Summary

A Chinese state-sponsored hacker group breached the U.S. Treasury Department by exploiting a vulnerability in the third-party cybersecurity provider BeyondTrust.

The attackers used a stolen key to override security measures, accessing departmental workstations and unclassified documents.

The Treasury Department, alerted on December 8, reported no evidence of ongoing access.

The department is working with the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI to investigate the breach, which highlights risks tied to third-party software vulnerabilities.

  • Justin@lemmy.jlh.name
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    3
    ·
    3 days ago

    Sounds like their contractors have shoddy security practices.

    Also, stop using windows in high security environments!

    • deadbeef79000@lemmy.nz
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      26 minutes ago

      I mean, windows itself can be reasonably secured. All the “security” crapware that CxO’s get sold by shysters become the attack vectors.

  • shalafi@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    5
    ·
    3 days ago

    I guess we never fight back? Maybe sink a fucking ship or 10? Like the ones fucking with our ally, the Philippines?

    All these fuckers do is test and test and test. Results? Nada. We do nothing. They escalate. We do nothing, “condemn” their actions. Same goes for Russia.

    The US has the most powerful military on the planet. What for? Either fold up, draw in, fight defense, or strike back. Diplomatic actions are not working.

    • deadbeef79000@lemmy.nz
      link
      fedilink
      English
      arrow-up
      1
      ·
      24 minutes ago

      Diplomatically recognising Taiwan/RoC would probably be enough, or stationing a carrier group in near by waters to defend it.

      CPC would lose their shit.

    • Hegar@fedia.io
      link
      fedilink
      arrow-up
      19
      ·
      3 days ago

      Sinking a ship is a dramatic overreaction to accessing unclassified Treasury documents.

      We spy on China as well, we just don’t make announcements like “in retaliation we’re going to continue hacking their shit too”.

      Besides, if china needs to know anything actually important they can just ask putin to ask any member of trump’s cabinet.

    • mlg@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      3 days ago

      looks at the master list of 3rd world countries with US installed regimes and dictators

      “Man we don’t utilize our military might enough, we should escalate to war with our single global competitor”