Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Cybersecurity Experts React To New Yahoo Developments
News & Analysis

Cybersecurity Experts React To New Yahoo Developments

ISBuzz TeamBy ISBuzz TeamSeptember 30, 2016Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Rubrik Admits Data Theft In GoAnywhere Zero-Day Attack
Rubrik Admits Data Theft In GoAnywhere Zero-Day Attack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Researchers at InfoArmor published the new findings this morning, based on extensive analysis of collected threat intelligence from various dark web sources conducted to clarify the motivation and attribution of the key threat actors. The data theft of the Yahoo customer database may be the key in several targeted attacks against US Government personnel, which resulted after the breach of account information on affected high-level officials in the intelligence community, which occurred in October 2015.

Jonathan Sander, Vice President of Product Strategy at Lieberman Software:

Jonathan Sander“The fact that the suspects in the Yahoo breach are both nation states and criminals shows the rising sophistication and power of organized crime in the cyber landscape.

To crack one of the largest names on the Internet would take massive resources – even if the exploit was simple the research to uncover and take advantage of it would be significant.

For most security experts, that points right to a state level actor, but the criminals are getting so sophisticated so fast it’s hard to be sure. The other thing that may be at play is the shadowy nature of cybercrime. It’s easy to see people slipping from state level groups to the organized crime side – and back. Could it be that a state actor contracted a criminal organization to do the job? Who knows.”

 John Gunn, Vice President at VASCO Data Security: 

John-Gunn“No one should make the mistake of assuming that criminal hacking organizations are not coordinating their efforts with state-run hacking teams before an attack or sharing their stolen data after a breach.

Whether the attack was state sponsored or a criminal group, the results are the same, and the increased risk to half a billion people is the same, and the need for the online world to finally move away from passwords is the same. Now that mobile phones are enabling hassle-free multifactor authentication, the move away from passwords will accelerate.”

Mark Wilson, Director of Product Management at STEALTHbits Technologies:

mark-wilson “Criminal hackers make far more sense than state sponsored in the case of the Yahoo breach. State sponsored would suggest either a show of power or an attempt at disruption of service. Whereas a criminal act backs up the fact that personal data is valuable.

Hack Joe Public’s Yahoo credentials and you likely have the password to most of their online personas.  Gain access to Joe Public’s mailbox and you will find a complete picture of their interests, financial history, social life and a smorgasbord of other useful information.  All of which can be used to socially engineer fake online personas, credit applications and probable responses to any question and answer profiles. I’m sure we’ll be hearing about the fallout of this epic scale hack for years to come.”

Brad Bussie, CISSP, Director of Product Management at STEALTHbits Technologies:

Brad-BussieIt appears we are in the middle of a new offensive targeting our government and military.

Cyberattacks against large targets have traditionally been set, forget, and react on compromise. Look at ransomware for instance. This technique blasts out at much virulent content as possible and waits for the infected to start looking for a cure.

What we seem to be looking at with the Yahoo breach is different. It appears that the cybercriminal (nation state or otherwise) is beginning to play the long game. If a compromise back in 2014 is being linked to espionage in 2015 and now in 2016, we have a serious problem.

The problem is simple; passwords are no longer an effective means of protecting credentials and data. It is going to take a significant overhaul to fix the password issue. The industry has been buzzing about how to fix the password equation for several years so I won’t rehash it here.

What does need to be considered is, when is enough going to be enough? 500 million accounts seems like a good place to draw a line in the sand and effect some real change.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}