Source: in January, IoT manufacturer Ubiquiti downplayed a “catastrophic” breach, which gained root access to its AWS accounts and access to countless devices
On Jan. 11, Ubiquiti Inc. [NYSE:UI] — a major vendor of cloud-enabled Internet of Things (IoT) devices such as routers …
Krebs on Security Brian Krebs
Related Coverage
Discussion
-
@briankrebs
@briankrebs
on x
On Jan 11, Ubiquiti said a breach involving a 3rd-party cloud provider exposed customer account credentials. A source who participated in the response to that breach now alleges Ubiquiti downplayed a “catastrophic” incident & that 3rd party claim was a lie https://krebsonsecurity…
-
@teambuild3r
James Turner
on x
“If you have Ubiquiti devices installed and haven't yet changed the passwords on the devices since Jan. 11 this year, now would be a good time to care of that.” https://twitter.com/...
-
@rmhrisk
Ryan Hurst
on x
“They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Adam said. https://twitter.com/...
-
@kennwhite
Kenn White
on x
Hell of a lede: “...in a letter to the European Data Protection Supervisor [the Ubiquiti insider wrote], “The breach was massive, customer data was at risk, access to customers' devices deployed in corporations and homes around the world was at risk."" https://krebsonsecurity.com…
-
@troyhunt
Troy Hunt
on x
Since I'm getting a heap of questions about this: it's obviously a *really* bad look and it puts the onus on @Ubiquiti to respond. The problem now is the same as I commented back in Jan which is that they're not providing anywhere near enough information about the incident. https…
-
@k8em0
Katie Moussouris
on x
“Legal overrode repeated requests to force rotation of all customer credentials, & to revert any device access permission changes within the relevant period” How many security breaches had responses botched by over aggressive lawyers where only Engineers & Communications belong? …
-
@charlesdardaman
Chase Dardaman
on x
Looks like Ubiquiti is about to lose its recommendation from IT and #infosec people https://twitter.com/...
-
@arekfurt
Brian
on x
If what the source says here is true, if half of it is true.... A legal department signing off on a misleading public statement and risking securities fraud actions and other consequences to try to keep the impact of a breach concealed from customers is appalling on every level. …
-
@marcan42
Hector Martin
on x
Well, shit. Ubiquiti got owned. Signing keys - I read that as even non cloud connected controllers could be compromised via the firmware autoupdate pipeline. Are there any decent networking gear vendors left? https://krebsonsecurity.com/ ...
-
@viss
@viss
on x
i guess everyone who skipped the “cloud integration” component for their ubnt gear doged a massive bullet. orgs forcing you to create ‘cloud accounts’ to manage networking infra getting popped like this means attackers can now get access to your infra. https://twitter.com/...
-
@wbm312
Whitney Merrill
on x
Transparency is key. Concealing the extent of a breach will only hurt you in the long run. This will definitely draw regulatory attention. https://twitter.com/...
-
@home_assistant
Home Assistant
on x
If you have any @Ubiquiti gear and have not reset your password since January 11, 2021, do it now! Hackers had full access to their systems, and so also yours. https://twitter.com/...
-
@hrbrmstr
@hrbrmstr
on x
🚨I'm breaking my RT policy for this source b/c this is Very Very Bad™ — IF true. If you run Ubiquiti kit or have customers who do, prbly time to consider switching to a less skeezy vendor. https://twitter.com/...
-
@j0hnnyxm4s
@j0hnnyxm4s
on x
Incident Responder claims Ubiquiti lied about the nature of its recently reported breach. Source was in fact a LastPass account, access using stolen credentials, that contained keys to the Ubiquiti kingdom: https://krebsonsecurity.com/ ...
-
@dangoodin001
Dan Goodin
on x
This reported breach cover up by router and IoT provider Ubiquity is a big deal because the company forces users to use cloud-based authentication to access devices. The data accessed in the breach, a whistleblower says, might allow the attackers to log in to customer devices. ht…
-
@charlesarthur
Charles Arthur
on x
@marcoarment soooooo anyway about your concerns over Ubiquiti.... https://twitter.com/...