Data Storage

Windows 10 Bug Corrupts Your Hard Drive On Seeing This File's Icon (bleepingcomputer.com) 96

An unpatched zero-day in Microsoft Windows 10 allows attackers to corrupt an NTFS-formatted hard drive with a one-line command. Bleeping Computer reports: In August 2020, October 2020, and finally this week, infosec researcher Jonas L drew attention to an NTFS vulnerability impacting Windows 10 that has not been fixed. When exploited, this vulnerability can be triggered by a single-line command to instantly corrupt an NTFS-formatted hard drive, with Windows prompting the user to restart their computer to repair the corrupted disk records. The researcher told BleepingComputer that the flaw became exploitable starting around Windows 10 build 1803, the Windows 10 April 2018 Update, and continues to work in the latest version. What's worse is, the vulnerability can be triggered by standard and low privileged user accounts on Windows 10 systems. [...] It is unclear why accessing this attribute corrupts the drive, and Jonas told BleepingComputer that a Registry key that would help diagnose the issue doesn't work.

One striking finding shared by Jonas with us was that a crafted Windows shortcut file (.url) that had its icon location set to C:\:$i30:$bitmap would trigger the vulnerability even if the user never opened the file! As observed by BleepingComputer, as soon as this shortcut file is downloaded on a Windows 10 PC, and the user views the folder it is present in, Windows Explorer will attempt to display the file's icon. To do this, Windows Explorer would attempt to access the crafted icon path inside the file in the background, thereby corrupting the NTFS hard drive in the process. Next, "restart to repair hard drive" notifications start popping up on the Windows PC -- all this without the user even having opened or double-clicked on the shortcut file.

Security

Amazon's Ring Neighbors App Exposed Users' Precise Locations and Home Addresses (techcrunch.com) 19

A security flaw in Ring's Neighbors app was exposing the precise locations and home addresses of users who had posted to the app. From a report: Ring, the video doorbell and home security startup acquired by Amazon for $1 billion, launched Neighbors in 2018 as a breakaway feature in its own standalone app. Neighbors is one of several neighborhood watch apps, like Nextdoor and Citizen, that lets users anonymously alert nearby residents to crime and public-safety issues. While users' posts are public, the app doesn't display names or precise locations -- though most include video taken by Ring doorbells and security cameras. The bug made it possible to retrieve the location data on users who posted to the app, including those who are reporting crimes. But the exposed data wasn't visible to anyone using the app. Rather, the bug was retrieving hidden data, including the user's latitude and longitude and their home address, from Ring's servers. Another problem was that every post was tied to a unique number generated by the server that incremented by one each time a user created a new post. Although the number was hidden from view to the app user, the sequential post number made it easy to enumerate the location data from previous posts -- even from users who aren't geographically nearby.
Google

Google Reveals Sophisticated Windows and Android Hacking Operation (zdnet.com) 15

Google published a six-part report this week detailing a sophisticated hacking operation that the company detected in early 2020 and which targeted owners of both Android and Windows devices. From a report: The attacks were carried out via two exploit servers delivering different exploit chains via watering hole attacks, Google said. "One server targeted Windows users, the other targeted Android," Project Zero, one of Google's security teams, said in the first of six blog posts. Google said that both exploit servers used Google Chrome vulnerabilities to gain an initial foothold on victim devices. Once an initial entry point was established in the user's browsers, attackers deployed an OS-level exploit to gain more control of the victim's devices. The exploit chains included a combination of both zero-day and n-day vulnerabilities, where zero-day refers to bugs unknown to the software makers, and n-day refers to bugs that have been patched but are still being exploited in the wild.
Desktops (Apple)

Apple Removes Feature That Allowed Its Apps To Bypass macOS Firewalls and VPNs (zdnet.com) 29

Apple has removed a controversial feature from the macOS operating system that allowed 53 of Apple's own apps to bypass third-party firewalls, security tools, and VPN apps installed by users for their protection. From a report: Known as the ContentFilterExclusionList, the list was included in macOS 11, also known as Big Sur. The exclusion list included some of Apple's biggest apps, like the App Store, Maps, and iCloud, and was physically located on disk at: /System/Library/Frameworks/NetworkExtension.framework/Versions/Current/Resources/Info.plist.

Its presence was discovered last October by several security researchers and app makers who realized that their security tools weren't able to filter or inspect traffic for some of Apple's applications. Security researchers such as Patrick Wardle, and others, were quick to point out at the time that this exclusion risk was a security nightmare waiting to happen. They argued that malware could latch on to legitimate Apple apps included on the list and then bypass firewalls and security software.

Hardware

BeagleV is a $150 RISC-V Computer Designed To Run Linux (arstechnica.com) 52

New submitter shoor writes: Seeed Studios -- the makers of the Odyssey mini-PC -- have teamed up with well-known SBC vendor BeagleBoard to produce an affordable RISC-V system designed to run Linux. The new BeagleV (pronounced "Beagle Five") system features a dual-core, 1GHz RISC-V CPU made by StarFive -- one of a network of RISC-V startups created by better-known RISC-V vendor SiFive. The CPU is based on two of SiFive's U74 Standard Cores -- and unlike simpler microcontroller-only designs, it features a MMU and all the other trimmings necessary to run full-fledged modern operating systems such as Linux distributions. StarFive's VIC7100 processor design is aimed at edge AI tasks as well as general-purpose computing. In addition to the two RISC-V CPU cores, it features a Tensilica Vision VP6 DSP for machine-vision applications, a Neural Network Engine, and a single-core NVDLA (Nvidia Deep Learning Accelerator) engine.
Encryption

Signal's Brian Acton Talks About Exploding Growth, Monetization and WhatsApp Data-Sharing Outrage (techcrunch.com) 42

Brian Acton is crossing paths again with Facebook. From a report: Over more than a decade of building and operating WhatsApp, the company's co-founder first competed against and then sold his instant messaging app to the social juggernaut. Only a few years ago he parted ways with the company that made him a billionaire in a bitter split over messaging and privacy. Now Acton says the ongoing outrage over what Facebook has done to the messaging service he helped build is driving people to his latest project -- Signal. Acton, who serves as the executive chairman of the privacy-conscious messaging app's holding company, told TechCrunch in an interview that the user base of Signal has "exploded" in recent weeks. "The smallest of events helped trigger the largest of outcomes," said Acton on a video call. "We're also excited that we are having conversations about online privacy and digital safety and people are turning to Signal as the answer to those questions." "It's a great opportunity for Signal to shine and to give people a choice and alternative. It was a slow burn for three years and then a huge explosion. Now the rocket is going," he said. The event Acton is referring to is the recent change in data-sharing policy disclosed by WhatsApp, an app that serves more than 2 billion users worldwide. Poll: Which Messaging App Do You Prefer To Use?
Encryption

WhatsApp Clarifies It's Not Giving All Your Data To Facebook (theverge.com) 92

An anonymous reader quotes a report from The Verge: WhatsApp has published a new FAQ page to its website outlining its stances on user privacy in response to widespread backlash over an upcoming privacy policy update. The core issue relates to WhatsApp's data-sharing procedures with Facebook, with many users concerned an updated privacy policy going into effect on February 8th will mandate sharing of sensitive profile information with WhatsApp's parent company. That isn't true -- the update has nothing to do with consumer chats or profile data, and instead the change is designed to outline how businesses who use WhatsApp for customer service may store logs of its chats on Facebook servers. That's something the company feels it is required to disclose in its privacy policy, which it's now doing after previewing the upcoming changes to business chats back in October.

But a wave of misinformation on social media, not helped by Facebook's abysmal track record on privacy and its reputation for obfuscating changes to its various terms of service agreements, has resulted in a full-blown WhatsApp backlash that has users fleeing to competitors like Signal and Telegram. [...] WhatsApp executives, as well as Instagram chief Adam Mosseri and Facebook AR / VR head Andrew "Boz" Bosworth, are now trying to set the record straight, perhaps to little avail at this point.

"We want to be clear that the policy update does not affect the privacy of your messages with friends or family in any way. Instead, this update includes changes related to messaging a business on WhatsApp, which is optional, and provides further transparency about how we collect and use data," the company writes on the new FAQ page. It also stresses in the FAQ that neither Facebook nor WhatsApp read users' message logs or listen to their calls, and that WhatsApp doesn't store user location data or share contact information with Facebook. (It's also worth noting that data sharing with Facebook is extremely limited for European users due to stronger user privacy protections in the EU.) WhatsApp chief Will Cathcart also took to Twitter a few days ago to post a thread (later shared by Bosworth in the tweet above) trying to cut through the confusion and explain what's actually going on. "With end-to-end encryption, we cannot see your private chats or calls and neither can Facebook. We're committed to this technology and committed to defending it globally," Cathcart wrote. "It's important for us to be clear this update describes business communication and does not change WhatsApp's data sharing practices with Facebook. It does not impact how people communicate privately with friends or family wherever they are in the world."

