Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
cisa.gov
cisa.gov
You don't need money, don't take fame
Don't need no credit card to ride this train
Weird pedants want to insist that the only proper use of the term is for states in the international law sense whuch are coextensive with nations in the sociological sense, which was somewhat normalized as an ideal, particularly in Europe, compared to the status quo ante by the Westphalian system, which both sonewhat aligned states with nations and resulted in states where working to reshape national identity around their own citizenry. But this sense is a pure unrealized ideal: there is essentially nothing which is actually a nation-state in this sense, though its a common aspirations, with nations without states seeking to form states and states without nations seeking to build national identities, and nations that roughly correspond to states, or vice versa, trying to round out the edges (sometimes via building more inclusive national identities, sometimes via ethnic cleansing) — but its only ever at best aoproximate and always in flux.
If you mean a “major regional power”-level actor, or a “global superpower”-level actor, then say that, but a category that includes both the United States of America and Tuvalu isn't communicating a coherent capability level in any domain.
I disagree.
Google can probably outspend the Israeli government, but the Israeli government has capabilities Google will never acquire because Google's control over its employees is limited (mainly to contract law). Google cannot sentence an employee to decades in prison for betraying Google's secrets.
So for example, it turns out that 1 or 2 of the employees of the Manhattan Project betrayed the project by giving nuclear secrets to the Soviet Union, but at least the US government had a realistic chance of keeping secrets there whereas a private corporation embarking on a project of similar scale (i.e., a similar number of employees with similar levels of knowledge and skill) has no realistic hope of doing so.
I think this argument is relevant to computer security because having an exploit is almost completely useless if the entity you hope to use the exploit against knows you have the exploit.
I mean, maybe you meant illegal, in the sense that they are not always in clear legal status (e.g, NSA doing illegal things), but I think for the reader "legal criminal organizations" makes more sense to the point.
Another way to write it maybe would be "sanctioned criminal organizations" but that would be confusing with the secondary meaning of sanctioned. Oh language :(
CVE-2022-47966 is a Zoho vulnerability, while the other is a fortigate one, both are RCEs Both have had public PoCs published at least early this year, there's a bunch more of publicly known RCEs that are still unpatched and used by some tens of thousands of machines, according to Shodan
0.0.0[.]0 instead of 0.0.0.0
FAANG is located in USA. /s