Telent have suffered a security breach of their managed internet and cyber unit, leading to misuse of the captive portal across UK train stations, NHS hospitals etc.
They’ve contained their network for now. Thread to track situation.
Telent have suffered a security breach of their managed internet and cyber unit, leading to misuse of the captive portal across UK train stations, NHS hospitals etc.
They’ve contained their network for now. Thread to track situation.
Pulled reference to network being contained as, well, it super isn’t.
They have everything from Outlook Web App facing the internet to a Cisco AnyConnect box without MFA to Juniper management interfaces to documentation servers etc.
The Telent incident is a simple web page defacement. The portal was internet facing on an Amazon EC2 box, which got owned.
It was changed to far right propaganda.
Here’s the Telent portal hack. The web page was public, along with the web server - it was a simple defacement. https://urlscan.io/result/fa1363df-f64b-474c-8223-21ecf310b4b5/
@GossiTheDog
Who's still using Telent when OpenSHS is free?
@GossiTheDog
Sorry, just making a joke at the expense of Telent because it sounds like Telnet. I shouldn't post while undercaffeinated.
Telent have issued a statement saying somebody changed the captive portal page (just a website) using a legitimate administrator account, and police are investigating. I’m going to guess staff or former staff member.
How the media in the UK have been covering this, fuelled by cyber vendor outreach to media.
For the record it never impacted departure boards.
Here’s one of the press pitches somebody tried sending me: "UK train stations hit by 'Nightsleeper' cyber attack as chilling terror threat issued"
HT @gcluley
The train station WiFi captive portal defacement incident has lead to the arrest of somebody who works at the provider of the service. https://news.stv.tv/scotland/man-arrested-after-wifi-at-scotlands-busiest-train-stations-displays-islamophobic-messages
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.