Security: Fireeye hacked - offensive tools and technics stolen

If there are known vulnerabilities, it’s a good - actually longterm the best - idea to fix them, to close the gaps. Unfortunately governments and especially governmental security instances seem to have a different viewpoint regarding that topic. They keep the holes open to use them egoistically themselves.

One of those has been hacked. Their offensive tools have been stolen. That might mean a lot of work before us…

From FireEye

“We are actively investigating in coordination with the Federal Bureau of Investigation and other key partners, including Microsoft.”

There’s the problem, the unspeakable horror than can not be named or tamed.

I was so impressed with Microsoft Mitigations and superb firewall on par with Packet Filter just doesn’t enter into the sentence of any systems security researcher. What does enter there vocabulary is “What was it?” when they hear the reply “Windows” they shrug and say what did you expect when you take a Browser with NSA keys called Internet Explorer and turn it into your filing systems file manager?

The topic was in the right category for its subject but the last posts are taking things to "Round Table" direction…


This post was flagged as off-topic

So please, when you write, try to be understandable to others. Next time someone says you're off topic and the post will be this incomprehensible I'll just agree with them and hide it.


FireEye now reveals some more details on the actual techniques - which is claimed to be SolarWinds supply chain being compromised/infiltrated and as result trjoan/backdoor planted into official software update (which was digitally signed).

