from the NSA.

    Now that would be embarrassing.
    That seems to be what the sources in the story are implying.

  • Reply 30 of 41
    danvmdanvm Posts: 1,465member
    Beats said:
    This is way worse than 14 iPhones bending in 2014. Will there be media hysteria and mocking of Microsoft?
    Look like MS wasn't the issue in the attack.  

    Customer Guidance on Recent Nation-State Cyber Attacks – Microsoft Security Response Center
    Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor | FireEye Inc

    If you noticed, AI removed "Office 365" from the title.  So it looks that there is no need to be in hysteria or ridicule at MS, as you suggest.  
    edited December 2020 gatorguy
  • Reply 31 of 41
    danvmdanvm Posts: 1,465member
    sflocal said:
    I'm guessing it was an infected Office365 document that was clicked by someone.  
    It looks like it was more complex than someone clicking a file,

    Customer Guidance on Recent Nation-State Cyber Attacks – Microsoft Security Response Center
    Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor | FireEye Inc


    GeorgeBMac
  • Reply 32 of 41
    Fang Fang!
    razorpit
  • Reply 33 of 41
    auxioauxio Posts: 2,753member
    mainyehc said:
    seanj said:
    Nikon8 said:
    n2macs said:
    Kuyangkoh said:
    Govt should quit using office....where’s Word Perfect??
    How about Pages?
    Wordstar? 
    vi ?
    emacs? ;)
    Ed manB)
    edited December 2020
  • Reply 34 of 41
    razorpitrazorpit Posts: 1,796member
    drdavid said:
    drdavid said:
    Just great.

    Sounds like something that Putin would do, considering his pal (crony?) has been voted out of office.

    What I want to know is: Was this a zero-day, or was treasury behind on their maintenance?

    If behind, someone needs to pay with his career.

    Microsoft to DOJ: You should look in Apple's app store.

    Me: You should look into the vulnerabilities using Microsoft software exposes you to.
    Haha. Please. Do you really believe all hacking that goes on around the world is directed by the countries the hackers reside in? There are enclaves of workaday hackers all over the world, in addition to the high-level hacking work being done by people in government.
    The reports say that it was a sophisticated attack and likely state directed. And that Russia is the main suspect. But since everyone knows trump would never stand up to Putin, we should expect knee jerk denial by trump and his followers on those points. 
    It's either China or Russia I'm guessing. Your Trump comment is ridiculous. Trump sold lethal aid to Ukraine, something that angered Putin and something Obama didn't have the balls to do. So is that not standing up to Putin? 
    That was the aid trump was holding up for political purposes, holding it up also helped Putin. The aid only got released when a whistleblower went public. So no that doesn’t sound like standing up to him. 
    You’re never going to get through to these people.

    Every person that is paying attention knows the Hillary campaign paid the Russians to write the dossier. Biden literally took money from the Ukraine and bragged openly bragged about it. Hunter literally took millions from the Russians and China and we have the proof, but their hate for Trump is so bad they are willing to look past those facts and flat out make stuff up.
    OctoMonkeycornchip
  • Reply 35 of 41
    GeorgeBMacGeorgeBMac Posts: 11,421member
    drdavid said:
    I’d like to know the impacts of this as it relates to having just fired the U.S. director of cyber security and infrastructure security, Christopher Krebs. 

    Seems like a good time for the bad guys to try something. 

    The hacking started last spring -- March or April.
  • Reply 36 of 41
    GeorgeBMacGeorgeBMac Posts: 11,421member
    dewme said:
    While this attack exploited Microsoft Office 365 what made it so much worse was that a centralized software management provider SolarWinds was breached, which allowed it to spread across multiple government organizations very effectively.  This is exactly what happens when a single point failure opportunity is exploited and fails. 

    Keep single point failure vulnerabilities in mind whenever you place your trust in any functional system. Defense in depth strategies, whether for security purposes or for safety purposes, always require heterogeneity, both in implementation and execution. 

    Reportedly victims may range from government agencies to the the U.S. military to Fortune 500 Corporations.

    We'll probably never be told how far ranging this went.
  • Reply 37 of 41
    GeorgeBMacGeorgeBMac Posts: 11,421member
    razorpit said:
    drdavid said:
    drdavid said:
    Just great.

    Sounds like something that Putin would do, considering his pal (crony?) has been voted out of office.

    What I want to know is: Was this a zero-day, or was treasury behind on their maintenance?

    If behind, someone needs to pay with his career.

    Microsoft to DOJ: You should look in Apple's app store.

    Me: You should look into the vulnerabilities using Microsoft software exposes you to.
    Haha. Please. Do you really believe all hacking that goes on around the world is directed by the countries the hackers reside in? There are enclaves of workaday hackers all over the world, in addition to the high-level hacking work being done by people in government.
    The reports say that it was a sophisticated attack and likely state directed. And that Russia is the main suspect. But since everyone knows trump would never stand up to Putin, we should expect knee jerk denial by trump and his followers on those points. 
    It's either China or Russia I'm guessing. Your Trump comment is ridiculous. Trump sold lethal aid to Ukraine, something that angered Putin and something Obama didn't have the balls to do. So is that not standing up to Putin? 
    That was the aid trump was holding up for political purposes, holding it up also helped Putin. The aid only got released when a whistleblower went public. So no that doesn’t sound like standing up to him. 
    You’re never going to get through to these people.

    Every person that is paying attention knows the Hillary campaign paid the Russians to write the dossier. Biden literally took money from the Ukraine and bragged openly bragged about it. Hunter literally took millions from the Russians and China and we have the proof, but their hate for Trump is so bad they are willing to look past those facts and flat out make stuff up.

    IF you're fool enough to believe that nonsense -- then it becomes true -- for you.

    But Trump fully exposed his willingness to fabricate hate filled lies about his opponents when he started spreading his seditious lies about the U.S. election.
    edited December 2020 dewmedrdavidDogperson
  • Reply 38 of 41
    razorpit said:
    drdavid said:
    drdavid said:
    Just great.

    Sounds like something that Putin would do, considering his pal (crony?) has been voted out of office.

    What I want to know is: Was this a zero-day, or was treasury behind on their maintenance?

    If behind, someone needs to pay with his career.

    Microsoft to DOJ: You should look in Apple's app store.

    Me: You should look into the vulnerabilities using Microsoft software exposes you to.
    Haha. Please. Do you really believe all hacking that goes on around the world is directed by the countries the hackers reside in? There are enclaves of workaday hackers all over the world, in addition to the high-level hacking work being done by people in government.
    The reports say that it was a sophisticated attack and likely state directed. And that Russia is the main suspect. But since everyone knows trump would never stand up to Putin, we should expect knee jerk denial by trump and his followers on those points. 
    It's either China or Russia I'm guessing. Your Trump comment is ridiculous. Trump sold lethal aid to Ukraine, something that angered Putin and something Obama didn't have the balls to do. So is that not standing up to Putin? 
    That was the aid trump was holding up for political purposes, holding it up also helped Putin. The aid only got released when a whistleblower went public. So no that doesn’t sound like standing up to him. 
    You’re never going to get through to these people.

    Every person that is paying attention knows the Hillary campaign paid the Russians to write the dossier. Biden literally took money from the Ukraine and bragged openly bragged about it. Hunter literally took millions from the Russians and China and we have the proof, but their hate for Trump is so bad they are willing to look past those facts and flat out make stuff up.

    IF you're fool enough to believe that nonsense -- then it becomes true -- for you.

    But Trump fully exposed his willingness to fabricate hate filled lies about his opponents when he started spreading his seditious lies about the U.S. election.
    Wow...  Almost a verbatim quote from the evening news.  Perhaps you are on the e-mail list for the left-wing/socialist talking points.

    Rather than being a puppet, I prefer to think for myself!
    razorpit
  • Reply 39 of 41
    crowleycrowley Posts: 10,453member
    razorpit said:
    drdavid said:
    drdavid said:
    Just great.

    Sounds like something that Putin would do, considering his pal (crony?) has been voted out of office.

    What I want to know is: Was this a zero-day, or was treasury behind on their maintenance?

    If behind, someone needs to pay with his career.

    Microsoft to DOJ: You should look in Apple's app store.

