The Justice Department this week attributed a string of intrusions against federal agencies and hospitals to a Chinese state-linked group, citing an attempted 2019 breach of NASA servers and a separate attack on an Ohio hospital system as evidence. Both incidents predate the announcement by roughly seven years. The attribution names a group, not a technique, a CVE, or a patch status defenders can check against their own logs today.
The same day, the DOJ confirmed a Russian-linked ransomware group's claim of breaching a system belonging to the Bureau of Alcohol, Tobacco, Firearms and Explosives, a live compromise with no disclosed initial access vector as of August 28. One filing closes a seven-year-old case file. The other opens one. A CISO reading both in the same news cycle gets a historical scorecard and an active incident with no indicator of compromise to hunt for, which is the wrong ratio when only one of the two can still be contained.