Who was behind Shadow Brokers?
The answer isn't publicly known.
Who was behind Shadow Brokers?
The answer isn't publicly known.
๐ ๐ง๐ผ๐ฑ๐ฎ๐ ๐ถ๐ป ๐๐๐ฏ๐ฒ๐ฟ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ถ๐๐๐ผ๐ฟ๐ | ๐๐ฎ๐ป๐๐ฎ๐ฟ๐ ๐ญ๐ณ, ๐ฎ๐ฌ๐ญ๐ต
Seven years ago today, Troy Hunt ( @troyhunt ) disclosed Collection #1, one of the largest known aggregations of breached credentials at the time.
๐ See Troy's original write-up on this finding: https://www.troyhunt.com/the-773-million-record-collection-1-data-reach/
Collection #1 showed how old breaches become new threats at scale when data is reused, automated, and repackaged. For deeper context on why this happens, we recommend two #CyberCanonHoF books published years before this incident.
๐๐ฅ๐๐ข ๐๐๐ฉ๐๐ค๐ฃ - the economics of stolen data ( @briankrebs )
๐ Review: https://cybercanon.org/spam-nation/
๐๏ธ Amazon affiliate link: https://amzn.to/4o0m5wz
๐๐๐ฃ๐๐ฅ๐๐ฃ - how cybercrime gets monetized ( @Kpoulsen )
๐ Review: https://cybercanon.org/kingpin-how-a-hacker-took-over-the-billion-dollar-cybercrime-underground/
๐๏ธ Amazon affiliate link: https://amzn.to/4nWQCv4
โก ๐ง๐ผ๐ฑ๐ฎ๐ ๐ถ๐ป ๐๐๐ฏ๐ฒ๐ฟ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ถ๐๐๐ผ๐ฟ๐ โ ๐๐ฒ๐ฐ๐ฒ๐บ๐ฏ๐ฒ๐ฟ ๐ฎ๐ฏ, ๐ฎ๐ฌ๐ญ๐ฑ
On a cold December evening in Ukraine, the lights began to go out.
Not because of a storm or a fallen transmission line. But because an unseen adversary, who was patient, disciplined, and already deep inside Ukraineโs networks, made its move.
Inside three regional power companies, operators watched helplessly as their mouse cursors began to move on their own. Breakers opened. Substations went dark. And within minutes, 230,000 people were without power.
It was the worldโs first confirmed blackout caused by a cyberattack.
In Sandworm, Andy Greenberg follows the trail back to the group behind it. An elusive GRU team whose operations would ripple across the globe. What makes this moment unforgettable isn't just the technical achievement of penetrating industrial control systemsโฆ
Itโs that December 23rd proved a new reality: code could now disrupt cities, societies, and the physical world itself.
Greenbergโs investigative storytelling captures the tension, the human impact, and the geopolitical stakes behind an attack that forever changed how we think about cyberwar.
๐ Cybersecurity Canon Hall of Fame winner,
๐๐๐ฃ๐๐ฌ๐ค๐ง๐ข: ๐ผ ๐๐๐ฌ ๐๐ง๐ ๐ค๐ ๐พ๐ฎ๐๐๐ง๐ฌ๐๐ง ๐๐ฃ๐ ๐ฉ๐๐ ๐๐ช๐ฃ๐ฉ ๐๐ค๐ง ๐ฉ๐๐ ๐๐ง๐๐ข๐ก๐๐ฃโ๐จ ๐๐ค๐จ๐ฉ ๐ฟ๐๐ฃ๐๐๐ง๐ค๐ช๐จ ๐๐๐๐ ๐๐ง๐จ:
https://cybercanon.org/sandworm-a-new-era-of-cyberwar-and-the-hunt-for-the-kremlins-most-dangerous-hackers/
๐๏ธ https://amzn.to/3JKUKAl
#CybersecurityBooks #CybersecurityHistory #CyberWar #OTSecurity (re-added picโฆ)
๐ฏ๐ง๐ผ๐ฑ๐ฎ๐ ๐ถ๐ป ๐๐๐ฏ๐ฒ๐ฟ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ถ๐๐๐ผ๐ฟ๐: ๐ง๐ต๐ฒ ๐ง๐ฎ๐ฟ๐ด๐ฒ๐ ๐๐ฎ๐๐ฎ ๐๐ฟ๐ฒ๐ฎ๐ฐ๐ต, ๐๐ฒ๐ฐ๐ฒ๐บ๐ฏ๐ฒ๐ฟ ๐ญ๐ต, ๐ฎ๐ฌ๐ญ๐ฏ
It started quietly, days before the holiday rush. Shoppers were filling stores, credit cards were swiping nonstop, and behind the scenes, a small foothold inside Targetโs network was about to become one of the most infamous breaches in retail history.
