Top US cyber security firm FireEye hit by 'state-sponsored adversary'
Wednesday, December 9, 2020
Top US-based cyber security firm FireEye has suffered an attack by what it calls a "highly sophisticated state-sponsored adversary", which has seen its Red Team tools falling into the hands of bad actors.
Unanswered questions
Ilia Kolochenko, founder and chief architect at ImmuniWeb SA, says the incident appears to be quite "mysterious and obscure".
On the one hand, Kolochenko says, FireEye readily talks about a "highly sophisticated state-sponsored adversary", on the other, says that no zero-days or otherwise highly valuable data was stolen.
"Why would a nation-state APT ever bother to expose their own zero-days and advanced hacking techniques to get a collection of semi-public Red Teaming tools?"
According to him, too many critical questions remain unanswered, such as when did the incident happen, which systems are impacted, and what are the chances that customers’ data was compromised?
"We cannot exclude a probability that this specific incident was merely a smokescreen aimed to distract FireEye from a more important attack targeting clients’ data or ultra-confidential private research. More transparency is expected from FireEye to dispel the doubts and bring clarity.” Read Full Article
Information Security Buzz: Expert On News: Hackers Appear To Begin Selling Data They Stole From Shirbit Insurance Firm
teiss: Personal information of 243m Brazilians could be accessed by anyone