Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Sickening
Jul 16, 2007

Black summer was the best summer.

Well this ruins my entire loving weekend if this is true. Cert revocation on its own would be a nightmare. Anyone using their ZIA product in dev environments knows what I am talking about.

Adbot
ADBOT LOVES YOU

The Earl of ToeJam
Jan 22, 2012
Preliminary public info from Zscaler legal team is expected shortly, but my contacts definitely said "it's not nothing". poo poo.

some kinda jackal
Feb 25, 2003

 
 
There's always more, and it's always worse.

:(

flakeloaf
Feb 26, 2003

Still better than android clock



There, now we have zero trust in them. Well done lads

Sickening
Jul 16, 2007

Black summer was the best summer.

The Earl of ToeJam posted:

Preliminary public info from Zscaler legal team is expected shortly, but my contacts definitely said "it's not nothing". poo poo.

The rumors are painful. Once that information starts circling everyone wants to start an incident with nothing actionable outside of reaching out to reps who aren't going to get back to us.

some kinda jackal
Feb 25, 2003

 
 
The happiest person at zscaler is the one account rep who left on vacation yesterday.

The Earl of ToeJam
Jan 22, 2012

Sickening posted:

The rumors are painful. Once that information starts circling everyone wants to start an incident with nothing actionable outside of reaching out to reps who aren't going to get back to us.

Yep. Counting the minutes till someone tells me to start standing up Squid boxes to replace on-prem Zscaler...

Rust Martialis
May 8, 2007

At night, Bavovnyatko quietly comes to the occupiers’ bases, depots, airfields, oil refineries and other places full of flammable items and starts playing with fire there
If anyone gets more info can you post links here plz

Accipiter
Jan 24, 2004

SINATRA.

Rust Martialis posted:

If anyone gets more info can you post links here plz

I really don't think this was a necessary request. Do you honestly think that WASN'T going to happen?

Sickening
Jul 16, 2007

Black summer was the best summer.
https://trust.zscaler.com/zscaler.net/posts/18686

Rust Martialis
May 8, 2007

At night, Bavovnyatko quietly comes to the occupiers’ bases, depots, airfields, oil refineries and other places full of flammable items and starts playing with fire there

Accipiter posted:

I really don't think this was a necessary request. Do you honestly think that WASN'T going to happen?

I'm twitchy now

The Earl of ToeJam
Jan 22, 2012
https://x.com/milkshakesbot/status/1788264515877949951

e: Can't do images right now, but the attacker confirms "begins with a z"

some kinda jackal
Feb 25, 2003

 
 
Wow, really bad week for Zntrust

Rust Martialis
May 8, 2007

At night, Bavovnyatko quietly comes to the occupiers’ bases, depots, airfields, oil refineries and other places full of flammable items and starts playing with fire there

some kinda jackal posted:

Wow, really bad week for Zntrust

Zisco

The Earl of ToeJam
Jan 22, 2012
I received an update from our rep stating no evidence of compromise to "customer and production environments".

e: they added the full statement to the trust site as well. https://trust.zscaler.com/zscaler.net/posts/18686

The Earl of ToeJam fucked around with this message at 20:22 on May 8, 2024

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

only $20K for that? I guess inflation hasn’t hit that market yet

Accipiter
Jan 24, 2004

SINATRA.

quote:

UPDATE Wed, 08 May 2024 12:07:38 UTC - Zscaler’s priority is our customer and production environment and we have not discovered any evidence of incident or compromise to these environments. We are continuing our investigation and closely monitoring the situation.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

The Infosec Thread: Yes, time to move to a mountain and raise goats

Accipiter
Jan 24, 2004

SINATRA.

Subjunctive posted:

The Infosec Thread: Yes, time to move to a mountain and raise goats

GOOSE FARMER

The Fool
Oct 16, 2003


Alpacas

Accipiter
Jan 24, 2004

SINATRA.
https://seekingalpha.com/news/4102870-zscaler-tumbles-company-confirms-ongoing-investigation-possible-data-breach

Pretty much the same as what we've seen so far, with the addition of info that the stock is falling.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I mean, the stock is down 3.3% on the day, which is pretty much within its normal volatility window from looking at the last month

it’s not being dumped in panic

…yet?

