Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
A firm that helps protect businesses and cities from cyberattacks just got hit by
#1
https://edition.cnn.com/2020/12/08/tech/...index.html        A firm that helps protect businesses and cities from cyberattacks just got hit by one
729627 CNN Digital Expansion Washington DC 2020, Brian Fung
By Brian Fung, CNN

Updated 0152 GMT (0952 HKT) December 9, 2020        (CNN)The cybersecurity firm FireEye (FEYE) said Tuesday that it had come under cyberattack by "highly sophisticated" actors likely sponsored by a nation-state, in a rare and extremely serious instance of a mainstream security vendor being compromised. The hack could even give the perpetrators the means to launch attacks against other targets.

In an investor disclosure, FireEye said the attack was highly customized to target FireEye's systems and is unlike any the company has responded to in the past.
"Based on his 25 years in cyber security and responding to incidents, Kevin Mandia, our Chief Executive Officer, concluded we are witnessing an attack by a nation with top-tier offensive capabilities," the SEC filing said.
The attacker accessed "certain Red Team assessment tools that we use to test our customers' security," the disclosure continued, implying that many of FireEye's clients, including its government customers, could be indirectly affected by the breach. "We are proactively releasing methods and means to detect the use of our stolen Red Team tools. We are not sure if the attacker intends to use our Red Team tools or to publicly disclose them. Nevertheless, out of an abundance of caution, we have developed more than 300 countermeasures for our customers, and the community at large, to use in order to minimize the potential impact of the theft of these tools."
In a blog post, Mandia said FireEye is working with the FBI and other forensic partners, including Microsoft (MSFT). Matt Gorham, assistant director of the FBI's Cyber Division, said in a statement that "preliminary indications show an actor with a high level of sophistication consistent with a nation state."
Mandia said the attackers tried to access information "related to certain government customers," but that the company has no evidence yet that customer information has been stolen.
None of the stolen cybersecurity tools contained so-called zero-day exploits, Mandia said. Zero-day vulnerabilities are software vulnerabilities that have never been publicly identified or patched, and can be extremely dangerous if weaponized by malicious actors.
The Cybersecurity and Infrastructure Security Agency, an arm of the Department of Homeland Security, said in a statement that it has been working with FireEye to determine the scope of the attack.
"As details are made available we are working to share and implement countermeasures across the federal networks and with our private sector partners," a CISA spokesperson said.
FireEye is among the world's preeminent cybersecurity firms, selling services designed to prevent, detect and respond to network security attacks. It also conducts extensive research on some of the most sophisticated hacking groups, known in the industry as advanced persistent threats.
Mike Chapple, a cybersecurity expert at the University of Notre Dame and a former National Security Agency official, called the FireEye breach "an extraordinarily significant attack."
"As one of the world's go-to cybersecurity firms, FireEye has a ringside seat for some of the most sophisticated breaches carried out worldwide," Chapple said. "The impact of this breach remains to be seen and depends upon the motivation of the attackers. We might see them go public in an attempt to monetize their work by selling exploits. On the other hand, they might remain in the shadows, stealthily using their new tools to compromise high-value systems."
Shares of FireEye fell more than 7% in after-hours trading Tuesday following the disclosure.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Taiwan Government Faces 5 Million Cyberattacks Daily mrtrout 0 519 11-11-2021 , 10:04 PM
Last Post: mrtrout
  Amnesty International links cybersecurity firm to spyware operation mrtrout 0 550 10-11-2021 , 10:02 PM
Last Post: mrtrout
  UK-based cybersecurity firm Avast in merger talks with NortonLifeLock mrtrout 0 688 07-15-2021 , 07:44 AM
Last Post: mrtrout
  Cyberattacks Should be Treated as a National Disaster in the U.S. mrtrout 0 617 07-14-2021 , 07:28 AM
Last Post: mrtrout
  McAfee sells its enterprise cybersecurity business to private equity firm for $4B mrtrout 0 828 03-09-2021 , 04:45 AM
Last Post: mrtrout

Forum Jump:


Users browsing this thread: 1 Guest(s)