Encryption

Telegram Adds 25 Million New Users In Just 72 Hours (androidpolice.com) 91

According to founder and CEO Pavel Durov, Telegram gained 25 million new users in the last 72 hours as it smashed past the 500 million active monthly user mark. Android Police reports: For comparison, the app averaged around 1.5 million new users per day in 2020, which was impressive enough already. Durvov says that this is down to his company's simple privacy and security promise, above all else.

The bulk of the new users are coming from Asia (38%), Europe (27%), and Latin America (21%), with around 8% signing up from the MENA region (Middle East and North Africa). Although not explicitly noted in Durov's post, there is likely a good number of Parler orphans joining Telegram -- although there are differences between the functions of the two apps, there's talk that former Parler users are heading to encrypted messaging apps in search of a more private platform. Signal has seen a similar rise in popularity for the same reason.

IT

The Impractical but Indisputable Rise of Retrocomputing (nytimes.com) 137

For all the personal technology introduced and popularized in 2020 -- upscale fitness bikes, at-home Covid tests, game consoles new and old -- the personal computer lands on the list with a bit of a thud. PCs lack the novelty of other gadgets, but they're practical, essential even, in a year when work, school and social life have come to rely heavily upon them. From a report: While modern, ever more efficient computers are selling better than they have in years, vintage computers -- impractical old devices in need of repairs and out-of-production parts -- are also in demand on sites like eBay. Collectors also flock to message boards, subreddits and Discord servers to buy, sell and trade parts. People are buying these PCs not necessarily for daily use, but for the satisfaction they get from rebuilding them. It's a trend one might chalk up to quarantine boredom, though it's been gaining traction for years.

Retrocomputing, the hobby is called, is hardly just a way to pass the time. Instead, as enthusiasts see it, it's a means of communing with the past. "You get into this mind-set of what it must've been like to be somebody in the late '70s, having spent thousands of dollars on this thing that barely does anything more than a calculator," said Clint Basinger, 34, who runs the YouTube channel Lazy Game Reviews. (The devices do allow retrocomputers to make art and music using software unavailable on new computers and to play 8-bit games, but not much else beyond that.) "It's like a time machine to me," Mr. Basinger added. Before the pandemic, there were several vintage computing conventions located around the United States, to which collectors brought their computers to show off. Attendees bought and traded hardware at these events, as well as meet the friends they've made online.

Bitcoin

Lost Passwords Lock Millionaires Out of Their Bitcoin Fortunes (nytimes.com) 194

Stefan Thomas, a German-born programmer living in San Francisco, has two guesses left to figure out a password that is worth, as of this week, about $220 million. From a report: The password will let him unlock a small hard drive, known as an IronKey, which contains the private keys to a digital wallet that holds 7,002 Bitcoin. While the price of Bitcoin dropped sharply on Monday, it is still up more than 50 percent from just a month ago when it passed its previous all-time high around $20,000. The problem is that Mr. Thomas years ago lost the paper where he wrote down the password for his IronKey, which gives users 10 guesses before it seizes up and encrypts its contents forever. He has since tried eight of his most commonly used password formulations -- to no avail. "I would just lay in bed and think about it," Mr. Thomas said. "Then I would go to the computer with some new strategy, and it wouldn't work, and I would be desperate again."

Bitcoin, which has been on an extraordinary and volatile eight-month run, has made a lot of its holders very rich in a short period of time, even as the coronavirus pandemic has ravaged the world economy. But the cryptocurrency's unusual nature has also meant that there are many people who are locked out of their Bitcoin fortunes as a result of lost or forgotten keys. They have been forced to watch, helpless, as the price has risen and fallen dramatically, unable to cash in on their digital wealth. Of the existing 18.5 million Bitcoin, around 20 percent -- currently worth around $140 billion -- appear to be in lost or otherwise stranded wallets, according to the cryptocurrency data firm Chainalysis. Wallet Recovery Services, a business that helps find lost digital keys, said it has gotten 70 requests a day from people who want help recovering their riches, three times the number of a month ago. Bitcoin owners who are locked out of their wallets speak of endless days and nights of frustration as they have tried to access their fortunes. Many have owned the coins since Bitcoin's early days a decade ago, when no one had confidence that the tokens would be worth anything.

