Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Tuesday, March 23rd, 2021

    Time Event
    2:33p
    Accellion Supply Chain Hack

    A vulnerability in the Accellion file-transfer program is being used by criminal groups to hack networks worldwide.

    There’s much in the article about when Accellion knew about the vulnerability, when it alerted its customers, and when it patched its software.

    The governor of New Zealand’s central bank, Adrian Orr, says Accellion failed to warn it after first learning in mid-December that the nearly 20-year-old FTA application — using antiquated technology and set for retirement — had been breached.

    Despite having a patch available on Dec. 20, Accellion did not notify the bank in time to prevent its appliance from being breached five days later, the bank said.

    CISA alert.

    << Previous Day 2021/03/23
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org