bolha.us is one of the many independent Mastodon servers you can use to participate in the fediverse.
We're a Brazilian IT Community. We love IT/DevOps/Cloud, but we also love to talk about life, the universe, and more. | Nós somos uma comunidade de TI Brasileira, gostamos de Dev/DevOps/Cloud e mais!

Server stats:

252
active users

#notepad

1 post1 participant0 posts today
Replied in thread

@AmbianceAsunder I mean, given the listed sample of a state-sponsored attack, we can assume the attackers have some basic project management skills and being able to collect both #OSINT and mobilize local assets to collect #SIGINT on street level.

After all, they most likely only realized that #WiFi-connected / authenticated devices are exempted by having collected #INTEL on the targeted org's employees and their workflows.

  • Making me conclude they had access to employer handbooks and IT documentation via a unclassified employee. But they couldn't risk have said #insider / #UC blow their cover by i.e. smuggling in an unathorized #device or sth.

It would however make sense to have someone inside as a #canary even if they ain't in #IT nor have any privilegues…

  • After all, depending on the organizational size it's a statistical inevitability to have privileged access...

youtube.com/watch?v=T4w6rloFpC