Microsoft removes Positive Technologies from a list of vendors it gives early access to vulnerability info; IBM also lists Positive as a security partner
MAPP Lily Hay Newman / Wired : Security News This Week: How the FBI Finally Got Into the San Bernardino Shooter's iPhone Dan Goodin / Ars Technica : US government strikes back at Kremlin for SolarWinds hack campaign Cynthia Brumfield / CSO : US sanctions Russian government, security firms for SolarWinds breach, election interference Tweets: T⚉ny Adams / @tadams0620 : Positive Technologies presents an extensive list of Russian government entities in its client list, but only if you are viewing the Russian language version of their site. EN - https://t.co/wA2emIpebU RU - https://t.co/XKXoaGheZe https://t.co/YP0oSCyWTS @briankrebs : One of the 6 Russian tech firms sanctioned yesterday by White House for allegedly aiding Russian cyberspies — Positive Technologies — had advance access to information about vulnerabilities in Microsoft products. MS says it's removed that access for PT https://apnews.com/... Kim Zetter / @kimzetter : Positive Technologies, the Russian security firm sanctioned this wk for allegedly helping Russian spies hack the US, has for yrs belonged to Microsoft's MAPP program, which gives security vendors advance access to info about vulns and proof-of-concept code https://t.co/NLhMDalED8 @sherrod_im : This is shocking but I'm glad they found them. https://apnews.com/... Kenn White / @kennwhite : This shouldn't be particularly surprising to those who closely follow vulnerability research - several PT principals are well respected by their peers for deeply technical (published) work in Windows core software and x86 management engine/microcode flaws. https://twitter.com/... Ben Hawkes / @benhawkes : Not enough. MAPP needs an overhaul. Signature based AVs are a best-effort defense against N-day exploits, and don't provide strategic value. On the other hand, MAPP has consistently been leaking to attackers since inception. The net balance favors attackers at the moment. https://twitter.com/... @lcamtuf : Our annual reminder about the perils of vulnerability sharing clubs... https://twitter.com/... Matt O'Brien / @mattoyeah : Left: Microsoft's MAPP website showing firms that get early access to vulnerability info; 9:30 p.m. EST Right: Same website, hour later. What's missing? Positive Technologies, now sanctioned by U.S. https://twitter.com/... https://twitter.com/... Matt O'Brien / @mattoyeah : That was quick: Microsoft now says it's dropped Russian firm from its MAPP list of companies that get early access to vulnerability info https://twitter.com/... via @fbajak Dan Goodin / @dangoodin001 : Last night, @fbajak of the AP reported that Positive Technologies was a member of the Microsoft Active Protections Program, which makes vulnerabilities and sometimes proof-of-concept exploits available in advance of patches being released to the public. https://apnews.com/... Matt O'Brien / @mattoyeah : Microsoft names the company, now facing U.S. sanctions, as one of the security software providers to which it gives early access to vulnerability information https://apnews.com/... Dan Friedman / @dfriedman33 : In new sanctions on Russia, Treasury bars U.S. banks from lending to key Russian gov institutions. That's a response to actions Russia took while facing (narrower) sanctions. Seems certain US will need better diplomacy too to change Kremlin's behavior. https://home.treasury.gov/... U.S. Embassy Kyiv / @usembassykyiv : Today, the U.S. Department of the Treasury took multiple sanctions actions under new and existing Executive Orders (E.O.) targeting aggressive and harmful activities by the Government of the Russian Federation. https://home.treasury.gov/... @wylienewmark : I can't recall a previous set of cyber-related sanctions against Russia that goes quite so deep into the public-private overlaps in how Russian intelligence engages in cyber operations. https://home.treasury.gov/... Thomas Brewster / @iblametom : Woah - Positive Technologies, a major cybersecurity company in Russia, is one of those targeted by the Biden regime's efforts against Russian cyber activities. The Treasury is saying Positive has been supporting Russian intelligence: https://home.treasury.gov/... Craig Caplan / @craigcaplan : April 15, 2021: “Treasury Sanctions Russia with Sweeping New Sanctions Authority” Treasury Secretary Janet Yellen: “The President signed this sweeping new authority to confront Russia's continued and growing malign behavior.” https://home.treasury.gov/...
Positive Technologies presents an extensive list of Russian government entities in its client list, but only if you are viewing the Russian language version of their site. EN - https://t.co/wA2emIpebU RU - https://t.co/XKXoaGheZe https://t.co/YP0oSCyWTS
One of the 6 Russian tech firms sanctioned yesterday by White House for allegedly aiding Russian cyberspies — Positive Technologies — had advance access to information about vulnerabilities in Microsoft products. MS says it's removed that access for PT https://apnews.com/...
Positive Technologies, the Russian security firm sanctioned this wk for allegedly helping Russian spies hack the US, has for yrs belonged to Microsoft's MAPP program, which gives security vendors advance access to info about vulns and proof-of-concept code https://t.co/NLhMDalED8
This shouldn't be particularly surprising to those who closely follow vulnerability research - several PT principals are well respected by their peers for deeply technical (published) work in Windows core software and x86 management engine/microcode flaws. https://twitter.com/...
Not enough. MAPP needs an overhaul. Signature based AVs are a best-effort defense against N-day exploits, and don't provide strategic value. On the other hand, MAPP has consistently been leaking to attackers since inception. The net balance favors attackers at the moment. https:/…
Left: Microsoft's MAPP website showing firms that get early access to vulnerability info; 9:30 p.m. EST Right: Same website, hour later. What's missing? Positive Technologies, now sanctioned by U.S. https://twitter.com/... https://twitter.com/...
That was quick: Microsoft now says it's dropped Russian firm from its MAPP list of companies that get early access to vulnerability info https://twitter.com/... via @fbajak
Last night, @fbajak of the AP reported that Positive Technologies was a member of the Microsoft Active Protections Program, which makes vulnerabilities and sometimes proof-of-concept exploits available in advance of patches being released to the public. https://apnews.com/...
Microsoft names the company, now facing U.S. sanctions, as one of the security software providers to which it gives early access to vulnerability information https://apnews.com/...
In new sanctions on Russia, Treasury bars U.S. banks from lending to key Russian gov institutions. That's a response to actions Russia took while facing (narrower) sanctions. Seems certain US will need better diplomacy too to change Kremlin's behavior. https://home.treasury.gov/.…
Today, the U.S. Department of the Treasury took multiple sanctions actions under new and existing Executive Orders (E.O.) targeting aggressive and harmful activities by the Government of the Russian Federation. https://home.treasury.gov/...
I can't recall a previous set of cyber-related sanctions against Russia that goes quite so deep into the public-private overlaps in how Russian intelligence engages in cyber operations. https://home.treasury.gov/...
Woah - Positive Technologies, a major cybersecurity company in Russia, is one of those targeted by the Biden regime's efforts against Russian cyber activities. The Treasury is saying Positive has been supporting Russian intelligence: https://home.treasury.gov/...
April 15, 2021: “Treasury Sanctions Russia with Sweeping New Sanctions Authority” Treasury Secretary Janet Yellen: “The President signed this sweeping new authority to confront Russia's continued and growing malign behavior.” https://home.treasury.gov/...