
Tales from the SOC: Never mix bleach with vinegar | S1 Ep002
When you come across a threat that seems mundane at first glance, is it OK to let AI try to mop it up on its own?


You’ve got to love SEC filings in which mega-rich, super-huge companies admit they’ve suffered a “cybersecurity incident.”
To you and me, a cybersecurity “incident” probably involves inadvertently clicking a dubious link, reaching a phishing site, but bailing out in time and then quickly double-checking that no harm was ultimately done.
Or it’s where you accidentally messaged friend X directly, when you really meant to moan about X behind their back to mutual friend Y, thus dropping all three of you into a cyber-awkward social standoff.
If our entire home network were trashed and then blasted offline by cyberattackers, we probably wouldn’t consider that an “incident,” but would reach for words such as crisis, disaster, wipe-out, and many other phrases not suitable for repeating on a family-friendly website.
But for Boston Scientific, a $20-billion-a year healthcare giant in the US, their latest reportable “incident” involves an attack against “certain of its information technology systems that has resulted in a global disruption to the Company’s operations.”
As Irish cybersecurity luminary Brian Honan reported yesterday, “This explains why staff in the Irish operations have been told to work from home.”
Boston Scientific continues:
The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders. While the Company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known.
Given the level of operational disruption, this feels like a ransomware attack where critical files across the network were deliberately scrambled to stop users doing their jobs, followed by an extortion note demanding money for decryption keys to recover the ruined files and get business back on track.
Or it might have been a straight-out data breach, followed by a blackmail demand “promising” to “delete” the stolen information in return for a cryptocurrency payment, leading the company to take its own systems down in the hope of stopping the criminals from continuing their attack (for example, by scrambling files for additional leverage, or simply out of spite if the company refused to pay).
We don’t know exactly what happened yet, and apparently Boston Scientific doesn’t know either, so let’s give them the benefit of the doubt for now.
The amusing bit is the concluding sentence of the SEC report, which says, “[T]he Company has not yet determined whether the incident is reasonably likely to have a material impact on the Company.”
Global disruption? Customer interactions halted? Staff sent home? No way to know how long it will take to fix?
Sure sounds like an impact, if you ask me.
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

When you come across a threat that seems mundane at first glance, is it OK to let AI try to mop it up on its own?

For many, the metaverse represents an idyllic future. Users can delve into a fully immersive virtual world, where geographic and physical barriers are removed. They can develop a perfectly crafted online identity, in the form of an avatar, which can move through various virtual environments to work, play games, shop, and socialize. Yet, while many are excited by the development of the metaverse, some are concerned about the cybersecurity risks it poses. Cybercrime is already a common occurrence. In fact, […]

Citrix patched its NetScaler products two months ago, but CERTs are still begging companies to update…

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






