6 ms·
With "cloud" services being mentioned, they say hackers used cloud storage to evade detection, but what if the initial intrusion vector itself was planted by an
by baybal2 3y ago
With "cloud" services being mentioned, they say hackers used cloud storage to evade detection, but what if the initial intrusion vector itself was planted by an AWS employee?
Saudis used their nationals inside Twitter quite brazenly. Imagine how many other rouge nation nationals are there being used by their governments.
- Jerrrry 3y agoAWS infrastructure is complaint, Twitter isn't. Apples to orangutans.
- MakeThemMoney 3y agoCompliant with what?
- hulitu 3y agoWith CIA requirements. /s
- tsujamin 3y agothat seems like a wildly overcomplicated method of hacking a commercial organisation...
- slt2021 3y agothese 3rd world authoritarian regimes try to do this all the time, for example Russia routinely tries to recruit russian-speaking engineers at US/EU companies for industrial espionage. for example [1] there are more cases that nobody publishes about - a lot of "ransomware" incidents - are actually employee who suddenly received email with malicious URL and clicked on it infecting his work computer - gaining plausable deniability by being "dumb IT user" while collecting $$$$ from criminal org for granting them initial access. a lot of smaller/obscure outsource IT companies can cause you ransomware incident if you decide to terminate software development contract with them, because these could be literally North Korean hackers working as your sysadmins [2]. 1. https://cpomagazine.com/cyber-security/hacker-offered-russian-speaking-tesla-employee-for-1-million-to-execute-ransomware-attack/ https://cpomagazine.com/cyber-security/hacker-offered-russia... 2. https://apnews.com/article/north-korea-weapons-program-it-workers-f3df7c120522b0581db5c0b9682ebc9b https://apnews.com/article/north-korea-weapons-program-it-wo...