4 ms·
> AnyDesk spokesperson Matthew Caldwell did not respond to an email from TechCrunch. CrowdStrike, which is working with AnyDesk to remediate the cyberattack, de
by calgarymicro 3y ago
> AnyDesk spokesperson Matthew Caldwell did not respond to an email from TechCrunch. CrowdStrike, which is working with AnyDesk to remediate the cyberattack, declined to answer TechCrunch’s questions when reached Monday.
> AnyDesk did not respond to questions asking if any customer data was accessed, though the company said in its statement that there is “no evidence that any end-user systems have been affected.”
> “We can confirm that the situation is under control and it is safe to use AnyDesk,” AnyDesk said. “Please ensure that you are using the latest version, with the new code signing certificate”.
Mmm. If I were an AnyDesk customer I'd definitively want more details on what actually happened before I used their software again.
- ziddoap 3y ago>AnyDesk did not respond to questions asking if any customer data was accessed, though the company said in its statement that there is “no evidence that any end-user systems have been affected.” In my experience, this answer is equivalent to "Yes, customer data was accessed". If it wasn't, they'd say something like "We have no reason to believe customer data was accessed", instead of trying to shift the focus to whether or not end-user systems were caught up in the blast radius.
- user3939382 3y agoSad that what we white wash with the label "PR" or sometimes a hair worse "spin" is actually misrepresentation and dishonesty which is so pervasive (and therefore actually horrible) in corporate culture that it is totally normalized. I don't care if every country in the world does it, it is not okay to deceive, twist, and spin things.
- amelius 3y agoIt's the total imbalance of power.
- mattigames 3y ago"mislead the focus" should be a valid and common way to describe this kind of thing.
- matbilodeau 3y agothere are accounts for sale https://securityonline.info/anydesk-breach-2024-dark-web-sale-of-18317-credentials/?expand_article=1 https://securityonline.info/anydesk-breach-2024-dark-web-sal...
- ThePowerOfFuet 3y agoIf (huge if!) those screen shots are legit, then Anydesk was storing passwords in cleartext or equivalent; many of them are far too random to be bruteforced so quickly. The last one, where both the domain name and password start with QR, makes me think the screenshots might actually be legit.
- matbilodeau 3y agoSeen on Breach Forums onion site as well ...
- GoblinSlayer 3y ago>In light of this breach, AnyDesk customers must take proactive steps to protect their accounts and data. Password changes alone are insufficient. Go figure :)
- fieldcny 3y agoThe vagueness of end-user is also a little concerning, are they using it in sense a lot of corporate it folks do to mean employees, or are they implying their customers are their end users.
- tecleandor 3y agoI understand Crowdstrike not talking about their client (as much as I hate their agent). But that "new code signing certificate" smells very bad. I would nuke anything signed by them ASAP.
- pintxo 3y ago> I'd definitively want more details on what actually happened before I used their software again. You’re probably not in their target demographic to begin with, if you ask such questions.