3 ms·
The way I read it: large companies use Carbon Black to have all their files and executables to checked for maliciousness. CB then uploads these file to antiviru
by PappaPatat 9y ago
The way I read it: large companies use Carbon Black to have all their files and executables to checked for maliciousness. CB then uploads these file to antivirus.com to have them checked against 50 AV engines. VT 'hides' the uploader behind a dedicated API key, in the case of CB: 32d05c66
directdefense then download some of these files from virustotal and found (among a shitload of nothing) sensitive stuff, wrote a blog and blamed CB.
With a little more digging they would have found many, many more services and applications that do the exact same thing.