https://krebsonsecurity.com/2022/08/final-thoughts-on-ubiqui...
He initially refused to retract the initial posts he had made..
He made a later post that said the hacker was a former employee being indicted and that he (the hacker) had contacted the media and leaked fake info about the hack.
Problem is that Brian never made it clear that the hacker was his own source for all the previous posts.
How many future potential sources are going to go to him or avoid him now?
The moment he was aware his source likely provided him with incorrect information he should had, at minimum, retracted his previous posts..
He did not necessarily had to share who the source was, but he could inform that new information came to light that made so he could not trust the information he based his posts on so he was retracting it..
Exactly how he had to do when he settled..
The hacker was also the employee assigned to investigate the hack internally..
And here is were Brian comes in, this same person, the hacker\internal investigator, was also Brian source about the event and he was feeding bad information to Brian to make things look way worst for Ubiquiti then they really were..
When this came to light Brian did not immediately retracted the posts, he just made a new post indicating that the hacker was a former employee, that the hacker was being indicted for the it, and that the hacker had contacted the media and leaked fake info about the hack.
But he never made it clear that the hacker was also his own source for all the earlier posts that likely contained wrong information.
So Ubiquiti sued him, they settled out of court, Brian retracted all posts on the hack and issued an apology to Ubiquiti.
https://krebsonsecurity.com/2022/08/final-thoughts-on-ubiqui...
That said, he brought receipts on this one, so I think he’s learned from this adventure.