Security

SolarWinds Malware Has 'Curious' Ties To Russian-Speaking Hackers (arstechnica.com) 53

An anonymous reader quotes a report from Ars Technica: The malware used to hack Microsoft, security company FireEye, and at least a half-dozen federal agencies has "interesting similarities" to malicious software that has been circulating since at least 2015, researchers said on Monday. Sunburst is the name security researchers have given to malware that infected about 18,000 organizations when they installed a malicious update for Orion, a network management tool sold by Austin, Texas-based SolarWinds. The unknown attackers who planted Sunburst in Orion used it to install additional malware that burrowed further into select networks of interest. With infections that hit the Departments of Justice, Commerce, Treasury, Energy, and Homeland Security, the hack campaign is among the worst in modern US history. The National Security Agency, the FBI, and two other federal agencies last week said that the Russian government was "likely" behind the attack, which began no later than October 2019. While several news sources, citing unnamed officials, have reported the intrusions were the work of the Kremlin's SVR, or Foreign Intelligence Service, researchers continue to look for evidence that definitively proves or disproves the statements.

On Monday, researchers from Moscow-based security company Kaspersky Lab reported "curious similarities" in the code of Sunburst and Kazuar, a piece of malware that first came to light in 2017. Kazuar, researchers from security firm Palo Alto Networks said then, was used alongside known tools from Turla, one of the world's most advanced hacking groups, whose members speak fluent Russian. In a report published on Monday, Kaspersky Labs researchers said they found at least three similarities in the code and functions of Sunburst and Kazuar. They are: The algorithm used to generate the unique victim identifiers; The algorithm used to make the malware "sleep," or delay taking action, after infecting a network; and Extensive use of the FNV-1a hashing algorithm to obfuscate code.

Monday's post cautions against drawing too many inferences from the similarities. They could mean that Sunburst was written by the same developers behind Kazuar, but they might also be the result of an attempt to mislead investigators about the true origins of the SolarWinds supply chain attack, something researchers call a false flag operation. Other possibilities include a developer who worked on Kazuar and later went to work for the group creating Sunburst, the Sunburst developers reverse engineering Kazuar and using it as inspiration, or developers of Kazuar and Sunburst obtaining their malware from the same source.

Security

Researchers Test UN's Cybersecurity, Find Personal Data On 100K Employees (securityledger.com) 9

chicksdaddy shares a report from The Security Ledger: Independent security researchers testing the security of the United Nations were able to compromise public-facing servers and a cloud-based GitHub development account used by the U.N. and lift data on more than 100,000 staff and employees, according to a report by The Security Ledger. Researchers affiliated with Sakura Samurai, a newly formed collective of independent security experts, exploited an exposed GitHub repository belonging to the International Labour Organization and the U.N.'s Environment Programme (UNEP) to obtain "multiple sets of database and application credentials" for UNEP applications, according to a blog post by one of the Sakura Samurai researchers, John Jackson, explaining the group's work.

Specifically, the group was able to obtain access to database backups for private UNEP projects that exposed a wealth of information on staff and operations. That includes a document with more than 1,000 U.N. employee names, emails; more than 100,000 employee travel records including destination, length of stay and employee ID numbers; more than 1,000 U.N. employee records and so on. The researchers stopped their search once they were able to obtain personally identifying information. However, they speculated that more data was likely accessible.

Security

Ubiquiti Tells Customers To Change Passwords After Security Breach (zdnet.com) 25

An anonymous reader quotes a report from ZDNet: Networking equipment and IoT device vendor Ubiquiti Networks has sent out today notification emails to its customers informing them of a recent security breach. "We recently became aware of unauthorized access to certain of our information technology systems hosted by a third party cloud provider," Ubiquiti said in emails today. The servers stored information pertaining to user profiles for account.ui.com, a web portal that Ubiquiti makes available to customers who bought one of its products. The site is used to manage devices from a remote location and as a help and support portal.

