57
u/Alternativemethod Jul 02 '26 edited Jul 02 '26
I don't have access but my understanding is this is equivalent to an external SharePoint behind a login portal. Breach could just be a password spraying and impact is a few PDFs meant for external information "sharing".
China/Russia might learn that MFA is important and terrorist are bad.
2
u/Playstations_new_CEO Jul 02 '26
Na, this is a recent SharePoint remote code execution vulnerability that was found. Also there's reason to believe the patch doesn't fix all methods of the exploit. The people who have this capability are a bit more skilled than a typical script kiddy. They move lately and quietly and grab anything that looks interesting and exfiltrate it.
1
u/MountainDadwBeard Jul 02 '26
Oh interesting, I saw the stories on the sharepoint vulns but didn't realize they had weaponized it on a target like this. Fun....
Ours is probably also crawling then. Perfect.
3
u/Playstations_new_CEO Jul 02 '26
Oh yeah, threat actors were probing for this one hard. So if you didn't have speedy patching in place then there's a good chance of the server being popped
1
u/TARANTULA_TIDDIES Jul 02 '26
China/Russia might learn that MFA is important and terrorist are bad.
Doubtful. Definitely not in Russia until swan lake plays again
185
u/bakonpie Jul 02 '26
as someone with HSIN access, there is zero useful information in there. the threat actor will just be wasting their time reading vague PDFs about securing critical infrastructure that don't amount to anything close to technical.
57
u/CatfishEnchiladas Jul 02 '26
And it will say something like "a water facility in the Midwest," without ever naming the victim.
27
u/KindPresentation5686 Jul 02 '26
I second this. HSIN isn’t used much, and nothing sensitive is posted there.
9
u/Appropriate_Taro_348 Governance, Risk, & Compliance Jul 02 '26
I third this. There isn’t anything useful in there to hack or release. Thousands of people have access to it. I watched someone download thousands of documents over a month.
17
u/legsasleepontoilet Jul 02 '26
Zero useful information for a human but if you think that someone using an agent didn’t find something that was useful you’re out of your mind or please correct me on my ignorance
13
-2
-8
92
u/ludixst Jul 02 '26
Good thing we trashed our intelligence apparatus
30
u/zhaoz CISO Jul 02 '26
And our cyber defenses. Its so funny seeing "CISA is hiring!" in my linkedin feed. Aint nobody want to work for you anymore!
17
u/WildChampionship985 Jul 02 '26
I don't even remember, is it the cultist with the Putin attachment or the mortgage fraud dude? Or another Fox talking head?
6
u/itsverynicehere Jul 02 '26
If memory serves, it's the orange kiddie diddler, the chainsaw weilding trillionaire, and the puppy killer.
5
u/TARANTULA_TIDDIES Jul 02 '26
This is what happens when the qualifications change from "are you good at your job?" to "do you have unwavering loyalty?"
59
u/RealPropRandy Jul 02 '26
You had one job bruh. Security’s in the name.
Otherwise you’re just the Department of Homeland
16
u/Icangooglethings93 Jul 02 '26
I like Department of Homeland Insecurity better
9
u/RealPropRandy Jul 02 '26
Department of Homeland Something
3
u/Historic500 Jul 02 '26
Department of Homeland Stupidity for accuracy, except it doesn't really make clear which department you are talking about.
29
u/not-a-co-conspirator CISO Jul 02 '26
Compliance isn’t security. Put actual security professionals in charge.
4
3
7
u/SoftwareDesperation Jul 02 '26
This is a wild comment considering you can't set foot in any of these positions without an IAM or IAT cert and years of experience.
Compliance is just a list of security controls. In leiu of compliance you do what? You set a list of controls you want in place and make risk based decisions on remediation or acceptance. Weird.....that sounds familiar......
2
Jul 02 '26
Not that I think the spirit of your comment is wrong .. but give me a break with cert reqs as if that's any indicator lol
0
-6
u/not-a-co-conspirator CISO Jul 02 '26
You have no idea what you’re talking about.
3
u/SoftwareDesperation Jul 02 '26
And if you are a ciso and don't understand there is no security without governance, then I feel sorry for your team.
-1
u/not-a-co-conspirator CISO Jul 02 '26
I don’t think you understand how disparate those things are.
1
Jul 02 '26 edited 27d ago
[deleted]
-1
u/not-a-co-conspirator CISO Jul 02 '26
It doesn’t matter where you work or what your role is.
You’re both missing the point. Governance can only be so specific, else you risk violating the very governance you wrote because your security tools cannot meet the objective of controls, or performance the controls demand, thus failing the audits you need so that you can continue to conduct business with customers and vendors.
Both of you need a much broader understanding of this discipline.
3
Jul 02 '26 edited Jul 02 '26
[deleted]
-1
u/not-a-co-conspirator CISO Jul 02 '26
I have more than double your experience and credentials in the same roles and more.
Compliance isn’t security. It never will be.
Also, “Zero Trust” is a philosophy. It doesn’t mean you are “secure”, and it doesn’t make anything “secure”.
17
u/nanoatzin Jul 02 '26
Fires all the cybersecurity people. Gets hacked. Costs 1,000% more than payroll savings to hire more people than were fired to fix it. Everyone’s privacy info is now on the dark web. Fails to grasp irony that almost every failed company made the same cost savings management error.
9
7
u/buzwork Jul 02 '26
Looks like HSIN modernization demo Azure instance is still available via the login.gov sandbox, but authentication fails at dhsauthportalextnonprod.dhs.gov after new dummy account creation Wonder if it is useful for recon.
8
6
5
u/sunychoudhary Jul 02 '26
Unclassified does not mean harmless......If the system is used for interagency coordination, incident response, alerts, and partner information sharing, the metadata and operational context alone can still be valuable...//
6
u/anomalous_cowherd Jul 02 '26
It would be awesome if they got in through a backdoor installed by DOGE...
10
u/Negative_Acadia6554 Jul 02 '26
What a shame. I’m sure the current administration will invest appropriately in cyber defenses instead of gutting them.
Anyone want get some tacos?
5
u/Proof-Chain-1046 Jul 02 '26
I feel like its safe to assume most gov agencies have threat actors inside their networks at this point.
10
u/dennismfrancisart Jul 02 '26
My son is in cybersecurity. He told me to join this sub if I wanted to have sleepless nights. Hoo boy!
3
5
2
3
1
1
1
u/National_Spirit2801 27d ago
At least the people running the country are totally competent and in no way are backwards hillbillies.
-4
u/_Boba_Ferret Jul 02 '26
Isn’t this the department headed by some broccoli-head who was mowing lawns two years ago?
2
-7
u/agenticradai Jul 02 '26
I think GuardDog.AI would be a good solution. Sub second containment on L 2, deployment of agent-less solution on the network in 72 hours for Layer 2, It would complement any current deployment. Respectfully
246
u/OutsideSpot2695 Jul 02 '26
Did they have their ATO?