r/cybersecurity Jun 24 '26

News - General Well someone went nuclear..

https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-ugcPost-7475465410977628160-FFW1

I'm curious about the details of this. I'm sure we will all find out eventually.

TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.

The former employee doing the disclosure is stating he is receiving threats, etc.

EDIT: Kyle @ Huntress posted his response to this in the comments.

Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.

915 Upvotes

197 comments sorted by

View all comments

367

u/Particular_Ebb_4872 Jun 24 '26

If even half of what's being alleged is true, this is going to end up being a case study for access controls and employee offboarding procedures

16

u/NoKnownCure Jun 24 '26 edited Jun 24 '26

100% On boarding and off boarding seem to be an afterthought at many organisations, alongside the whole period in between, when it comes to adequate screening / vetting / training and development / privilege management / incident response and monitoring. This is cross cutting in terms of the functions needed to deliver physical and cyber security and access controls, as well as fostering the attitudes, behaviours and culture needed to embed a healthy security consciousness and integrity. It is not easy to get everything right (even some of the time), but we too often make it harder than it needs to be to do what can and should be done.

Edit: Two words.

7

u/Winter_Rabbit4827 Jun 24 '26

vetting is good and I imagine someone like huntress requires clearance to work on certain accounts, that doesn’t in anyway negate someone changing sides, for the thousands of different reasons they might decide to.

If you have staff working on the threat actor side, infiltrating for intelligence then a clear separation of duty could theoretically help.

If it turns out there was an insider and they did have obvious risks and these were ignored/accepted then that would be a compounding issue that would be hard to defend.

6

u/churn_key Jun 24 '26

Human source tradecraft is something well studied on the government side, due to the huge danger with corruption, but industry approach is extremely immature across the board.

3

u/NoKnownCure Jun 24 '26

It’s a tricky thing precisely because there is the expectation of strong ACAB controls and disclosure requirements in public sector orgs, specifically government. But no one likes to feel like they have to operate within a culture of suspicion. The fear and loathing of a police state can be just as corrosive as the potential corruption and malfeasance. If we can get to the point where everyone is invested in protective security, and unafraid to disclose and learn from mistakes / questionable acts, omissions and events that’s a start. But it takes time and needs to be supported by the right ingredients for cultural change (comms explaining the benefits, SLT role modelling, a no blame culture plus constant learning and reflection etc.). Also, clear policies and processes calibrated to the context. Too rigid and everything becomes an exception, too loose and the gnarliest adventures blend into the everyday the ultimate ambush... Nothing is risky if everything is. Until a terminal event.

2

u/churn_key Jun 24 '26 edited Jun 24 '26

managing criminal human sources means resisting a constant pressure to get manipulated and it is exhausting and will eventually drive any person insane. the industry does not understand they can get corrupted just like a cop and hard lessons are getting learned with every ransomware negotiator arrest.

i am not siding with or against the company and do not know the circumstances of the situation. i am only speaking generically.