Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

admin
Pinned March 19, 2019

<> Embed

@  Email

Report

Uploaded by user
Iranian hackers stole terabytes of data from software giant Citrix
<> Embed @  Email Report

Iranian hackers stole terabytes of data from software giant Citrix

Jon Fingas, @jonfingas

March 09, 2019
 
 

Iranian hackers stole terabytes of data from software giant Citrix | DeviceDaily.com

 
 

Citrix is best-known for software that runs behind the scenes, but a massive data breach is putting the company front and center. The FBI has warned Citrix that it believes reports of foreign hackers compromising the company’s internal network, swiping business documents in an apparent “password spraying” attack where the intruders guessed weak passwords and then used that early foothold to launch more extensive attacks. While Citrix didn’t shed more light on the incident, researchers at Resecurity provided more detail of what likely happened in a conversation with NBC News.

Resecurity understood that hackers from Iridium, an Iran-linked group, stole data in December 2018 and again on March 4th. They made off with at least 6TB of documents and as much as 10TB, and they seemed to be focused on project data for the aerospace industry, the FBI, NASA and Saudi Arabia’s state-owned oil company. The intruders may have been lurking for a long time, too. Resecurity’s Charles Yoo said that Iridium broke into Citrix’s network roughly 10 years ago and had been hiding since then.

The researchers said they’d told Citrix about the first attack on December 28th. It’s not clear if Citrix addressed the issue then, although it took a number of steps after the FBI got in touch on March 6th. The company said it launched a “forensic investigation” with the help of an unnamed security firm and took “actions” to lock down its network.

Citrix stressed there was “no indication” that the intruders compromised its products or services. However, that’s not the major concern here. As a government contractor that focuses on networking and the cloud, Citrix could hold sensitive data on other companies. It may be aware of their network layouts and security measures, for instance. Like the OPM hack, the consequences could reach well beyond the initial target.

Engadget RSS Feed

(45)