ZeroHour
Schneier on Securitypublished ()ingested

Leaked NSA Hacking Tools

criticalExploit / PoCimportance 60
Full article178 words · extracted from schneier.com · click to collapse

In 2016, a hacker group calling itself the Shadow Brokers released a trove of 2013 NSA hacking tools and related documents. Most people believe it is a front for the Russian government. Since, then the vulnerabilities and tools have been used by both government and criminals, and put the NSA’s ability to secure its own cyberweapons seriously into question.

Now we have learned that the Chinese used the tools fourteen months before the Shadow Brokers released them.

Does this mean that both the Chinese and the Russians stole the same set of NSA tools? Did the Russians steal them from the Chinese, who stole them from us? Did it work the other way? I don’t think anyone has any idea. But this certainly illustrates how dangerous it is for the NSA—or US Cyber Command—to hoard zero-day vulnerabilities.

EDITED TO ADD (5/16): Symantec report.

Tags: China, disclosure, hacking, NSA, Russia, vulnerabilities, zero-day

Posted on May 8, 2019 at 11:30 AM20 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2019/05/leaked_nsa_hack.html