Symantec says it wasn't impacted by Fxmsp hack, denies being contacted by researchers, who refute Symantec's claim; Trend Micro calls hack a “low risk” incident
Symantec, Trend Micro, and McAfee—b/c their names had been offered up on reddit, twitter & in one article this morning as maybe victims. Trend Micro confirmed it's working w/ law enforcement. Symantec denied being notified & assumes it's clear. Jeremiah Grossman / @jeremiahg : If recent source code of major AV vendors begins circulating publicly, we should expect to see a notable uptick in the number of CVEs. https://twitter.com/... Dell Cameron / @dellcam : So it appears Symantec, Trend Micro, and (likely) McAfee are the three companies. (McAfee sent me a “we're investigating” reply, but did not answer when asked specifically if AdvIntel had reached out.) The first two I can confirm are companies Fxmsp claims it breached. Dell Cameron / @dellcam : AdvIntel also took issue with Trend Micro's claim that no source code was accessed, saying “This statement is incorrect based on the portion of the data we have and the actor's statement.”