<a href="https://blog.fefe.de/?ts=a71ea9ca">[l]</a> Old and busted: Hacker klauen US-Geheimnisse via Kaspersky.<p>New hotness: <a href="https://www.theguardian.com/australia-news/2017/oct/12/secret-files-on-jets-and-navy-ships-stolen-in-extensive-and-extreme-hack">Hacker klauen US-Geheimnisse via australischem Defense-Contractor</a>. Das geilste Detail steht beim Guardian gar nicht drin, nur bei <a href="https://www.wsj.com/articles/cyberattack-captures-data-on-u-s-weapons-in-four-month-assault-1507806261">Paywall-WSJ</a>, aber man kann es gerade so sehen in den ersten Zeilen:<blockquote lang="en">Using the simple combinations of login names and passwords “admin; admin” and “guest; guest” and exploiting a vulnerability in the company’s help-desk portal, the attacker roved the firm’s network for four months.</blockquote>