    Me: You should look into the vulnerabilities using Microsoft software exposes you to.
    Haha. Please. Do you really believe all hacking that goes on around the world is directed by the countries the hackers reside in? There are enclaves of workaday hackers all over the world, in addition to the high-level hacking work being done by people in government.
    The reports say that it was a sophisticated attack and likely state directed. And that Russia is the main suspect. But since everyone knows trump would never stand up to Putin, we should expect knee jerk denial by trump and his followers on those points. 
    It's either China or Russia I'm guessing. Your Trump comment is ridiculous. Trump sold lethal aid to Ukraine, something that angered Putin and something Obama didn't have the balls to do. So is that not standing up to Putin? 
    That was the aid trump was holding up for political purposes, holding it up also helped Putin. The aid only got released when a whistleblower went public. So no that doesn’t sound like standing up to him. 
    You’re never going to get through to these people.

    Every person that is paying attention knows the Hillary campaign paid the Russians to write the dossier. Biden literally took money from the Ukraine and bragged openly bragged about it. Hunter literally took millions from the Russians and China and we have the proof, but their hate for Trump is so bad they are willing to look past those facts and flat out make stuff up.
    But the Hillary Clinton campaign didn't pay Russians to wriote the dossier, it was written by Christopher Steele, a British ex-MI6 agent, and was funded by a mixture of the Hillary Clinton campaign, the DNC and Fusion GPS, a political research agency under contract to a conservative website.
    Joe Biden bragged about withholding aid from Ukraine unless they fired a corrupt prosecutor, is that the "literally took money" that you're referring too? i.e. "literally not a true representation"?  Incidentally I think bragging is a bad look, and it wasn't the best act of foreign policy, but there's nothing illegal about it.
    Hunter being paid for work isn't a crime, he isn't a politician, and irrespectively the proof offered so far is highly dubious.

    So your self declared "facts" are a mix of half-truths, misrepresentations and irrelevancies.  But sure, "these people" are blinded by their hate of a President who has blatantly enriched himself and abused his power for petty and vindictive reasons, during his thankfully short though seemingly endless term in office.
    drdavidfastasleepGeorgeBMac
  • Reply 40 of 41
    razorpitrazorpit Posts: 1,796member
    crowley said:
    razorpit said:
    drdavid said:
    drdavid said:
    Just great.

    Sounds like something that Putin would do, considering his pal (crony?) has been voted out of office.

    What I want to know is: Was this a zero-day, or was treasury behind on their maintenance?

    If behind, someone needs to pay with his career.

    Microsoft to DOJ: You should look in Apple's app store.

    Me: You should look into the vulnerabilities using Microsoft software exposes you to.
    Haha. Please. Do you really believe all hacking that goes on around the world is directed by the countries the hackers reside in? There are enclaves of workaday hackers all over the world, in addition to the high-level hacking work being done by people in government.
    The reports say that it was a sophisticated attack and likely state directed. And that Russia is the main suspect. But since everyone knows trump would never stand up to Putin, we should expect knee jerk denial by trump and his followers on those points. 
    It's either China or Russia I'm guessing. Your Trump comment is ridiculous. Trump sold lethal aid to Ukraine, something that angered Putin and something Obama didn't have the balls to do. So is that not standing up to Putin? 
    That was the aid trump was holding up for political purposes, holding it up also helped Putin. The aid only got released when a whistleblower went public. So no that doesn’t sound like standing up to him. 
    You’re never going to get through to these people.

    Every person that is paying attention knows the Hillary campaign paid the Russians to write the dossier. Biden literally took money from the Ukraine and bragged openly bragged about it. Hunter literally took millions from the Russians and China and we have the proof, but their hate for Trump is so bad they are willing to look past those facts and flat out make stuff up.
    But the Hillary Clinton campaign didn't pay Russians to wriote the dossier, it was written by Christopher Steele, a British ex-MI6 agent, and was funded by a mixture of the Hillary Clinton campaign, the DNC and Fusion GPS, a political research agency under contract to a conservative website.
    Joe Biden bragged about withholding aid from Ukraine unless they fired a corrupt prosecutor, is that the "literally took money" that you're referring too? i.e. "literally not a true representation"?  Incidentally I think bragging is a bad look, and it wasn't the best act of foreign policy, but there's nothing illegal about it.
    Hunter being paid for work isn't a crime, he isn't a politician, and irrespectively the proof offered so far is highly dubious.

    So your self declared "facts" are a mix of half-truths, misrepresentations and irrelevancies.  But sure, "these people" are blinded by their hate of a President who has blatantly enriched himself and abused his power for petty and vindictive reasons, during his thankfully short though seemingly endless term in office.
    @drdavid I rest my case...
Sign In or Register to comment.