According to Ubiquiti, the intruder accessed servers that stored data on UI.com users, such as names, email addresses, and salted and hashed passwords. Home addresses and phone numbers may have also been exposed, but only if users decided to configure this information into the portal. How many Ubiquiti users are impacted and how the data breach occurred remains a mystery. It is currently unclear if the "unauthorized access" took place when a security researcher found the exposed data or was due to a malicious threat actor. Despite the bad news to its customers, Ubiquiti said that it had not seen any unauthorized access to customer accounts as a result of this incident. The company is now asking all users who receive the email to change their account passwords and turn on two-factor authentication.

Businesses

Staples Offers To Buy Office Depot For $2.1 Billion (cnn.com) 56

For the third time, Staples is proposing to buy rival Office Depot in a $2.1 billion deal. CNN reports: The $40-per-share offer price for Office Depot's parent company, ODP Corp., is a roughly 60% premium over its average closing price for the last 90 trading days. The all-cash transaction, according to Staples, is a "compelling value proposition" and is a "superior to the intrinsic, standalone value" of Office Depot. Staples said it's "prepared to take all necessary measures" to get the merger approved by the Federal Trade Commission, which said in 2015 that the combination would give the combined companies too large a chunk of the office supply retail market and would violate antitrust law.

To avoid antitrust scrutiny, Staples proposed selling its IT management company CompuCom or its business-to-business unit. Doing that might lead to Staples increase its proposal price, it said. The regulatory process could take about six months, the company estimated, and Staples is urging ODP's board to "instruct management to cooperate with the regulatory authorities as soon as possible." Monday's proposal is about a third of the purchase price of the original 2015 purchase agreement of $6.3 billion. This marks the third time in about 25 years that the companies have tried to merge, including once in 1997.

Social Networks

Scraped Parler Data Is a Metadata Gold Mine (techcrunch.com) 333

An anonymous reader quotes a report from TechCrunch: Embattled social media platform Parler is offline after Apple, Google and Amazon pulled the plug on the site after the violent riot at the U.S. Capitol last week that left five people dead. But while the site is gone (for now), millions of posts published to the site since the riot are not. A lone hacker scraped millions of posts, videos and photos published to the site after the riot but before the site went offline on Monday, preserving a huge trove of potential evidence for law enforcement investigating the attempted insurrection by many who allegedly used the platform to plan and coordinate the breach of the Capitol.

The hacker and internet archivist, who goes by the online handle @donk_enby, scraped the social network and uploaded copies to the Internet Archive, which hosts old and historical versions of web pages. In a tweet, @donk_enby said she scraped data from Parler that included deleted and private posts, and the videos contained "all associated metadata." The scraped videos from Parler appear to also include the precise location data of where the videos were taken. That metadata could be a gold mine of evidence for authorities investigating the Capitol riot, which may tie some rioters to their Parler accounts or help police unmask rioters based on their location data.

Security

Some Ransomware Gangs Are Going After Top Execs To Pressure Companies Into Paying (zdnet.com) 31

A new trend is emerging among ransomware groups where they prioritize stealing data from workstations used by top executives and managers in order to obtain "juicy" information that they can later use to pressure and extort a company's top brass into approving large ransom payouts. From a report: ZDNet first learned of this new tactic last week during a phone call with a company that paid a multi-million dollar ransom to the Clop ransomware gang. Similar calls with other Clop victims and email interviews with cybersecurity firms later confirmed that this wasn't just a one-time fluke, but instead a technique that the Clop gang had fine-tuned across the past few months.

The technique is an evolution of what we've been seen from ransomware gangs lately. For the past two years, ransomware gangs have evolved from targeting home consumers in random attacks to going after large corporations in very targeted intrusions. These groups breach corporate networks, steal sensitive files they can get their hands on, encrypt files, and then leave ransom notes on the trashed computers. In some cases, the ransom note informs companies that they have to pay a ransom demand to receive a decryption key. In case data was stolen, some ransom notes also inform victims that if they don't pay the ransom fee, the stolen data will be published online on so-called "leak sites."

