My high school getting hacked is now, apparently, national news. @SenSchumer is proposing that DHS publish more guidance on ransomware that few people will read.https://www.newsday.com/long-island/nassau/school-cyberattack-ransom-rockville-centre-1.36741245 …
-
Show this thread
-
Dan Guido Retweeted Dan Guido
Here's an earlier thread from when I first found out they were hacked, and a second where I was doing some background research. The most interesting service I learned about was from
@malwrhunterteam: https://twitter.com/dguido/status/1166760063647780865 … https://twitter.com/dguido/status/1172890325125406720 … https://id-ransomware.malwarehunterteam.com/Dan Guido added,
1 reply 0 retweets 0 likesShow this thread -
Note to
@SenSchumer: guidance on ransomware is in abundant supply from USG already. Here's a few good resources: - DOJ: https://www.justice.gov/criminal-ccips/file/872771/download … - MS-ISAC: https://www.cisecurity.org/white-papers/ms-isac-security-primer-ransomware/ … - NGA: https://www.nga.org/wp-content/uploads/2019/04/IssueBrief_MG.pdf … - US-CERT (note: part of DHS): https://www.us-cert.gov/Ransomware1 reply 0 retweets 5 likesShow this thread -
Meanwhile, two months since getting hacked,
@mineolaufsd is running their own Microsoft Exchange server with misconfigured or absent SPF, DKIM, and DMARC. There's no 2FA on remote login, and I won't guess how they handle attachments or links. https://toolbox.googleapps.com/apps/checkmx/check?domain=mineola.k12.ny.us&dkim_selector= …1 reply 0 retweets 2 likesShow this thread -
I don't think this problem gets meaningfully improved with more guidance or "hunt teams." No one reads it, and it's pretty easy for even a single ransomware team to cause havoc on a large scale.
1 reply 0 retweets 3 likesShow this thread -
I think the problem is that most schools blew their entire IT budget, up front, on insecurable garbage they got sold by VARs without considering how they'd maintain any of it. They can't afford the staff required to securely admin a network as complex as what they currently own.
6 replies 2 retweets 19 likesShow this thread
Unfortunately, I think this means that certain schools will require a bailout. It should come with strings: it's only for cloud migration, and ongoing maintenance and incident response are budgeted appropriately. 
-
-
Replying to @dguido
Public schools should be supported by the government. Private schools should (maybe) have access to loans, but tax payer shouldn’t be subsidizing for-profit corporations. Better yet would be getting rid of the various contractual scams these companies use to avoid liability :-/
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.