ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Accellion Supply Chain Hack

highData breachimportance 57
Tagsbreach
Full article153 words · extracted from schneier.com · click to collapse

A vulnerability in the Accellion file-transfer program is being used by criminal groups to hack networks worldwide.

There’s much in the article about when Accellion knew about the vulnerability, when it alerted its customers, and when it patched its software.

The governor of New Zealand’s central bank, Adrian Orr, says Accellion failed to warn it after first learning in mid-December that the nearly 20-year-old FTA application—using antiquated technology and set for retirement—had been breached.

Despite having a patch available on Dec. 20, Accellion did not notify the bank in time to prevent its appliance from being breached five days later, the bank said.

CISA alert.

EDITED TO ADD (4/14): It appears spy plane details were leaked after the vendor didn’t pay the ransom.

Tags: hacking, patching, supply chain, vulnerabilities

Posted on March 23, 2021 at 6:32 AM10 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2021/03/accellion-supply-chain-hack.html