Shedding 25 Pounds in 20 Days: My Experience on the Front Lines of a Global Cyberattack

Tim Brown will always remember December 12, 2020.

This was the day SolarWinds, a software company, learned it had been hacked by Russia.

As the chief information security officer, Brown quickly grasped the impact. The hack could potentially affect any of the company’s more than 300,000 customers globally.

The breach enabled hackers to remotely access systems of customers using SolarWinds’ Orion networking software, which included the U.S. Department of the Treasury, the National Telecommunications and Information Administration, and numerous businesses and public organizations.


Brown mentioned he was “running on adrenaline” during the initial days following the breach.

Amid full-time remote work due to the COVID-19 pandemic, the company’s email system was compromised, rendering it unusable for internal communication.

“We stopped taking calls, and everyone came into the office for COVID-19 testing,” Brown recalled. “I lost 25 pounds in about 20 days. I just kept going.”

He has been featured on CNN and 60 Minutes, along with major newspapers.

“The world is on fire. We’re working to inform people about what is secure and what isn’t.”

Brown indicated the company moved to Proton email and Signal during the email breach, as he received calls from companies and government entities worldwide, including the U.S. military and the COVID-19 vaccine initiative, Operation Warp Speed.

“People prefer spoken communication to written communication. That’s a crucial lesson. You can document things, but people want personal interaction,” said Brown during a talk at Cybercon in Melbourne.

“They want to hear the nuances, so it’s vital to be ready for that kind of response.”

How did the cyberattack unfold?

The notification of the breach came via a call from Kevin Mandia, the founder of cybersecurity firm Mandiant, to SolarWinds’ then-CEO, Kevin Thompson.

Mandia informed Thompson that SolarWinds had “shipped contaminated code” within its Orion software, which aids organizations in monitoring their networks and servers for outages.

According to Mandia, the exploits in Orion were utilized to infiltrate government agencies.

“What you can see from that code is that it wasn’t ours, so we realized right away this was serious,” Brown recalled.




Brown stated that SolarWinds was not the main target of the hack but served as a “conduit to it.” Photo: Sean Davey/The Guardian

The Texas-based company discovered that 18,000 people had downloaded the contaminated product, and hackers, later attributed to Russia’s Foreign Intelligence Service, managed to inject it into Orion’s build environment where the source code is converted into software.

The news broke on a Sunday, and SolarWinds released the announcement before the stock market opened on Monday.

Initial estimates suggested that as many as 18,000 customers might be impacted, which later adjusted down to approximately 100 government agencies and businesses that were truly affected.

“I wish I had known that on the first day, but that’s the reality,” Brown says. “We weren’t specifically the target; we were merely a gateway to it.”

SolarWinds enlisted the help of CrowdStrike, KPMG, and law firm DLA Piper to respond and investigate.

Aftermath: heart attack

For the next six months, SolarWinds suspended the development of new features and redirected its team of 400 engineers to focus on systems and security to restore the company’s stability.

“We prioritized transparency—how can we ensure people understand what threats there are, how those actors operate, how they gather information, how they execute attacks, and how they withdraw?”

Brown noted that the company’s customer renewal rate dropped to around 80% in the aftermath but has since risen back to over 98%.

However, legal consequences soon followed.

In 2021, the Biden administration enacted sanctions and expelled Russian diplomats in response to the attack.

In 2022, SolarWinds settled a class action suit related to the incident for $26 million. The Securities and Exchange Commission (SEC) initiated a lawsuit against SolarWinds and Brown personally in October 2023, alleging that the company and Brown misled investors regarding cybersecurity measures and failed to disclose known vulnerabilities.




Mr. Brown has remained with SolarWinds since the cyberattack. Photo: Sean Davey/The Guardian

Brown was in Zurich when he became aware of the charges.

“As I ascended a hill, I felt out of breath, my arms were heavy, and my chest was tight—I wasn’t getting enough oxygen,” he recalled. “I made a poor decision and flew home. I couldn’t walk from the terminal to my car without pausing; it was a journey I had made countless times.”

He was experiencing a heart attack. Upon returning home, his wife took him to the hospital for surgery, after which he recovered.

“The stress continued to mount, leading me to think I was handling it well without proactively visiting a doctor,” he explained.

Now, Brown is advocating for companies facing similar crises to engage psychiatrists to assist employees in managing stress.


“My stress levels were at a peak, and I was really close to the edge, though the pressure had been building for a while.”

