Archive for July 17, 2023

Colorado State Is The Latest To Be Pwned By The MOVEit Vulnerability

Posted in Commentary with tags on July 17, 2023 by itnerd

Last week, Colorado State University informed its students and staff that the Cl0p ransomware operation has gained access to their personal data through the recent MOVEit data-theft attacks on the University’s service vendors, TIAA, National Student Clearinghouse, Corebridge Financial, Genworth Financial, Sunlife, and The Hartford.”

Some data about prospective, current, and former CSU students and current and former employees maintained by the affected vendors contains personally identifiable information, which may include first name, middle initial, last name, date of birth, student or employee identification numbers, social security number, and demographic information such as gender, ethnicity, and level and area of education.” warned CSU.

All of the providers utilized the MOVEit Transfer security file transfer platform and since then, Stony Brook University, the University of Delaware, and the Western University of Health Sciences have posted data breach notices relating to the compromise of TIAA, NSC, and Corebridge Financial.

Stephen Gates, Principal Security SME, Horizon3.ai had this to say:  

“Although most organization have regularly scheduled maintenance windows where they take systems offline, apply the latest patches, perform system updates, and complete any other scheduled maintenance, organizations must be able to make exceptions to their standard operational procedures, especially for times like these.  

“In the case of the recent MOVEit vulnerabilities that threat actors are actively exploiting in the wild, organizations cannot wait for regularly scheduled maintenance windows to patch. If organizations have applied patches, good job! If they have not already applied patches, they must make an exception and update now. If not, the likelihood of more organizations falling victim is extremely high.”

The fact that new victims are appearing every day makes me wonder I this will never end. And the fact that in this case, it was a supply chain attack highlights the fact that you’re only as strong as your weakest link. And this illustrates that there are a lot of weak links out there.

Elon Musk To World: Twitter Is Bleeding Cash Like A Gunshot Victim

Posted in Commentary with tags on July 17, 2023 by itnerd

I’ve been saying for a while now that Elon Musk’s optimistic Tweets and public statements about Twitter being just fine were likely lies. Now we know the truth. And that Truth comes straight from Elon:

So that pretty much confirms earlier reports that Twitter’s US ad revenue plunged 59% between spring 2022 and spring 2023. And it also confirms that Elon was lying. Not that anyone should be shocked about that. The real question is if he and his CEO Linda Yaccarino can do anything about it? I personally don’t think so as that would require Elon to show some sort of self discipline in a number of areas such as not getting in his own way, keeping his mouth shut for a considerable amount of time. Thus once again, I have to say that Twitter is doomed and it’s all Elon’s fault.

Threads Engagement Drops…. While It’s Confirmed That Threads Won’t Work In The EU At All

Posted in Commentary with tags on July 17, 2023 by itnerd

After an initial launch, it seems that Meta’s Twitter killer Threads has run into a couple of hiccups. The first is that engagement on Threads has dropped:

By the numbers: Daily active users were down about 20% on Tuesday and Wednesday this week from Saturday, marketing data firm Sensor Tower says.

  • Time spent has fallen from 20 minutes to 10 minutes.
  • Separate data from Similarweb revealed similar patterns — a more than 25% drop in daily active users between July 7 and Monday among Android phone users.

What they’re saying: Twitter competitor Threads “will need a more compelling value proposition than simply ‘Twitter, but without Elon Musk,'”Anthony Bartolacci, managing director at marketing data firm Sensor Tower, tells CNBC.

Interesting, but not a shock. I was privately wondering if people would remain engaged on Threads after getting an account. If they did, Elon and company would have a lot to worry about. But that apparently isn’t the case. So that might give Elon and company some hope. Key word: Some.

Also, if you’re going to the EU and wish to post to Threads, I have bad news for you. Threads isn’t going to work in the EU even if you’ve signed up for a Threads account in the US or any other place that Threads is available:

Recently, EU users began to notice they were suddenly unable to post on the new social media platform. Industry analyst Matt Navarra reached out to Meta to figure out what’s going on. In a statement given to Navarra, the tech giant admitted to taking extended “measures to prevent people [in EU] countries [from] accessing Threads,” which apparently includes blocking the use of VPNs that people often use to bypass online access restrictions.

Currently, the platform remains unavailable to most European nations. There are, of course, exceptions for non-members like the United Kingdom. Meta concludes its statement by saying it hopes to one day “bring Threads to more countries in the future” as Europe is an important market for the company.

That isn’t surprising either. Clearly Meta doesn’t want any trouble from the EU until they can figure out a way to launch Threads there that allows them not to run afoul of any EU laws, while at the same time being able to do Meta things. By that I mean gather up all the data on you that it can so that it make money off it it. It will be interesting to see if Meta course corrects on that front as that’s 100 million users that Meta would like to get their hands on.