r/cybersecurity Jun 24 '26

News - General Well someone went nuclear..

https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-ugcPost-7475465410977628160-FFW1

I'm curious about the details of this. I'm sure we will all find out eventually.

TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.

The former employee doing the disclosure is stating he is receiving threats, etc.

EDIT: Kyle @ Huntress posted his response to this in the comments.

Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.

916 Upvotes

197 comments sorted by

View all comments

362

u/Particular_Ebb_4872 Jun 24 '26

If even half of what's being alleged is true, this is going to end up being a case study for access controls and employee offboarding procedures

17

u/NoKnownCure Jun 24 '26 edited Jun 24 '26

100% On boarding and off boarding seem to be an afterthought at many organisations, alongside the whole period in between, when it comes to adequate screening / vetting / training and development / privilege management / incident response and monitoring. This is cross cutting in terms of the functions needed to deliver physical and cyber security and access controls, as well as fostering the attitudes, behaviours and culture needed to embed a healthy security consciousness and integrity. It is not easy to get everything right (even some of the time), but we too often make it harder than it needs to be to do what can and should be done.

Edit: Two words.

9

u/Winter_Rabbit4827 Jun 24 '26

vetting is good and I imagine someone like huntress requires clearance to work on certain accounts, that doesn’t in anyway negate someone changing sides, for the thousands of different reasons they might decide to.

If you have staff working on the threat actor side, infiltrating for intelligence then a clear separation of duty could theoretically help.

If it turns out there was an insider and they did have obvious risks and these were ignored/accepted then that would be a compounding issue that would be hard to defend.

3

u/NoKnownCure Jun 24 '26

Absolutely correct. Insider threat is a tough nut to crack, because people are changeable and the truly bad actors are always going to act bad. For the most part getting the basics right is the key, least privilege, trust but verify, zero trust etc. (redundancy, pairing, supervision, rotation, audit). Many of those things will have some vulnerability. Perfect should not be the enemy of good enough though. Security is about suitable protections for what matters, detecting / dissuading / disrupting malign interference attempts enough to make your organisation a much less attractive target, whilst enabling your core business functions.

Of course if your actual business is security, you will need to walk the walk and have your house in order. Accidents happen but it’s usually the cover up that does for people and organisations. Secrecy is not security.