A proposed confidential settlement with the SEC was announced in July but still awaits approval. The finalization of the agreement has faced delays due to the U.S. government shutdown.

Mr. Brown has remained with SolarWinds throughout this entire ordeal.

“This happened on my watch, and that’s how I perceive it. There are factors that contributed, like a state-sponsored attack, but it still occurred under my supervision,” he reflected.

“I admit I can be stubborn, but it was paramount for us to navigate this entire process, and leaving before it was resolved wasn’t an option.”

Source: www.theguardian.com

Scientists obtain sharper images of fault lines posing a threat to the Pacific Northwest

A silent colossus lurks off the Pacific coast, threatening hundreds of miles of coastline with tsunamis and devastating earthquakes.

For decades, scientists have been warning about the possibility of a major fault line breaking off from the Cascadia Subduction Zone, a megathrust fault that runs offshore along the coast from northern Vancouver Island to Cape Mendocino in California. The next time this fault, or parts of it, breaks, it could upend life in Oregon, Washington, and Northern California.

Of particular concern are signs of great earthquakes in the region’s geological history. Many researchers have been pursuing clues about the last “big quake,” a magnitude 8.7 earthquake that occurred in 1700. They have pieced together this history using centuries-old tsunami records, Native American oral histories, physical evidence of saltwater-flooded ghost forests, and limited maps of faults.

But no one had ever comprehensively mapped the fault structure until now. The study published Friday A paper published in the journal Science Advances describes the data collected during a 41-day research voyage, in which the ship dragged a mile-long cable along the fault, listening to the ocean floor and piecing together images.

The team completed a detailed map of the subduction zone, stretching more than 550 miles to the Oregon-California border.

Their work will give modelers a clearer picture of the impact of a megaquake in the region — a megaquake that occurs in a subduction zone, where one plate pushes under another — and give planners a more detailed, localized view of the risks to Pacific Northwest communities, which could help redefine earthquake-resistant building codes.

“It’s like wearing Coke-bottle glasses, and when you take them off, they give you the correct prescription,” said lead author Suzanne Calbott, a marine geophysicist and research professor at Columbia University’s Lamont-Doherty Earth Observatory. “Before, we only got very blurry, low-resolution images.”

Scientists have discovered that subduction zones are much more complex than previously thought. They are divided into four segments, and researchers believe each segment could rupture independently or simultaneously. Each segment has different rock types and different seismic properties, which means some segments may be more hazardous than others.

Earthquake and tsunami modelers are beginning to assess how the new data might affect earthquake scenarios in the Pacific Northwest.

Kelin Wang, a research scientist with the Geological Survey of Canada who was not involved in the study, said her team, which focuses on earthquake hazards and tsunami risk, is already using the data to make predictions.

“The accuracy and resolution is truly unprecedented, and this is an incredible dataset,” said Wang, who is also an adjunct professor at the University of Victoria in British Columbia. “This will allow us to better assess risk and inform building codes and zoning.”

Harold Tobin, co-author of the paper and director of the Pacific Northwest Seismic Network, said the data will help fine-tune predictions, but it won’t change the untenable reality of life in the Pacific Northwest.

“It could potentially produce earthquakes and tsunamis that are comparable in magnitude to the largest earthquakes and tsunamis the Earth has ever seen,” said Tobin, who is also a professor at the University of Washington. “It looks like Cascadia could produce an earthquake of magnitude 9 or a little less or a little more.”

A quake of that magnitude could cause shaking for about five minutes and generate a tsunami up to 80 feet high, damaging more than 500,000 buildings. According to emergency planning documents:.

Neither Oregon nor Washington are adequately prepared.


To map the subduction zone, researchers at sea used active seismic imaging, a technique that sends sound waves into the ocean floor and processes the returning echoes, a method often used in oil and gas exploration.

They towed more than nine miles of cables called streamers behind the ship and used 1,200 hydrophones to capture the returning sounds.

“This will give us an idea of ​​what the conditions are like underground,” Calbot said.

The research vessel Marcus Langes docked in Seattle after a 41-day survey along the Pacific coast that allowed researchers to map the Cascadia Subduction Zone.
Courtesy of Harold Tobin

Trained marine mammal spotters would alert the crew to any signs of whales or other animals. Sounds produced by this type of technology could be disruptive and potentially harmful to marine life.

Calbot said the new research makes it even clearer that the entire Cascadia Fault won’t rupture all at once.

