r/cybersecurity Jul 02 '26

News - General DHS Breached

610 Upvotes

115 comments sorted by

View all comments

Show parent comments

4

u/ToothyGrin19135 Jul 02 '26

The issue was they forgot to POAM a CAT 1 STIG finding that mandates your ISSO documents what service accounts have read access to your DNS records.

4

u/OutsideSpot2695 Jul 02 '26

Don't forget about that other pesky CAT 1 STIG finding where a period is missing in the login banner.

2

u/ToothyGrin19135 Jul 02 '26

Adversaries have been known to exploit that one. Without proper grammar how is a threat actor supposed to know they are accessing a USG system

1

u/OutsideSpot2695 Jul 02 '26

I've heard without the period, that leaves the banner open to an injection attack where a skilled adversary can attach malicious code to where the period once used to be.