使用Player FM应用程序离线!
Feds Let Fancy Bear Embers Die Out | Gestalt IT Rundown: February 21, 2024
Manage episode 402221957 series 2134755
The US Department of Justice is at it again with a new team for Operation Dying Ember. Sounds spooky, right? This time it was to undertake a secret court order to remove malware from Ubiquiti devices infected by Fancy Bear. The devices in question had default administration passwords as well as remote admin access on the public Internet. The DOJ reinfected the routers with the original malware used to compromise them in the first place and then used that compromise to remove remote access and clean up the secondary payload that had been installed to turn them into a potential botnet. The DOJ said it would then notify users to do a factory reset and install the latest firmware as well as changing their admin password. There's a lot to unpack here! This and more on the Gestalt IT Rundown hosted by Tom Hollingsworth and guest Max Mortillaro.
Hosts:
Tom Hollingsworth: https://www.linkedin.com/in/networkingnerd/
Max Mortillaro: https://www.linkedin.com/in/maxmortillaro/
Follow Gestalt IT
Website: https://www.GestaltIT.com/
Twitter: https://www.twitter.com/GestaltIT
LinkedIn: https://www.linkedin.com/company/Gestalt-IT
Tags: #Rundown, #Security, #AI, #DataCenters, #GenAI, #Data, @NGINX, @LockbitTeam, @GestaltIT, @NetworkingNerd, @MaxMortillaro
314集单集
Manage episode 402221957 series 2134755
The US Department of Justice is at it again with a new team for Operation Dying Ember. Sounds spooky, right? This time it was to undertake a secret court order to remove malware from Ubiquiti devices infected by Fancy Bear. The devices in question had default administration passwords as well as remote admin access on the public Internet. The DOJ reinfected the routers with the original malware used to compromise them in the first place and then used that compromise to remove remote access and clean up the secondary payload that had been installed to turn them into a potential botnet. The DOJ said it would then notify users to do a factory reset and install the latest firmware as well as changing their admin password. There's a lot to unpack here! This and more on the Gestalt IT Rundown hosted by Tom Hollingsworth and guest Max Mortillaro.
Hosts:
Tom Hollingsworth: https://www.linkedin.com/in/networkingnerd/
Max Mortillaro: https://www.linkedin.com/in/maxmortillaro/
Follow Gestalt IT
Website: https://www.GestaltIT.com/
Twitter: https://www.twitter.com/GestaltIT
LinkedIn: https://www.linkedin.com/company/Gestalt-IT
Tags: #Rundown, #Security, #AI, #DataCenters, #GenAI, #Data, @NGINX, @LockbitTeam, @GestaltIT, @NetworkingNerd, @MaxMortillaro
314集单集
Semua episod
×欢迎使用Player FM
Player FM正在网上搜索高质量的播客,以便您现在享受。它是最好的播客应用程序,适用于安卓、iPhone和网络。注册以跨设备同步订阅。