“The next earthquake in Cascadia could rupture just one of these segments, or it could rupture the entire boundary,” Calbot said, adding that some individual segments are thought to have the potential to produce a quake of at least magnitude 8.


Over the past century, scientists have observed only five earthquakes of magnitude 9.0 or higher, all of which were the kind of giant quakes predicted in the Cascadia subduction zone.

Scientists have compiled the latest insights into the 1700 Cascadia earthquake, based on records of an unusual orphan tsunami that was not preceded by any shaking in Japan.

“It would take a magnitude 8.7 earthquake to send a tsunami all the way to Japan,” Tobin said.

Those in Japan who recorded the event had no idea that the earthquake occurred across the ocean in what is now the United States.

Right now, the Cascadia subduction zone is eerily quiet. At other subduction zones, Calbot says, scientists often observe small, frequent earthquakes that make it easier to map the region. But that’s not the case here.

Scientists have a few hypotheses as to why. Wang said the region could be getting quieter as stress builds on the fault, and that time may be approaching.

“The interval between big earthquakes in this subduction zone is about 500 years,” Wang said. “It’s hard to know exactly when it will happen, but it’s certainly quite late compared to other subduction zones.”

Source: www.nbcnews.com

U.S. states and big tech companies clash over online child safety bills: Battle lines drawn

On April 6, Maryland passed the first “Kids Code” bill in the US. The bill is designed to protect children from predatory data collection and harmful design features by tech companies. Vermont’s final public hearing on the Kids Code bill took place on April 11th. This bill is part of a series of proposals to address the lack of federal regulations protecting minors online, making state legislatures a battleground. Some Silicon Valley tech companies are concerned that these restrictions could impact business and free speech.

These measures, known as the Age-Appropriate Design Code or Kids Code bill, require enhanced data protection for underage online users and a complete ban on social media for certain age groups. The bill unanimously passed both the Maryland House and Senate.

Nine states, including Maryland, Vermont, Minnesota, Hawaii, Illinois, South Carolina, New Mexico, and Nevada, have introduced bills to improve online safety for children. Minnesota’s bill advanced through a House committee in February.

During public hearings, lawmakers in various states accused tech company lobbyists of deception. Maryland’s bill faced opposition from tech companies who spent $250,000 lobbying against it without success.

Carl Szabo, from the tech industry group NetChoice, testified before the Maryland state Senate as a concerned parent. Lawmakers questioned his ties to the industry during the hearing.

Tech giants have been lobbying in multiple states to pass online safety laws. In Maryland, these companies spent over $243,000 in lobbying fees in 2023. Google, Amazon, and Apple were among the top spenders according to state disclosures.

The bill mandates tech companies to implement measures safeguarding children’s online experiences and assess the privacy implications of their data practices. Companies must also provide clear privacy settings and tools to help children and parents navigate online privacy rights and concerns.

Critics are concerned that the methods used by tech companies to determine children’s ages could lead to privacy violations.

Supporters argue that social media companies should not require identification uploads from users who already have their age information. NetChoice suggests digital literacy education and safety measures as alternatives.

During a discussion on child safety legislation, a NetChoice director emphasized parental control over regulation, citing low adoption rates of parental monitoring tools on platforms like Snapchat and Discord.

NetChoice has proposed bipartisan legislation to enhance child safety online, emphasizing police resources for combating child exploitation. Critics argue that tech companies should be more proactive in ensuring child safety instead of relying solely on parents and children.

Opposition from tech companies has been significant in all state bills, with representatives accused of hiding their affiliations during public hearings on child safety legislation.

State bills are being revised based on lessons learned from California, where similar legislation faced legal challenges and opposition from companies like NetChoice. While some tech companies emphasize parental control and education, critics argue for more accountability from these companies in ensuring child safety online.

Recent scrutiny of Meta products for their negative impact on children’s well-being has raised concerns about the company’s role in online safety. Some industry experts believe that tech companies like Meta should be more transparent and proactive in protecting children online.

Source: www.theguardian.com

Protecting the entire power grid from outages by rainproofing 1% of power lines

Damage from storms like Hurricane Harvey caused severe power outages to the Texas power grid.

Mark Ralston/AFP via Getty Images

Simulations suggest that storm sheltering just 1% of the power lines in a power grid can reduce the likelihood of a hurricane-induced power outage by a factor of five to one in 20. The demonstration, conducted on a mock version of the Texas power grid, could help improve the resiliency of power transmission systems around the world.

