4 ms·
The title is not correct. They used credentials to get access to the vpn. How they moved laterally is obviously the interesting part anyway. Change the title
by peteradio 2y ago
The title is not correct. They used credentials to get access to the vpn. How they moved laterally is obviously the interesting part anyway. Change the title, it gives cover to the lumbering behemoth that fault might lie anywhere besides UnitedHealths corrupt IT.
- skilled 2y agoYou are correct. I made a mistake with the title, it should say that access was acquired through a Citrix account without MFA as opposed to a direct Citrix bug. My bad. I will email mods to change it. This Reuters[0] article is much more specific about saying it was a Citrix vulnerability, but since Citrix has not issued an official statement, it's better to have it changed to the default title. [0]: https://www.reuters.com/technology/cybersecurity/unitedhealth-hackers-took-advantage-citrix-vulnerabilty-break-ceo-says-2024-04-29/ https://www.reuters.com/technology/cybersecurity/unitedhealt...
- dang 2y agoFixed now. Thanks! (Submitted title was "UnitedHealth hackers exploited Citrix bug, CEO says")
- SkyPuncher 2y agoHow they moved laterally was likely trivial. Every place that I seen with a VPN tends to trust everything within the VPN.
- blackmesaind 2y agoCheck the network share for a folder called "Passwords"