Was this reported to the site owners (https://gema.georgia.gov/get-involved/report-cybersecurity-e...) and appropriate government law enforcement agencies (https://www.cisa.gov/report)?
I do see a call to share other incidents to the blog owner.
Was this reported to the site owners (https://gema.georgia.gov/get-involved/report-cybersecurity-e...) and appropriate government law enforcement agencies (https://www.cisa.gov/report)?
I do see a call to share other incidents to the blog owner.
Edit: and I’m not sure standard disclosure even applies. I’m just talking about IOCs, not the actual attack vector (which I do not know)
"Responsible" disclosure is anything but.
Asking because I had multiple bad experiences with responsible disclosure, yet I do not believe full (public presumably) disclosure is the right initial path.
(Full disclosure should be done anonymously to prevent the latter from happening anyway)
Some would say a "responsible" disclosure which allows the danger to continue unabated for a year is a greater danger than a public disclosure, which would lead to the danger being fixed.
Seems reckless to me to not even _try_ responsible disclosure. You don't have to wait a year. But at least give a chance for the problem to be solved before you make it common knowledge.
:)
It's the 90% of the time, when it doesn't work, that's the problem.
Full disclosure might have short-term negatives for _companies_ involved but is best for customers/users as it allows them to evaluate and implement their own mitigations as early as possible. It's the only truly ethically consistent way to operate.