“The importance of different power lines to the overall system becomes clear only when studying the partial disruption of the power grid as the storm progresses,” he says. frank hellman at the Potsdam Institute for Climate Impact Research, Germany.

To identify the critical power lines most in need of protection, Hellman and his colleagues investigated how the power grid responds to widespread damage over time. They focused on the large-scale “failure cascade” that occurs after the initial storm damage. When power plants and transmission lines shut down to protect against further damage, secondary power outages can occur and increase the impact of a hurricane.

Researchers have determined that wind-related storm damage, such as damaged pylons and fallen tree limbs from gusts, and resulting damage to Texas during seven historic hurricanes between 2003 and 2020. simulated both a series of power outages that occurred on the power grid.

Rather than trying to predict individual power line failures, which can be caused by fallen trees or lightning strikes, researchers set each power line's probability of failure based on local wind speeds during each storm event. assigned. Their model maintains the same 20 critical transmission lines, where initial storm damage can cause a series of secondary line failures, even if they randomly vary the probability of failure for each line and rerun the simulation. Consistently identified electrical wires.

This experiment synthetic network model of the Texas Grid, which was previously developed by a team at Texas A&M University. It is not an exact replica of the actual physical grid, but represents the overall behavior of the grid. “None of the power lines in that grid are real power lines,” he says. adam burchfield at Texas A&M University. “Therefore, to see if these results hold true for the real Texas grid, we need to perform the study on at least a model of the real Texas grid.”

Power grid operators themselves can run this simulation with their own detailed power grid models, although independent researchers typically do not have access to such models for security reasons. Once you identify which specific lines are weak points, you can weatherize critical components of your grid.

Beyond Texas, such simulations can also model grids in other locations where similar storms have occurred. It says it “may provide an opportunity to validate the model and results.” Chuan Yi Ji from Georgia Tech in Atlanta was not involved in the study.

Hellman acknowledges that wind damage models have limitations. It does not take into account the possibility of further damage from flooding or how precautions grid operators can take to prevent power outages.

Still, Burchfield said the study's use of “different scenarios” to check the probability of outages in a realistic grid model further emphasized the study's main findings. “I think grid strengthening is a key element in making the grid more resilient,” he says. “And this paper shows that strategically choosing which transmission lines to strengthen is important to have the greatest impact on resiliency.”

topic:

Source: www.newscientist.com

The new Airbus A321neo plane from Delta Air Lines includes AirPod technology

Now listen to this.

cookie dough brands If you fly on Delta’s new Airbus A321neo, you can use Bluetooth technology to connect your Apple AirPods to Delta’s seatback TV screen.

Delta’s A321neo, which began accepting commercial flyers in May 2022, features smooth leather recliners in first class, wide privacy dividers between seats and 13-inch high-definition touchscreen monitors.

TikToker Elise Brulotte On my Wednesday trip from Seattle to Honolulu, I was captivated by the in-flight entertainment.

“Finally, I can now watch movies on my AirPods on Delta’s new plane,” Brulot, who co-founded Hot Take Cookie Dough with her sister, wrote in a text. on her TikTok.

“As someone who has never bought over-ear headphones, I’m already blown away. Game changer,” she emphasizes in the caption of her video, which has been viewed over 520,000 times on TikTok. .

“The A321neo is our first aircraft to offer Bluetooth connectivity, available in the first class cabin,” a Delta representative said in a statement.

Bluelott told the Post that he was happy to see Delta Air Lines “achieve something I’ve wanted for a while.”

“I wish more airlines would integrate this feature, but it seems like a no-brainer to me,” Brulot said. “I’ve never seen it on a plane before, so it was very refreshing! I’ll be looking for more from now on.”


Delta Air Lines began commercial flights with the Airbus A321neo in May 2022. Getty Images

As of NovemberDelta Air Lines operates 35 A321neos and has a contract to purchase 155 of the aircraft through 2027.

The 194-seat aircraft features 20 domestic first class seats, 42 Comfort+ seats and 132 main cabin seats.

The in-flight entertainment system is It said it was loaded There are over 500 movies and over 100 TV series.

Meanwhile, Apple launched AirPods, wireless Bluetooth earphones, in 2016.

Brulotte’s 300,000 TikToker followers shared their experiences with AirPod technology on other flights.

“I ate this on a United Airlines flight. It changed the game,” one flyer said.

“The new Virgin Airlines has this and I was very happy (lol),” laughed the next.

“We just did this on Emirates!” exclaimed a third.

Source: nypost.com