Security

Hacker Locks Internet-Connected Chastity Cage, Demands Ransom (vice.com) 139

A hacker took control of people's internet-connected chastity cages and demanded a ransom to be paid in Bitcoin to unlock it. From a report: "Your cock is mine now," the hacker told one of the victims, according to a screenshot of the conversation obtained by a security researcher that goes by the name Smelly and is the founder of vx-underground, a website that collects malware samples. In October of last year, security researchers found that the manufacturer of an Internet of Things chastity cage -- a sex toy that users put around their penis to prevent erections that is used in the BDSM community and can be unlocked remotely -- had left an API exposed, giving malicious hackers a chance to take control of the devices. That's exactly what happened, according to a security researcher who obtained screenshots of conversations between the hacker and several victims, and according to victims interviewed by Motherboard. A victim who asked to be identified only as Robert said that he received a message from a hacker demanding a payment of 0.02 Bitcoin (around $750 today) to unlock the device. He realized his cage was definitely "locked," and he "could not gain access to it."
Mozilla

Firefox To Block Backspace Key From Working as 'Back' Button (zdnet.com) 130

Mozilla developers plan to remove support for using the Backspace key as a Back button inside Firefox. From a report: The change is currently active in the Firefox Nightly version and is expected to go live in Firefox 86, scheduled to be released next month, in late February 2021. The removal of the Backspace key as a navigational element didn't come out of the blue. It was first proposed back in July 2014, in a bug report opened on Mozilla's bug tracker. At the time, Mozilla engineers argued that many users who press the Backspace key don't always mean to navigate to the previous page (the equivalent of pressing the Back button).
Security

New Zealand's Central Bank Says Its Data System Was Breached (apnews.com) 22

The Associated Press reports: New Zealand's central bank said Sunday that one of its data systems has been breached by an unidentified hacker who potentially accessed commercially and personally sensitive information. A third party file sharing service used by the Reserve Bank of New Zealand to share and store sensitive information had been illegally accessed, the Wellington-based bank said in a statement.

Governor Adrian Orr said the breach has been contained. The bank's core functions "remain sound and operational," he said... "The nature and extent of information that has been potentially accessed is still being determined, but it may include some commercially and personally sensitive information," Orr added...

Dave Parry, professor of computer science at Auckland University, told Radio New Zealand that another government was likely behind the bank data breach. "Ultimately if you were coming from a sort of like criminal perspective, the government agencies aren't going to pay your ransom or whatever, so you'd be more interested probably coming in from a government-to-government level," Parry said.

Security

After the Riot, the US Capitol's IT Staff Faces 'a Security Mess' (wired.com) 140

After Wednesday's invasion by protesters, America's Capitol building is now grappling with "the process of securing the offices and digital systems after hundreds of people had unprecedented access to them," writes Wired.

Long-time Slashdot reader SonicSpike shares their report: Rioters could have bugged congressional offices, exfiltrated data from unlocked computers, or installed malware on exposed devices. In the rush to evacuate the Capitol, some computers were left unlocked and remained accessible by the time rioters arrived. And at least some equipment was stolen; Senator Jeff Merkley of Oregon said in a video late Wednesday that intruders took one of his office's laptops off a conference table...

Former Senate sergeant at arms Frank Larkin, who retired as Senate sergeant at arms in 2018, adds that cybersecurity is the next priority after physical security. In spite of this, the mob Wednesday had ample opportunities to steal information or gain device access if they wanted to. And while the Senate and House each build off of their own shared IT framework, ultimately each of the 435 representatives and 100 senators runs their own office with their own systems. This is a boon to security in the sense that it creates segmentation and decentralization; getting access to Nancy Pelosi's emails doesn't help you access the communications of other representatives. But this also means that there aren't necessarily standardized authentication and monitoring schemes in place. Larkin emphasizes that there is a baseline of monitoring that IT staffers will be able to use to audit and assess whether there was suspicious activity on congressional devices. But he concedes that representatives and senators have varying levels of cybersecurity competence and hygiene.

It's also true that potentially exposed data at the Capitol on Wednesday would not have been classified, given that the mob had access only to unclassified networks. But congressional staffers are not subject to Freedom of Information Act obligations and are often much more candid in their communications than other government officials. Security and intelligence experts also emphasize that troves of unclassified information can still reveal sensitive or even classified information when combined... Kelvin Coleman, executive director of the National Cyber Security Alliance, who formerly worked in the Department of Homeland Security and National Security Council... adds, though, that for now the most important thing congressional IT staffers can do is account for which devices were stolen and begin a mass effort to reset passwords, add multifactor authentication to any accounts that don't already have it, wipe and reimage hard drives when practical, and comb monitoring logs for signs of access or exfiltration.

Slashdot Top Deals