Discussion about this post

User's avatar
Francis Turner's avatar

At $dayjob the boss has a saying about classic antivirus software that it works by asking the patient if they are OK and if they say yes believing them. A lot of the AI protection seems to work on the same kind of principle. Tell the AI to not do something and believe them when they say they won't but don't have some thing external to check/validate/confirm.

As someone in network security I find the lack of network and DNS blocking to be the most surprising thing in the various Irregular related incidents. I think these people are basically incompetent at network security. The fact that their SIEMs did not trigger on alerts about abnormal activity is also amazing, but I suspect it is because they didn't actually have a SIEM to alert or had not got it set up correctly.

Kristin Newton's avatar

We’ve opened a Pandora’s Box. How will this story end?

2 more comments...

No posts

Ready for more?