Cattle mortality: why is everything dying at once?

I'm not writing this to troll. I read reviews on "The Register" and don't understand why the attacks have such severe consequences?
Why isn't the security paradigm for critical infrastructure being rebuilt?
Why do convenience and comfort dominate over security system add-ons?
Why is the entire enterprise security architecture being undermined in the name of mythical speed, mobility, "scalability, and flexibility"?
Have you noticed how airlines, holding companies, and communications companies are collapsing like dead cattle after being injected by attackers?
I've been reading this for years, and nothing has changed.
Okay, one internal link fails, or a frontline collapses at one point, but how can the entire state of Nevada collapse?
https://xakep.ru/2025/08/28/nevada-hack/
Perhaps you read the other day about how numerous state government organizations "fell"? But politicians hid it, and the X-wing told tall tales.

Have we really passed the point of no return? Have simple and obvious security solutions become obsolete? Why do automobile manufacturers connect industrial zones and workshops to this crap internet?
Why is IP telephony from production areas "released" to the internet?
Why are kitchens and food service areas connected to accounting and finance departments through EXPENSIVE corporate conglomerates?
We guarantee you, we provide you with services, we commit to you in the event of... blah-blah-blah...
All this is spelled out in contracts, yes. But when EVERYTHING crashes and downtime begins, the parties rush to court, and there begins a battle for money.
After all, how many times has all this failed?
Why has the world abandoned the idea of physically isolating departments from the general infrastructure? Yes, there is separation at the logical level,
there are containerization and virtualization systems.
But in practice, even companies that provide DDoS protection for other corporations fail. Have you read about this?
A digital storm record was just broken – over 1.5 Gpps.
Why has competition for profit ("time is money") between companies become more important than their own security?
"We'll lose the battle with our competitors if we don't introduce a convenient, fast logistics system," they say, the managers. Yes, and then, when
your logistics are disrupted, you spend months trying to fix it and lose millions of euros, dollars, pounds, and sterling per day due to downtime...

Or maybe it makes sense to force staff to switch to dot matrix printers and get rid of those AI-enabled, online-printing office publishing machines...
Maybe we shouldn't create "demilitarized" "rest areas" for employees, where they can connect their personal iPhones to the external network during breaks and connect with their grandchildren?
Or maybe you'll just go with them to McDonald's after work and have a Coke? Maybe we shouldn't connect branches with logical tunnels to ensure the isolation of administrative zones and enterprise sectors?
Has everyone seen the types of attacks on tunneled connections? There are dozens of them. And if you do connect, connect only the most essential.
Maybe we should eliminate excessive reporting and document flow via electronic communication channels?
Maybe it's time to completely eliminate all this cloud-based online document editing?
Maybe we should firmly block management's access to CCTV cameras from iPhones, so that the director only drinks his drink on Caribbean beaches,
and not surf the company intranet and stay online?
When you arrive at work, the security administrator will make you a video that will last a few hours, and you'll watch it from the hard drive on your work PC, in your office, not at home in the kitchen.

I think that INFRASTRUCTURE is the ultimate target of attacks today, not the individual product, as it used to be. That's why branches on multiple continents are already falling.

Today, millions of devices can be compromised from Google Stores in the shortest possible time (a day, two, or three).
Today, it's possible to orchestrate a targeted tsunami of these infected Android phones onto a company's internal resources.
But the companies themselves install gateways and multimedia, multi-format converters on their telephone networks, sucking the ready-made Android abomination into the organization's ecosystem. It's convenient, we have multi-format support, we can hold online conferences, and...
And then the company is stuck in a "Z" position for several weeks: like the British division of Jaguar Land Rover...

The attacks of 30 years ago were aimed at mass infection or the incapacitation of a large number of PCs and servers.
These are classic Trojan viruses, phishing, and other "probes" in the form of firmware and hardware chips in network equipment.
Yes, that's right. But back then, there weren't such bandwidth and broadband channels, bitrates, data centers, or clouds.
Today, a tsunami of banking is wiping out banks. This happens regularly in Ukraine (Monobank, PrivatBank, etc.).
Only the media keeps telling us that "maintenance work is underway," "we're fixing the problem after the update," and blah-blah-blah.

So, to finish my nonsense, I want to say that a conceptually new wave of attacks is already sweeping the world:
blockchain + crypto exchanges + clouds + compromised data centers with powerful resources are already actively involved.
And then there's mining and colossal energy consumption!
I mean, how many powerful entities are at risk! It's not just phone company phreaking and a call from a payphone
to the White House (80s-90s-style attacks, just for fun).
So, data centers could become a springboard for cybercrime, launching an attack that could bring down
all connected cyberspace.

There was a power outage in Europe recently... a wave came from Italy or something like that...
Maybe it wasn't a hack, but simply a test of switching from the main power grid to alternative sources, but the fact is – countries collapsed!
So why the hell did you connect everything to one chain without calculating the risks?
Hacking a data center connected to the banking sector, an agricultural holding, the real estate sector, and logistics – that's just crazy.
This is exactly what we're reading in the news today.
Can you imagine the POWER of this grader aimed at domestic cats?