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Subjunctive posted:

The Infosec Thread: Yes, time to move to a mountain and raise goats

The Infosec Thread: Teaching rocks to do math was our first mistake

The Earl of ToeJam
Jan 22, 2012

Looking hopefully like just the one day ruined for me, and not the entire weekend.

quote:

UPDATE [Wed, 08 May 2024 23:09:00 UTC] - Zscaler can confirm there is no impact or compromise to its customer, production and corporate environments. 


Our investigation discovered an isolated test environment on a single server (without any customer data) which was exposed to the internet. The test environment was not hosted on Zscaler infrastructure and had no connectivity to Zscaler’s environments. The test environment was taken offline for forensic analysis. 

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


The Earl of ToeJam posted:

Looking hopefully like just the one day ruined for me, and not the entire weekend.

Did they remove that update? I don’t even see the one from a few hours ago saying they didn’t detect anything.

The Earl of ToeJam
Jan 22, 2012

rafikki posted:

Did they remove that update? I don’t even see the one from a few hours ago saying they didn’t detect anything.

Still seems to be up for me. Maybe it's blocked on your proxy?

Sickening
Jul 16, 2007

Black summer was the best summer.
Smells like dev nonsense.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


The Earl of ToeJam posted:

Still seems to be up for me. Maybe it's blocked on your proxy?

Guess it was a caching issue on my phone despite refreshing.

Accipiter
Jan 24, 2004

SINATRA.
https://www.bleepingcomputer.com/news/security/zscaler-says-it-was-not-hacked-after-rumors-circulate-online/

I hope some sucker got bilked out of $20k.

Potato Salad
Oct 23, 2014

nobody cares



ha

ha ha ha.

heh. phoooooo. I'm on vacation biiiiiiiiiitch

Potato Salad
Oct 23, 2014

nobody cares


Sickening posted:

Smells like dev nonsense.

out of curiosity, what piqued your skepticism?

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

Subjunctive posted:

The Infosec Thread: Yes, time to move to a mountain and raise goats

I threaten to do this on a regular basis.

Sickening
Jul 16, 2007

Black summer was the best summer.

Potato Salad posted:

out of curiosity, what piqued your skepticism?

You misunderstand me. I read the last update as some devs building dumb test poo poo in dumb loving spaces outside of normal company owned areas.

Basically “gently caress following any processes, I am spinning up my own aws and doing what I want”. I hope I am right and I hope everyone involved gets ejected.

CLAM DOWN
Feb 13, 2007




in local news (for me lol)

https://www.cbc.ca/news/canada/british-columbia/bc-premier-cyberattacks-sophisticated-1.7198501

quote:

B.C.'s premier said Wednesday that the government has recently identified "sophisticated cybersecurity incidents" involving government networks.

In a statement, Premier David Eby said the provincial government is working with the Canadian Centre for Cyber Security to find out the extent of the cyberattacks, and implement safety measures.

they reset all passwords for all 35,000+ public service workers suddenly last week and it was clear something was up but everyone was being so cagey

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Sickening posted:

You misunderstand me. I read the last update as some devs building dumb test poo poo in dumb loving spaces outside of normal company owned areas.

Basically “gently caress following any processes, I am spinning up my own aws and doing what I want”. I hope I am right and I hope everyone involved gets ejected.

Following along with your hypothetical, these are the logical consequences of "our security controls don't account for the business's needs."

Accipiter
Jan 24, 2004

SINATRA.
WELP

quote:

[Access] Largest Cyber Security Company [SOLD]

Only registered members can see post attachments!

Accipiter fucked around with this message at 13:32 on May 9, 2024

The Fool
Oct 16, 2003


Blinkz0rz posted:

Following along with your hypothetical, these are the logical consequences of "our security controls don't account for the business's needs."

earlier this week I had a dev tell me he needed to open a storage account to the public so they could write to it from salesforcd


lmao

Shumagorath
Jun 6, 2001

The Fool posted:

earlier this week I had a dev tell me he needed to open a storage account to the public so they could write to it from salesforcd

lmao
In the two seconds before I realized that was a typo I genuinely thought salesforce might have made their own systemd

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


Very polite of them to try to blank out Ms No Reply’s email address.

Adbot
ADBOT LOVES YOU

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


So uh is zscaler owned or not

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply