• Contact Us
  • Login
Upgrade
Tech News Hero
Advertisement
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
Tech News Hero
No Result
View All Result
Home Security

Russia’s FireEye Hack Is a Statement—but Not a Catastrophe

by technewshero
December 13, 2020
in Security
0
Russia’s FireEye Hack Is a Statement—but Not a Catastrophe
Share on FacebookShare on Twitter

FireEye has built its reputation on defending high-stakes clients from hackers. Today, the cybersecurity firm acknowledged that it had itself been the victim of a breach—and that the attackers made off with some of its offensive tools. It’s a startling admission but almost certainly not as devastating as it may first sound.

Like many cybersecurity companies, FireEye uses its “red team” tools to mimic those used in real attacks and look for vulnerabilities in its customers’ digital systems the way real adversaries would. The firm is able to update and refine its methods because it encounters and studies real nation-state and criminal hacking tools while assisting customers with incident response. But that’s still a far cry from investing to develop a novel offensive arsenal—and not nearly as scary as the tools at the disposal of, say, the National Security Agency.

FireEye CEO Kevin Mandia said in a blog post today that the company has been dealing with the fallout of “an attack by a nation with top-tier offensive capabilities” and has engaged the help of the Federal Bureau of Investigation along with industry peers like Microsoft. The Washington Post reported on Tuesday that hackers from a group known as APT 29 or Cozy Bear, attributed to Russia’s SVR foreign intelligence service, carried out the breach.

FireEye has both global prominence and a history of engaging with Russian actors. The company was the first, for instance, to tie the hacker group known as Sandworm—responsible for blackouts in Ukraine in 2015 and 2016 as well as the hyperdestructive worm NotPetya the following year—to Unit 74455 of Russia’s GRU military intelligence agency. FireEye also provided the first public evidence that the same GRU unit was responsible for the attempted sabotage of the 2018 Winter Olympics. All of those attacks were later named in a US indictment of six Sandworm hackers unsealed in October.

The apparently retaliatory hack sends a clear statement that while Russia may have been relatively quiet during the US presidential election, the Kremlin’s digital prowess remains formidable. At the same time, the fallout from the hack doesn’t compare to the release of tools like the NSA’s Eternal Blue tool, which a mysterious group called the Shadow Brokers leaked in 2017, or the breach of exploit broker Hacking Team in 2015.

“The most important data that a company like FireEye has is data about its customers. The second most important data they have are the sources and methods they use to protect their customers,” like threat intelligence data, says Richard Bejtlich, former chief security officer of Mandiant, the incident response division of FireEye, and principal security strategist at the network analysis firm Corelight. “Farther down the line are the red team tools, where they’re emulating adversaries.”

FireEye said on Tuesday that none of the stolen red team tools utilize so-called zero-day exploits—mechanisms that weaponize secret, unpatched software vulnerabilities, which makes them especially dangerous. Nonetheless, Russia could use the tools itself, share them with others, or leak them publicly. The company said it does not yet fully understand the hackers’ plans or motives, though they primarily focused their attack on information related to some of FireEye’s government clients.

Mandia emphasized repeatedly that FireEye is offering more than 300 “countermeasures” meant to make it more difficult for Russia to use the stolen hacking tools effectively. The company has incorporated these digital antidotes, essentially detection mechanisms and blocking tools, into its own security products, has shared them with other firms, and has released them publicly.

Previous Post

Cyberpunk 2077 draws criticism for seizure-inducing sequence with no warning or mitigation – TechNewHero

Next Post

Amazon, Facebook, Google Faces PIL Over Fintech Regulation in India

technewshero

technewshero

Related Posts

2020 Shows the Danger of a Decapitated Cyber Regime
Security

2020 Shows the Danger of a Decapitated Cyber Regime

by technewshero
January 13, 2021
A ‘Bulletproof’ Criminal VPN Was Taken Down in a Global Sting
Security

A ‘Bulletproof’ Criminal VPN Was Taken Down in a Global Sting

by technewshero
January 14, 2021
The Worst Hacks of 2020, a Surreal Pandemic Year
Security

The Worst Hacks of 2020, a Surreal Pandemic Year

by technewshero
January 15, 2021
Security

How Your Digital Trails Wind Up in the Police’s Hands

by technewshero
December 31, 2020
How to Understand the Russia Hack Fallout
Security

How to Understand the Russia Hack Fallout

by technewshero
December 22, 2020
Next Post
Amazon, Facebook, Google Faces PIL Over Fintech Regulation in India

Amazon, Facebook, Google Faces PIL Over Fintech Regulation in India

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Most Popular

Asobu Frosty Beer 2 Go Vacuum Insulated Beer Cooler » Gadget Flow

June 24, 2019
Mmhmm App for Virtual Meetings, Launched by Former Evernote CEO, Now Generally Available

Mmhmm App for Virtual Meetings, Launched by Former Evernote CEO, Now Generally Available

December 13, 2020

Cybersecurity: How a layered approach keeps this F1 team’s data secure

May 21, 2019

Browse by Category

  • Apps
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • News
  • PC & Laptops
  • Security
  • Social
Tech News Hero

© 2020 Tech News Hero.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© 2020 Tech News Hero.

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?