Today's cybersecurity approaches are outdated and don't work, if I'm reading news like this.
Do you feel the difference between the hacking eras?

Thanks for reading.
 

There seems to be a hell of a lot of it going on, that's for sure. Industrial sabotage? Cyber warfare? Organized crime? Kids in bedrooms??
All four at the same time??? :oops: 😫
 
Have you noticed how airlines, holding companies, and communications companies are collapsing like dead cattle after being injected by attackers?
Yes. Privatise profits, socialize losses. Same old game. Because such an attack has "a considerable amount of criminal energy", what they use as a term here in the news for such things. Because then, insurance will pay. Labeling it (more correctly) "penny pitching stupidity" would leave the C-level at the mercy of the share holders. That would be unfair, noooo?

I'm holding the position that for such deeds the private assets of the responsible clowns should be on the table, along with everything they shifted to their wife.
when
your logistics are disrupted, you spend months trying to fix it and lose millions of euros, dollars, pounds, and sterling per day due to downtime...
You need to change some laws here. A CEO can be sued by the shareholders when he does not everything legal (as in - not likely being found out about) to increase value. It does not serve anything else but the shareholder value. We would need to make cooperations liable for damages caused to every person affected, customer or not. Then the calculation would maybe shift, and we might see results.
 
Looks like analogue of scheme "organize migration for organization fightings against migration for putting some ideologies into legal field" but in digital world. Who will be "saver"? And what will be legalized by this "saver", what ideology?

Syndicates want to replace governments by themselves, so... it will be hot century.
 
No one cares about code correctness anymore. So much of our proprietary crapware (and a decent amount of OSS too) is unaudited, bloated and is simply inefficient spaghetti code that is loaded with unfound security vulnerabilities, and with the advent of AI, and it being trained on crap code, the problem will just get worse. I personally make sure all of my code is readable and clean. I can't imagine an entire (large) program being contained in one badly-organized main.java!
 
The flying spaghetti monster always wins in the end... 😁

1758659242734.png
 
Maybe they used the hi-viz jacket trick...
Looks more like the UN was the target. For officials, wouldn't DC be a better place? Also, afair, you don't need such a farm to disrupt the network. Smells more like a "local terrorist group".
 
1758705653666.png


Something doesn't add up. It says they found "300 servers". Suppose they found 300 1U servers (assuming the "servers" weren't raspberry pi's!) .... say 20 to a rack... that's 10 full height racks. Then you need power distribution, power supplies, network switches, network cabling, KVM's, perhaps some UPS's, probably some central storage... and in addition the 100000 SIMs as in the photo above. This was a large scale setup. How did they get the mains power? An install like that would be quite an impressive setup for a medium sized commercial company! It's millions of dollars worth of kit, set up in "disused buildings". You probably need 3-phase power and local power regulation, you can't run that lot off the domestic mains. It doesn't add up. It's certainly not a few teenage hackers sitting in their bedrooms with laptops. Well, I expect a lot of the details are being kept secret. But someone has put a lot of money into that, and you need a multi-man team to build it.

Of course it doesn't tell you what the "servers" were, maybe they really were raspberry pi's...
 
Why isn't the security paradigm for critical infrastructure being rebuilt?
Why do convenience and comfort dominate over security system add-ons?
Why is the entire enterprise security architecture being undermined in the name of mythical speed, mobility, "scalability, and flexibility"?
Have you noticed how airlines, holding companies, and communications companies are collapsing like dead cattle after being injected by attackers?
I've been reading this for years, and nothing has changed.
Maybe you need reading what is actually in the legal pipline:


 
It says they found "300 servers". Suppose they found 300 1U servers (assuming the "servers" weren't raspberry pi's!)
300 SIM servers, those aren't the typical 1U "pizzabox" servers you might be thinking off.

The devices in the picture look like one of these: https://www.discoverytelecom.eu/catalog/5683.htm
That's a SIM server, there's 8 of them in the picture.

Edit: Weird, link suddenly leads to a 404. Lets try this way:
 

Attachments

  • simserver.png
    simserver.png
    231.2 KB · Views: 46
Yes, I must have got the wrong end of the stick thinking it would be 1U servers. I mean... a rack mount unit is what I call a 'server' anyway, not something like a mini board. So yes, I've probably got the wrong end of the stick, it just doesn't add up if they are 1U's, it has to be something much smaller.
 
Granted, telecom equipment is weird. Has its own way of configuring too, looks and feels totally foreign, that's mainly because its based on stuff that predates computers and networking.
 
Looks more like the UN was the target. For officials, wouldn't DC be a better place? Also, afair, you don't need such a farm to disrupt the network. Smells more like a "local terrorist group".

US federal government communication is probably prepared to deal with this sort of threat (unless the president just uses his personal cellphone...).

Presumably most or almost all UN people coming into NYC have to rely on the cellphone network with at best an encryption layer on top.I have low expectations for average standard of security here.
 
Back
Top