MOVEit body count closes in on 400 orgs, 20M+ individuals
theregister.com
theregister.com
Do others agree or am I being hyperbolic?
If you think about it, it was inevitable when incentives became more aligned with quick 'hot takes' and volume over signal/noise ratio.
The darkpattern of our times.
Of course, it's the Register, they try to be clever with every headline.
Did the victims die?
[1] - https://www.theregister.com/Author/Jessica-Lyons-Hardcastle
It would have been much more readable to write "victim count".
Would you say it's "problematic"? :)
Funny and "cringey" titles are a staple of the Register since the beginning.
Every single aspect of a persons confidential info.
Everything from SSN to eye and hair color.
> Progress disclosed a third hole, CVE-2023-35708, on June 15.
> Finally (we hope), three additional vulnerabilities – CVE-2023-36934, CVE-2023-36932, and CVE-2023-36933 – were spotted and fixed on July 5.
It seems like fixes came out the same day or the day after the problems were discovered. Yet an estimated 23% of customers are still vulnerable to the recent CVEs.
It seems to me that there's more going on than just shitty security practices by Progress Software, as reported on by this article. The fixes are out, the problems are known, and the fixes are available.
Because the bug is super trivial to fix, it's also super trivial to do. Not to mention, the human mind is naturally inclined to not care about trivial stuff, which leads to careless mistakes at many levels and thus Bobby Tables dropped out of school.
Tt's very easy to do it incorrectly.
It's at best equal... unless there is some SQL driver/client somewhere that disallows hardcoded strings everywhere (that would actually really help).
Procurement works by ticking off features of a list, possibly comparing prices. Quality and security are hard to quantify, and often cannot really assessed by the purchase managers themselves, so they don't play a major role in purchasing decisions.
Thus, vendors aren't really incentivized to make robust, reliable and secure software, they are incentivized to sell their software.
And the high expense of contractors to customize and migrate, keeps the legacy tech debt around.
But that is also what keeps an entire industry making money, and many legacy mom/pop shops employed for decades.
I love how legislators have upped the ante for (big) businesses to survive, to the point some will appear to perjure themselves in public as the lessor evil. https://gdpr-info.eu/issues/fines-penalties/#:~:text=For%20e....
However, are legislators trying to kill the golden goose, has the money printing exercise called quantitive easing given them an unfounded level of hubris for their central bank purchased national debt?
However, TJX could have written their security policy such that their Moveit server was not allowed to use that feature, so they used a different piece of software to do the encrypt/decrypt outside of Moveit. Thus, hacking the TJX server would only get a bunch of unencrypted reports and encrypted files with personal info in them. Again, I'm not saying this was what actually happened.