12 March 2018
Somebody’s watching! When cameras are more than just ‘smart’The researchers at Kaspersky Lab ICS CERT decided to check the popular smart camera to see how well protected it is against cyber abuses.
Filter
12 March 2018
Somebody’s watching! When cameras are more than just ‘smart’The researchers at Kaspersky Lab ICS CERT decided to check the popular smart camera to see how well protected it is against cyber abuses.
28 February 2018
IoT hack: how to break a smart home… againThere can never be too many IoT gadgets – that’s what people usually think when buying yet another connected device with advanced functionality. From our perspective, we also think there can’t be too many IoT investigations.
07 February 2018
Gas is too expensive? Let’s make it cheap!A few months ago, while undertaking unrelated research into online connected devices, we uncovered something surprising and realized almost immediately that we could be looking at a critical security threat.
22 January 2018
A silver bullet for the attacker. A study into the security of hardware license tokensIn the past years, the problem of vulnerabilities in industrial automation systems has been becoming increasingly important. The fact that industrial control systems have been developing in parallel with IT systems, relatively independently and often without regard for modern secure coding practices is probably the main source of ICS security problems.
16 January 2018
MLAD: Machine Learning for Anomaly DetectionModern industrial control systems (ICS) are cyber-physical systems that include IT infrastructure and operational technologies or OT infrastructure. Attacks on OT pose the greatest danger and are very difficult to detect. The MLAD (Machine Learning for Anomaly Detection) technology is designed to protect OT.
30 November 2017
Industrial Enterprise and IoT Security Threats: Forecast for 20182017 was one of the most eventful years in terms of information security incidents affecting industrial systems, and it changed the way industrial companies think about protecting key operational technology systems.
15 November 2017
The Relevance of WPA2 Vulnerabilities and KRACK Attacks to Industrial SystemsCritical vulnerabilities that have recently been identified in the WPA2 protocol enable threat actors to carry out Man-in-the-Middle (MitM) attacks and force devices connected to the network to reinstall encryption keys that protect traffic. These vulnerabilities can be used, among other things, to implement attacks on industrial automation systems.
28 September 2017
Threat Landscape for Industrial Automation Systems in H1 2017Kaspersky Lab Industrial Control Systems Cyber Emergency Response Team (Kaspersky Lab ICS CERT) publishes the results of its research on the threat landscape for industrial automation systems for the first six months of 2017.
22 June 2017
WannaCry on industrial networks: error correctionDuring the period from 12 to 15 May 2017, numerous companies across the globe were attacked by a network cryptoworm called WannaCry. The worm’s victims include various manufacturing companies, oil refineries, city infrastructure objects and electrical distribution network facilities.
19 June 2017
Vulnerable System Update Statistics. General ElectricThis article is devoted to vulnerabilities in General Electric products. The article looks only at known vulnerabilities, a list of which was prepared based using the MITRE CVE database. All the vulnerabilities in question were uncovered in 2012 – 2016.
Filter
21 November 2017
Moxa Fixes Serious Vulnerabilities in NPort Serial Network Interface DevicesMoxa has released updates that close serious flaws in NPort device firmware. Devices of this type were targeted in December 2015 attacks on Ukrainian power companies.
17 November 2017
Serious Vulnerabilities Found in Siemens SICAM RTU ModulesSerious vulnerabilities allowing attackers to execute code remotely and bypass authentication have been identified in Siemens SICAM RTU modules. Disabling the integrated web server is recommended to reduce risk.
16 November 2017
Schneider Electric Closes Critical Vulnerability in HMI ProductsSchneider Electric has released patches for a vulnerability which affects InduSoft Web Studio and HMI InTouch Machine Edition products
15 November 2017
Vendors Confirm That Industrial Solutions Are Vulnerable to KRACK AttacksSeveral companies, including Cisco, Rockwell Automation, Sierra Wireless, ABB and Siemens, have reported vulnerabilities in their industrial devices. The vendors are preparing updates to close these vulnerabilities and will release the patches as they are ready.
09 November 2017
New Botnet Recruits IoT Devices Across the GlobeThe Reaper IoT botnet includes about 10-20 thousand infected devices, with some of these devices possibly being used by industrial enterprises, hospitals, railway terminals and airports
26 October 2017
Bad Rabbit, Brother of [Ex]PetrKaspersky Lab experts believe that the same threat actor is behind ExPetr and Bad Rabbit
25 October 2017
US-CERT Reports APT Attack on Critical InfrastructureUS-CERT has published a report on a targeted (APT) attack on government entities and organizations in energy, nuclear, aviation and other sectors. The attackers were interested in documents on industrial processes in targeted organizations.
18 October 2017
WPA2 Vulnerabilities Can Be Used to Attack Industrial SystemsOn October 16, information on critical vulnerabilities in the WPA2 protocol, which enable attackers to bypass protection and listen to Wi-Fi traffic, was disclosed. Comments from Kaspersky Lab ICS CERT experts
15 September 2017
MITRE Grants Kaspersky Lab CVE Numbering Authority (CNA) StatusThe MITRE Corporation has recognized Kaspersky Lab as an authority in the area of vulnerabilities, granting the company the CVE Numbering Authority (CNA) status.
15 September 2017
New Attack Vector Affecting Bluetooth DevicesResearches from Armis Labs have identified a new attack vector, dubbed BlueBorne, that endangers mobile, desktop and IoT operating systems, including Android, iOS, Windows, and Linux.
Filter