GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Taggart :donor: (mttaggart@infosec.town)'s status on Saturday, 09-Mar-2024 18:52:53 JSTTaggart :donor:Taggart :donor:
    in reply to

    To Recap

    The British Library:

    - used unsupported, unpatched software as critical infra
    - used multiple IT vendors with varying levels of access
    - lacked sufficient in-house staff to coordinate a proper security policy
    - lacked resources (or leadership, probably) to appropriately fund an infrastructure refresh program
    - launched remote access during COVID WITHOUT MFA

    And although we cannot say for sure that the Terminal Server was the point of access, it's a good dang bet. Rhysida works smarter, not harder.

    As usual, the reality of defense is not sexy malware research. It's not breathlessly shouting about patching 0-days. It's the quotidian work of getting the basics right, not taking shortcuts, and making security—across the CIA triad—a budget priority.

    In cultural and educational institutions, it is very common to think of IT systems as an afterthought, or ancillary to the primary mission. These institutions maintain this mentality at their own considerable risk. This extends to the governments and organizations who fund these institutions.

    In conversationabout a year ago from infosec.townpermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.