๐ Attackers slipped in through a third-party HVAC vendor
๐ชฒ Malware moved silently across point-of-sale systems
๐ณ 40 million payment cards skimmed
๐ 70 million customers' data exposed
While many are (sadly) becoming numb to breach news nowadays, this disclosure, announced 12 years ago today, shook the industry. Boardrooms across the globe were confronted with the fact that cybersecurity wasnโt just an IT problem, but a critical business-wide issue.
The incident is covered very nicely in this Huntress article: https://www.huntress.com/threat-library/data-breach/target-data-breach
Many books in the #CyberCanon address themes related to the breach. Here are two recos to get you started:
๐๐๐ซ๐๐๐๐ฉ๐๐ฃ๐ ๐ฉ๐๐ ๐ฟ๐๐๐๐ฉ๐๐ก ๐ผ๐๐ discusses cyber risk at the board/executive level and uses high-profile cases to illustrate governance, risk oversight, and leadership implications. Our review๐: https://cybercanon.org/navigating-the-digital-age-the-definitive-cybersecurity-guide-for-directors-and-officers/
๐๐๐ ๐พ๐๐๐ ๐๐ก๐๐ฎ๐๐ค๐ค๐ is your go-to for structured guidance on integrating 3rd party risk into enterprise security strategy. Our review๐: https://cybercanon.org/the-ciso-playbook/
On November 24, 2014, Sony Pictures Entertainment experienced a landmark cyber-attack. A hacker group calling itself the โGuardians of Peaceโ unleashed destructive malware, wiped large portions of the studioโs network, and dumped terabytes of sensitive internal data.
๐พ๐ฎ๐๐๐ง ๐๐๐ง๐จ: ๐๐๐๐ ๐จ ๐๐๐๐ฉ ๐๐๐ค๐๐ ๐๐ ๐ฉ๐๐ ๐๐ค๐ง๐ก๐, by Charles Arthur, covers this pivotal event amongst other cyber attacks.
See our review ๐ https://cybercanon.org/cyber-wars-hacks-that-shocked-the-world
#CybersecurityHistory #SonyHack #CyberWar #CybersecurityBooks
๐ ๐ง๐ผ๐ฑ๐ฎ๐ ๐ถ๐ป ๐๐๐ฏ๐ฒ๐ฟ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ถ๐๐๐ผ๐ฟ๐!
On November 2, 1988, the Morris Worm became the first major computer virus to spread across the Internet. What began as a graduate studentโs โexperimentโ quickly spiraled out of control, taking down much of the early Internet and costing millions in cleanup. It also gave rise to one of cybersecurityโs most important realizations: even well-intentioned code can cause catastrophic damage in a connected world.
To learn more, ๐๐๐ฃ๐๐ฎ ๐ฝ๐๐๐ง ๐๐ค๐๐จ ๐๐๐๐จ๐๐๐ฃ๐ by Scott Shapiro, a #CyberCanonHoFCandidate, covers the #MorrisWorm as one of its five infamous hacks. See our review โก๏ธ https://tinyurl.com/r2b3zc2u
๐ฅAnd as a bonus, many may not be aware that ๐๐๐ ๐พ๐ช๐๐ ๐ค๐ค'๐จ ๐๐๐ also contains an interesting perspective on the Morris Worm. A year after astronomer Cliff Stoll's spy tracking journey, he was one of many admins around the country who were investigating the Morris Worm live as it was spreading through the night. Cliff writes about this experience in the book's epilogue, where he discovers that the author of the worm was actually the son of NSA's Chief Scientist, Robert Morris, whom Cliff worked with in relation to his international hacker sleuthing a year earlier.
#CyberCanonHoF review โก๏ธ https://tinyurl.com/3rywf7zw
Did you know?
The first computer worm, 'Creeper', appeared in 1971. It moved across ARPANET, leaving a message in it's wake. Cybersecurity was born from this experiment.