Tons of great Sophos research is dropping today which I’ll link in thread. China goes brrr.
I want to give them particular credit for directly talking about the cyber industry elephants in the room, both in the research and during media interviews
e.g. insecurity in appliances, need for industry change, monitoring threat actors through telemetry etc etc.
It’s really refreshing as they’re talking about what is *actually happening* - not all vendors do this.
wired.com/story/sophos-chengdu…
reshared this
Kevin Beaumont
in reply to Kevin Beaumont • • •First one news.sophos.com/en-us/2024/10/…
“Pacific Rim timeline: Information for defenders from a braid of interlocking attack campaigns”
Threat actor calls themselves Tstark (lol) and has an SSH backdoor called libgoat
Pacific Rim timeline: Information for defenders from a braid of interlocking attack campaigns
Sophos NewsKevin Beaumont
in reply to Kevin Beaumont • • •Next up news.sophos.com/en-us/2024/10/…
“Pacific Rim: Inside the Counter-Offensive—The TTPs Used to Neutralize China-Based Threats”
Lots in there again but big one for me - the threat actor started blocking on appliance telemetry and breaking update process. They also developed patch bypasses.
Pacific Rim: Inside the Counter-Offensive—The TTPs Used to Neutralize China-Based Threats
Sophos NewsKevin Beaumont
in reply to Kevin Beaumont • • •Another news.sophos.com/en-us/2024/10/…
“Digital Detritus: The engine of Pacific Rim and a call to the industry for action”
Contains lots of bangers from a wider theme.
Digital Detritus: The engine of Pacific Rim and a call to the industry for action
Sophos NewsKevin Beaumont
in reply to Kevin Beaumont • • •I’ve worked for two telcos now and one thing I’ll say - China goes brrrr…. a LOT.
If you sell security products to countries of interest to China - eg large populations of Uyghurs, Tibetan nationals etc - you should not be running apache as root on appliances, you should be monitoring telemetry, and your customers (and their customers) are in danger from highly determined threat actors.
The security industry needs to mature and to do that it needs to talk about it and make better products.
Dave "Wear A Goddamn Mask" Cochran reshared this.
Dragon
in reply to Kevin Beaumont • • •unicornCoder ☑️ :gnome: :bash:
in reply to Kevin Beaumont • • •silverwizard
Unknown parent • •daveyk00
in reply to silverwizard • • •silverwizard likes this.
lit
Unknown parent • • •