3 ms·
> On October 10, 2023, one of Xfinity’s software providers, Citrix, announced a vulnerability in one of its products used by Xfinity and thousands of other comp
by liquidise 3y ago
> On October 10, 2023, one of Xfinity’s software providers, Citrix, announced a
vulnerability in one of its products used by Xfinity and thousands of other companies worldwide. At the time Citrix made this announcement, it released a patch to fix the vulnerability. Citrix issued additional mitigation guidance on October 23, 2023. We promptly patched and mitigated our systems[1]
This reads like "we didn't patch until weeks after the vulnerability and patch were provided" but it's worded intentionally unclear to differ blame.
> Q: How will Comcast prevent another incident from occurring?
> A: We have robust security programs in place which help us to discover criminal activity such as this one
You have to love how their response to their own question is, functionally, "we won't prevent your information from being stolen, but boy howdy we'll sure know when it happens though!"
As a long-time disgruntled comcast customer, i have to say none of this surprises me. But local monopolies mean my wallet doesn't really get a vote in this matter.
1. https://assets.xfinity.com/assets/dotcom/learn/Notice%20To%20Customers%20of%20Data%20Security%20Incident.pdf?INTCMP=dsi-12152023 https://assets.xfinity.com/assets/dotcom/learn/Notice%20To%2...