Chinese hackers counted on no one clicking 'update' in decade

关于我们 2024-09-22 12:32:57 22571

Uh, maybe stop asking your computer to remind you tomorrow.

The Department of Justice unsealed an indictment Tuesday alleging two hackers worked in collaboration with the Chinese Ministry of State Security to steal everything from video game source code to weapons designs from hundreds of companies around the globe. And, if the indictment is to be believed, the hackers were able to do much of this by exploiting people's natural laziness about updating their software.

Notably, the indictment claims, the two hackers — Li Xiaoyu, 34, and Dong Jiazhi, 33 — had a decade-long spree that succeeded, in large part, because people and companies often don't immediately download and install software patches as soon as they become available.

"[To] gain initial access to victim networks, the defendants primarily exploited publicly known software vulnerabilities in popular web server software, web application development suites, and software collaboration programs," reads a DOJ press release. "In some cases, those vulnerabilities were newly announced, meaning that many users would not have installed patches to correct the vulnerability."

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

The two stand accused of mixing profit-driven exploits in with more traditional state-sponsored hacks. In addition to supposedly attempting to extort at least one company for around $15,000 worth of cryptocurrency, they allegedly stole personally identifiable information (PII) from educational companies as well as info on military communications systems and counter-chemical weapons technology. They also, the indictment alleges, helped the Ministry of State Security break into email accounts belonging to peaceful dissidents, human rights groups, religious figures, and a former Tiananmen Square protester.

Oh yeah, and the press release notes the two also "probed for vulnerabilities in computer networks of companies developing COVID-19 vaccines, testing technology, and treatments."

SEE ALSO: Why you should absolutely worry about the anti-privacy EARN IT Act

The trade secrets supposedly stolen by Xiaoyu and Jiazhi, former college classmates, are said to be worth hundreds of millions of dollars. The two are charged with conspiracy to commit computer fraud, conspiracy to commit theft of trade secrets, conspiracy to commit wire fraud, unauthorized access of a computer, and seven counts of aggravated identity theft.

While it's unlikely the two will ever face jail time in the U.S., maybe now you'll actually update your software the next time your computer prompts you.

Related Video: It's surprisingly easy to be more secure online

本文地址:http://o.zzzogryeb.bond/html/60b899166.html
版权声明

本文仅代表作者观点,不代表本站立场。
本文系作者授权发表,未经许可,不得转载。

全站热门

Slot extends perfect Liverpool start

柑香四溢!德庆贡柑果园成国庆热门“打卡地”

员工年底离职公司拒付年终奖 法院判公司须支付

大奖等你拿!“绿美广东”随手拍火热进行

Ford can make your Mustang Mach

广东柚香飘央视,给全国人民带来甜蜜“柚”惑

努力营造安全畅通交通环境

努力营造安全畅通交通环境

友情链接