The ransomware group ALPHV, also known as BlackCat, reportedly social-engineered their way into MGM Grand’s computer systems in just 10 minutes, causing a shutdown of MGM Resorts International properties across the U.S. The ransomware group allegedly took hold of MGM’s computer systems in three simple steps, according to vx-underground. “All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk,” the organization wrote in a Twitter post. “A company valued at $33,900,000,000 was defeated by a 10-minute conversation,” it added.
The Cybersecurity and Infrastructure Security Agency (CISA) has published a new roadmap to help fortify open-source software security, including establishing CISA’s role in providing security support to the open-source software community, increasing visibility into the usage of open-source software, reducing risks to the federal government, and improving the overall cyber posture of the open source ecosystem. CISA plans to partner with open-source software communities and expand engagement and collaboration with international partners while developing a framework to help organizations conduct risk prioritizations for open-source software components.
And in good resources,
CompTIA has launched an Emergency Response Team (ERT) to provide real-time guidance to solution providers experiencing a cybersecurity incident or service disruption. The ERT is a group of dedicated CompTIA members who have either experienced a security incident or can guide solution providers who have been victimized. The service is free to businesses and can be accessed by calling (630) 678-8400. The ERT supplements an organization’s formal incident response relationships and provides support in areas such as employee well-being and health, along with experienced guidance.
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is offering free security scans for critical infrastructure facilities, such as water utilities, to help protect them from hacker attacks. The program identifies vulnerabilities or misconfigurations in internet-exposed endpoints and sends weekly reports with action recommendations.
Besides these great resources to leverage, I want to focus again on that social engineering angle. Consider what happened to MGM Resorts. A Linkedin search, finding someone, and coming in via the help desk. Now, as an IT provider, consider that YOU might be the help desk. This is an easy entry point. Far easier than technical entry. I’ve done bonus episodes about both corporate espionage like this and the coming voice security problem. It’s time to spend more time considering your policies here.

