thewayne: (Default)
[personal profile] thewayne
Citrix is a major player in the computer networking equipment market. And they had a major, sorry, MAJOR software flaw back in October that was exploited bigly. They patched it and announced the patch as fast as they could, and their customers patched as fast as they could.

Which brings us to Xfinity.

From the article: "Citrix disclosed the vulnerability and issued a patch on October 10. Eight days later, researchers reported that the vulnerability, tracked as CVE-2023-4966 and by the name Citrix Bleed, had been under active exploitation since August. Comcast didn’t patch its network until October 23, 13 days after a patch became available and five days after the report of the in-the-wild attacks exploiting it."

Ruh-roh!

Two weeks is far too long for a vulnerability that big to go unpatched. Care to guess what happened? Oh, I forgot. It was in this post's subject line.

To continue the article: "“However, we subsequently discovered that prior to mitigation, between October 16 and October 19, 2023, there was unauthorized access to some of our internal systems that we concluded was a result of this vulnerability,” an accompanying notice stated. “We notified federal law enforcement and conducted an investigation into the nature and scope of the incident. On November 16, 2023, it was determined that information was likely acquired.”

Comcast is still investigating precisely what data the attackers obtained. So far, Monday’s disclosure said, information known to have been taken includes usernames and hashed passwords, names, contact information, the last four digits of social security numbers, dates of birth, and/or secret questions and answers. Xfinity is Comcast’s cable television and Internet division."


Yeah. Free credit monitoring? Thoughts and prayers? There needs to be some executive job loss and demotions. But as this is Comcast, nothing will change.

Completely inexcusable.

Back in the '90s, when the I Love You email virus hit, I learned about it at about 7:15 or so in the morning. We literally unplugged our firewall from the internet as there was no patch for it at the moment. And we had no problems. You can't let shit like this go unchecked, or things like this happen.

https://arstechnica.com/security/2023/12/hack-of-unpatched-comcast-servers-results-in-stolen-personal-data-including-passwords/

Date: 2023-12-20 02:51 pm (UTC)
elayna: (Keanu Whoa)
From: [personal profile] elayna
I worked for a state agency in the 90s and the I Love You virus went on for *days,* it was horrible. They got it cleaned up and then apparently someone came back from vacation, it was still in their inbox and they started it going again, it was such a nightmare. I’m impressed you guys knocked it out right away.

Date: 2023-12-20 08:18 pm (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
Oh, that's inexcusable. Company-destroying, fines-to-the-point-of-bankruptcy inexcusable. They won't get hurt that much, because they can buy off whomever they need to, but someone should put an exclamation point on that so that everyone else is frightened into doing the right thing immediately.

Date: 2023-12-20 10:24 pm (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
That is genuinely one of the problems that we have in enforcement of the rules: it's impossible for any creatures of a certain size to be knocked down and destroyed fully, because they have a phylactery in bought regulators and Congresscritters.

Fine them multiple years' profits and see if they are that callous again.

Date: 2023-12-21 06:01 am (UTC)
disneydream06: (Disney Shocked)
From: [personal profile] disneydream06
WOWZA!!!!!!!!!!
Talk about epic failure. :o :o :o
Hugs, jon

Date: 2023-12-22 12:47 am (UTC)
disneydream06: (Disney Angry)
From: [personal profile] disneydream06
It's sad that most companies are heading that way. :(

Date: 2023-12-26 03:33 am (UTC)
kellan_the_tabby: My face, reflected in a round mirror I'm holding up; the rest of the image is the side of my head, hair shorn short. (Default)
From: [personal profile] kellan_the_tabby
ooooookay, when I, with my tiny lil website & weensy lil customer base, with an IT department that consists of me, do a better job of keeping up with this kinda stuff than FUCKING.

COMCAST.

... there's a PROBLEM.

May 2025

S M T W T F S
    1 23
45678910
1112 131415 1617
18 19 20 212223 24
25262728 2930 31

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 5th, 2025 07:21 am
Powered by Dreamwidth Studios