Sadly yes, this is exactly what happens. And it ends up being IT holding the bag at the end, with the managers having long since cashed out their stock options and left.
sylver_dragon
The hacks target internet-facing programmable logic controllers (PLCs)
Why the fuck
is your PLC
facing the fucking internet!
Jesus Zombie Christ an a pogo stick. Has no one been paying attention for the last two decades? Seriously, we learned this sort of lesson in Two Thousand and fucking Three. Your critical assets do not get public IP addresses.
While I'm glad these guys are going to jail, this does go to show that one should not use Windows if they care about OPSEC.
Not surprising. Web search from the Start Menu was always a bad idea.
Hell, I've had to deal with users getting their systems compromised because of this idiocy. User typed 'ms teams' in the start menu, clicked on the first link and ended up at an attacker's page which mimicked the official Teams download page. User clicked "Download", received the trojaned .msi file and ran it.
Sure, there's some blame to go around in that case (and we finally got some default configuration changes out of it), but the fact that Microslop's greed led to a malvertising link showing up in a user's Start Menu is indicative of everything wrong with Windows 11.
Edge is just Chrome with a Microslop skin. They went from crushing Netscape so hard it got open sourced (mostly via monopoly shenanigans) to copying Google's homework. And their attempts at mobile anything has been failure (Windows CE) after failure (Windows Phone) after failure (Windows for ARM).
If it weren't for Office and companies' undying love of Active Directory and Exchange, Microslop would be a memory and little more.
I think it's pretty telling that so many of the people they talk to and a lot of the focus of the article isn't really about older gamers, it's about their money.
The opportunity is substantial. The 40+ segment in the US is on track to grow from $19 billion in 2022 to $43 billion by 2030, a 132% expansion at a moment when the rest of the industry is shrinking. These are players with the most disposable income, the longest gaming literacy, and the highest brand loyalty.
I'm in that "40+ segment" and I suspect part of the "problem" these companies face is that older gamers have seen the enshitification of so many of the brands we love. Our tolerance for bullshit is basically gone at this point. Micro transactions, season passes, fucking ads in games, all of that bullshit is a quick way to not get our money.
I also suspect "brand loyalty" is basically gone for the same reason. As a kid, I looked for the Electronic Arts logo. If I saw this logo on a game package, I knew I was looking at a good game. I haven't bought an EA game in years. I don't expect to buy an EA game any time soon and I basically ignore everything they do. Sure, if a trailer for Starflight 3 dropped, I'd sit up and take notice. I'd also expect it to be an enshitified mess wearing the skin of a beloved series to sucker me in, before pouncing on my wallet.
So ya, maybe just make good games and older gamers will inevitably buy them. I mean, Larian can pretty much say, "hi we're making..." and I'll have my wallet out and be pulling bills before they get any further. And maybe that's your "brand loyalty". Game companies who make good games and aren't private equity firms wearing the dead skin suits of brands we used to love.
Even when a company is doing things pretty well with a VPN, all it takes is one mistake and the cat is out of the bag. At one of my previous employers, we had a fairly good setup with VPNs using single sign on via our IdM provider. IdM enforced SSO and the VPN had a number of policies setup which kept good control over what users could login. And then someone had the brilliant idea to take an old VPN appliance, reset it to factory defaults and configure it just enough to work on our network and then hung it out on the internet for some sort of test (our configuration management left a lot to be desired). Of course, that led to it being left there for a couple months and an attacker finally found it. They also had a valid username/password combination which got them in the door.
Security is hard and often expensive. But still, compared to "we put out OT devices on the internet" a basic VPN is a huge step up.