GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Nov-2024 02:54:40 JST Kevin Beaumont Kevin Beaumont

    9 days since Blue Yonder SaaS ransomware incident began, 6 days since the last comms saying no ETA to recovery.

    In conversation about 6 months ago from cyberplace.social permalink

    Attachments


    1. https://cyberplace.social/system/media_attachments/files/113/567/521/926/721/020/original/ab3d7b897af2ee1c.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 02-Dec-2024 21:15:28 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Blueyonder just gave their first update in 8 days, saying “several” impacted customers are back online.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/583/175/025/814/241/original/9485432bca801d90.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 05-Dec-2024 23:35:37 JST Kevin Beaumont Kevin Beaumont
      in reply to

      It's now two weeks to the day since SaaS provider Blue Yonder got hit with ransomware. Their customer update page, which is not indexed on Google, has not been updated for 5 days.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/600/711/975/366/805/original/acc0662cbdec4e00.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 06-Dec-2024 21:18:34 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Termite ransomware group just claimed Blue Yonder. "Our team got 680gb of data such as DB dumps Email lists for future attacks (over 16000) Documents (over 200000) Reports Insurance documents. Check for updates. Data links will be available soon."

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/605/833/024/452/004/original/f47349bb8942cc0e.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 06-Dec-2024 21:28:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody is wondering, Termite ransomware = operators from another two prior groups, the brand launched last month. They use a variant of Babuk to encrypt ESXi via vCenter. #threatintel #ransomware

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Sunday, 08-Dec-2024 03:37:57 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Blue Yonder’s legal team would like you to know nothing #threatintel #ransomware

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/612/990/557/105/662/original/d06722bb80e8ec3a.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 13-Dec-2024 09:03:18 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Blue Yonder update, they say a significant majority of customers have service restored after 23 days, and they’re working with the rest. #threatintel #ransomware

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/642/581/415/131/113/original/df1f22fee7d50925.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 16-Dec-2024 01:44:14 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Termite ransomware group appear to have quietly published some Blue Yonder content, on 13th December.

      #threatintel #ransomware

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/657/840/163/622/988/original/82b35cb45c1d73a8.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 18-Dec-2024 04:05:59 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Termite's ransomware groups download site has mysteriously been offline for several days.

      #threatintel #ransomware

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 24-Dec-2024 01:55:41 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The Termite download site is back up. In terms of Blue Yonder, there's 220k files for download across about 700gb of data.

      #threatintel #ransomware

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 03-Jan-2025 02:04:52 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I think kudos to Blue Yonder, they clearly haven't paid the Termite ransomware group extortion attempt as the data is still sat there.

      My view in these things is don't pay as aside from the obvious, the data will disappear anyway -- ransomware groups can't afford to keep it online for long. Also, it gives you the option of downloading a free backup of your own data.

      Their last update is December 12th.

      In conversation about 5 months ago permalink

      Attachments



      1. https://cyberplace.social/system/media_attachments/files/113/759/840/913/667/473/original/37d204f717c9f006.png

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.