https://cyberintel.substack.com/p/doge-exposes-once-secret-government
Usual preface, sharing strictly and solely from a security interest POV to the exclusion of everything else. Originally posted Feb 9th, and while one may be quick to jump on the “January 8, 2025” start date, IF the systems listed are exposed – and continue to be exposed – as specified, the supernova-level security f**kup should be beyond “Are You Fscking Kidding Me?” levels :
Nuclear Risks
Between January 14 and February 8, servers belonging to Lawrence Livermore National Laboratory, Los Alamos National Laboratory, Thomas Jefferson National Accelerator Facility, and Fermi Accelerator National Laboratory have been found with Remote Desktop Protocol (RDP) services exposed to the public internet. This grants malicious actors the opportunity to hack into servers hosting sensitive nuclear research data, a golden egg for spy agencies across the globe.
Unleashing AI on sensitive government data
My investigation also revealed government servers directly interfacing with AI products, creating yet another disturbing risk to national security that is extremely difficult to reverse or mitigate. …
Treasury Department …
Comptroller of the Currency’s Citrix NetScaler Gateway – enables remote access to internal applications, desktops, and data. It acts as a VPN (Virtual Private Network) or proxy for users connecting to a corporate or government network. Exposing this gateway to the Internet makes it a highly attractive target for Russia- and China-sponsored hackers.
The U.S. Treasury Inspector General for Tax Administration (TIGTA) is responsible for investigating fraud within IRS programs, with divisions fighting cybercrime, fraud, and insider risk. On January 14 and continuing to present, TIGTA’s server used for conducting meetings are publicly exposed.
The Treasury Department’s Office of Inspector General’s Outlook Web login page is now publicly exposed. This allows attackers to attempt brute force password attacks. Once inside, hackers could exploit CVE-2024-21413 to send malicious emails that further compromise government systems. Another Treasury mail server is observed here.
Regards