Incompetence, part one
You work in IT. It’s Saturday. You wake up to news of a vulnerability being exploited in the wild for a product your company uses. You take a deep breath, log in, check, and your heart sinks as you realize your product checks all the boxes for exploitable configuration.
Sigh. You’re part of a global team and also have a personal event that you’re not going to miss. You check the time, it’s early morning on the East coast, and you have less than an hour till you have to drive. Upgrading all the vulnerable devices to the patched version is going to take a lot longer than you have, plus there’s this thing around change control and new protocols you’re supposed to use before making impactful changes. And you’re not on call.
You decide you’re going to raise the alarm to your team, provide the info you have, and trust that they can pick up from there. You’ll also start the download of the patched software on all the impacted devices, at least you save a step. You put all this in an initial email, include links and all, then follow up with a second one with some additional notes and your updated progress. Then you leave.
And you come back that evening to several people telling you that they’ve already looked at this [you silly] two weeks ago and it’s not impacting us, and that while it may make sense to upgrade, I guess (and you can read the patronizing eye roll in the wording, it practically jumps at you), it’s at best a low priority thing.
You read and you wonder if you’ve lost your mind. You’re just an engineer, albeit with a darn good track including in similar vulnerabilities, and there’s enough condescension in that email chain to make you doubt yourself.
But you take a deep breath and then one more and click all three links that you sent to your team for their review. Turns out you mistakenly added one article that points to another vulnerability from the same vendor thats also now being exploited in the wild but to which you’re imune. The other article and the vendor CVE page were right. You had been frantically trying to log in, download, search, screenshot, confirm, type all at the same time in a very short time, which you explained as well, managed to grab the wrong news piece, yet that didn’t matter.
Your team and the higher ups in the chain preferred to tell you in writing that you’re just a scaredy silly little cat who jumped up at nothing at all rather than look at what you typed and all of the info you provided, especially in light of your track record there.
And they have now wasted over ten hours not doing anything. Well - anything other than talk down at you, and there were multiple ones who took the opportunity to carve a few minutes out of their Saturday to do so. Hm wonder what would’ve happened had they actually read what you wrote.
So you don’t bother with a hello, just hit reply all and succinctly mention that there are in fact two vulnerabilities and you’re very vulnerable for one of them and not at all for the other, then sign off mumbling something about bumbling idiots under your breath.
What do you think the attackers have been doing during all this time?
