I don’t think people appreciate how effectively Darkside has been ramping up operations mostly under the radar for the last year. This was a very big “oops”. They were doing a really good job of decimating businesses, including infrastructure - and everyone has been really quiet.
A lot of firms are going to be out there shilling magic boxes to fix “everything” in the coming weeks, but while the malware and anti-forensics in these cases are often quite sophisticated, we see the same lack of security hygiene and basic defense in depth exploited repeatedly.
Like, lack of basic monitoring or logging capability. No MFA where it counts. Forgetting to check system exposure with assessments or at least Shodan. No IR plan or retainer.
People don’t talk about being ransomed for the same reasons they don’t talk about being the victims of other crimes: they don’t want to look weak or irresponsible, they don’t want to be held liable, they’re ashamed, they’re afraid to lose friends or customers, they want to forget
But it’s happening like, all the time - IR firms can’t hire analysts fast enough. That also means there are a lot of predatory and unqualified IR firms at the top of Google searches right now.
If I could humbly suggest you to do something, it’s assume that your personal PCs, corporate IT, and corporate OT will be ransomed, and be prepared for that inevitability with something better than an insurance policy, which is wildly inadequate. Then do the basics as deterrence.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Lesley Carhart

Lesley Carhart Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @hacks4pancakes

11 May
One of the most talented young martial artists I’ve ever worked with burnt out and suddenly quit after a decade today. I’m reeling.

I don’t know if any teens at all read my account at all but like... if there are a bunch of adults really invested in mentoring you it’s... (1/x)
... totally okay to say you’re like, overwhelmed, need a break, you need to switch learning styles or speed, or just that you need more support.

Please don’t just give up and vanish because you don’t think you can meet our expectations, or because you think you messed up.
This goes for like your hobbies, infosec, hacking, whatever. Like, people who mentor can be self-centered jerks, but most of us really just want you to succeed - even if your measure of success changes over time! We are emotionally invested in you.
Read 4 tweets
5 May
Oh: “we don’t call threat hunting ‘threat hunting’ here when we do it, though”

I don’t care
You still have to do it if you want to catch stuff your automated detection misses
Your people had better know what to search for in reality when they need any education or references
WTF
Stop making ridiculous job titles and renaming common Cybersecurity terms just because it internal politics? All it hurts is your current and future analysts?
Every Cybersecurity monitoring organization today with any bandwidth available after detection automation and response not *performed by a hamster* should be doing the proactive task which is, in fact, called threat hunting.
Read 4 tweets
26 Apr
Today in, “wow, we’re failing as a profession”, a 60-reply-long joke thread on my neighborhood forum in 2021 about how ‘obviously everyone has to reuse passwords because they’re just too hard to remember as one gets older’.
Actually biting my fingers to not be “that nerd” on a funny ha ha joke.

Until the AOL-using retired gardeners in my town feel comfy using password managers and/or FIDO keys, we’re still lacking in usability and awareness.
Meanwhile we’re like, “just use a password manager, except you have to open it separately on iPhone if you use that plus a PC, and you can use a FIDO key on some sites, but don’t lose it, and you need a different authenticator app for home and work, but don’t use SMS.”
Read 5 tweets
22 Apr
Asexual Enby story time because you keep asking for more representation:
“Is this a fad?”
I can only speak for myself, but as an adolescent I was so skeeved by turning into an adult, sexualized woman that I quit every single school activity that started making me dress like one.
Like, I literally gave up music and art because at 10-12 they started requiring nylons and heels for uniforms and I was so not cool seeing myself.

When I was 15 I had a girl BFF for the first time. She would go have sex with her boyfriend at someone’s basement. I never snitched.
She “hooked me up” with his buddy as a ‘boyfriend’, but we just played MUDs on the computer while we were waiting and I was honestly very confused by everything that was happening.
Read 5 tweets
21 Apr
If you accuse people who give a crap about others who don't look, date, or pray like them of "virtue signaling", maybe you don't know enough people, and maybe you have been too sheltered from people who are suffering. Ultimately, it will impact you as a security professional.
I'll never forget the black, woman, veteran employee I watched break into tears because she had been pulled over by the police on her way to work during Chicago protests, held, and aggressively accused of being a rioter. She had ID reflecting all of this and was dressed for work.
There are whole neighborhoods here that are incredibly difficult to escape, and the police automatically make assumptions about anyone living or entering there. Places that have poor access to jobs, good education, support resources, and even decent food.
Read 5 tweets
3 Apr
The great thing about being ~middle age is knowing exactly what you like, which manifests in very amusing ways when you are single and childless. “You know what would be good in the living room? A big Lego Rube Goldberg machine, discount tequila, and a sauna”.
My married friends: “maybe we could do this in the basement”

My parent friends: “I do not understand any of this but it’s cool. Do you have wet wipes?”
I am the very fun eccentric auntie,
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!

:(