Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


01:03 PM
Fritz Nelson
Fritz Nelson
Connect Directly

McAfee Stews; HP Speculation Brews

McAfee takes heat for fear mongering, while HP watches its future predicted. One scenario envisions an Oracle takeover.

InformationWeek Now--What's Hot Right Now

With well-publicized security breaches on the rise, business is good for vendors hawking security solutions. The danger, of course, is the hawking part. It has always been a tricky business for technology providers tempted to play up the latest problems. The fear mongering can seem self-serving, like a doctor trumpeting the latest flu virus to drum up some seasonal business. For the second time this year, McAfee finds itself under fire in the security community for just such tactics.

As InformationWeek's Mat Schwartz reports, researchers at Symantec, and the outspoken Eugene Kaspersky, CEO of Kaspersky Labs, have now downplayed the sophistication of "Operation Shady RAT." That's the widespread advanced persistent threat (APT) attack, brought to light by McAfee, that allegedly continued for five years and targeted intellectual property from 70 government agencies in 14 different countries. Kaspersky calls out the McAfee conclusions in his blog post "Shoddy RAT." That McAfee report was featured in a lengthy exclusive in the most recent issue of Vanity Fair.

Schwartz writes: "According to Kaspersky, the malware used in the attack was widely known, but relatively unsophisticated, and would be worth just a few hundred dollars on the black market, compared with top botnets, which might fetch $2,000 to $3,000." Schwartz cites similar statements from Symantec researchers, and a rebuttal from McAfee.

When McAfee first revealed "Operation Shady RAT," Dark Reading's Kelly Jackson-Higgins detailed some of the surprising findings, including those from other security researchers--for example, some of the tools the hackers used to hide their whereabouts. Already, security researchers were saying that the Shady RAT findings were nothing new. Jackson-Higgins also reported that the hackers used steganography, "a relatively rarely deployed technique for hiding malicious code or data behind image files or other innocuous-looking files."

The timing of McAfee's report was not a coincidence--right before Black Hat, one of the biggest security gatherings of the year (disclosure: Black Hat is part of UBM TechWeb, also the parent company of InformationWeek).

But this is not the first time McAfee has used a hot security news cycle to generate attention, and not the first time it has come under question for doing so. Earlier this year, right before the RSA Conference in February, McAfee put out a report on Night Dragon, another series of APT attacks going back to 2008. "According to the report," Dark Reading wrote at the time, "Night Dragon combines a variety of attack techniques, including social engineering, spear-phishing, Windows vulnerability exploits, Active Directory compromises, and remote administration tools (RATs)." These attacks reportedly came from Beijing.

As with Shady RAT, several researchers pointed out that the Night Dragon attacks were nothing new.

While the timing of McAfee's reports is opportunistic, many inside the security industry believe that publicizing these attacks is good, even if they are widely known. The attention heaped on this ever-growing series of threats, whether state-sponsored or not, will continue to raise awareness, the argument goes.

In other words, where your data and intellectual property are concerned, a little fear may be a good thing.

Speaking of intellectual property, speculation is rampant on what HP will do with its WebOS asset now that it has decided to kill the related HP devices. After a weekend blowout that saw HP TouchPad's go on sale for $99, only to be scarfed up in buyer frenzy worthy of an Apple product, a few thoughts jump to mind. First, I think we've finally found the price at which an Apple iPad might be vulnerable to some competition. Second, maybe HP still has time to change its mind. Finally, HP must decide what to do with WebOS. Perhaps, as blogger Robert Scoble suggests, HP could sell it solely as a patent armament. Meanwhile, Microsoft is aggressively targeting WebOS developers. It seems Microsoft, with its Mango release of Windows Phone 7 right around the corner, is soaring around all of the dead carcasses like a very smart vulture.

The bigger question is what becomes of HP. InformationWeek's Kurt Marko calls HP "Blue Junior," a nod to what seems to be a move to make HP more like IBM. Marko predicts that HP will also jettison its imaging and printing business soon. But despite whatever exiting the PC and mobile business will drain from HP's attention in the short term, I like the look of a newly-focused HP for the future. As we reported last week, HP must still close its latest acquisition; others, like Microsoft and Oracle, may bid for Autonomy, if only to drive HP's price up.

More enterprise focus is exactly what HP needs, but as Marko and others have pointed out, IBM and Oracle have a big head start, especially in some of the areas in which HP needs to win. A deal for SAP, as complicated as that might be for a very unsettled HP right now, would certainly jostle everyone else in the process. And it's not such a far stretch for the former SAP CEO.

More unsettling, however, was the New York Post's weekend speculation that the Autonomy acquisition would make HP a good target for an Oracle takeover. How such a deal could work with all of the vitriol HP and Oracle have spit at each other through the courts lately, I'll never know. But it drove Wells Fargo's analysts to put together some scenarios for such a deal, including how it could be financed.

That's just silly talk. This far-fetched deal benefits nobody.

Never say never, Wells Fargo's report implored. I'll say it, though: Never. I don’t believe it.

Fritz Nelson is the editorial director for InformationWeek and the Executive Producer of TechWebTV. Fritz writes about startups and established companies alike, but likes to exploit multiple forms of media into his writing.

Follow Fritz Nelson and InformationWeek on Twitter, Facebook, YouTube, LinkedIn, and Google+:


Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
Browsers to Enforce Shorter Certificate Life Spans: What Businesses Should Know
Kelly Sheridan, Staff Editor, Dark Reading,  7/30/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-08-05
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate...
PUBLISHED: 2020-08-05
Jeedom through 4.0.38 allows XSS.
PUBLISHED: 2020-08-05
In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flip...
PUBLISHED: 2020-08-05
In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. If the given string is not found, a response with a `400` error code is returned, along with a error message saying that th...
PUBLISHED: 2020-08-05
Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.