The internet of things security maturity model: a nudge for IoT cybersecurity
The purpose of the IoT Security Maturity Model (IoT SMM) is to help choose protection measures against cyberthreats that correspond to the company’s actual business needs.
How we hacked our colleague’s smart home, or morning drum & bass
In this article, we publish the results of our study of the Fibaro Home Center smart home. We identified vulnerabilities in Fibaro Home Center 2 and Fibaro Home Center Lite version 4.540, as well as vulnerabilities in the online API.
Threat landscape for industrial automation systems. H2 2018
Key Events – H2 2018 APT attacks on industrial targets APT attack by the Leafminer group New GreyEnergy malware The Sharpshooter campaign MuddyWater Cloud Hopper Shamoon v.3 Cybercrime Activity Ransomware attacks Phishing attacks on Russian industrial companies Phishing attacks on enterprises around the world Vulnerabilities identified in 2018 Vulnerabilities in various ICS components Number of...
GreyEnergy’s overlap with Zebrocy
Kaspersky Lab ICS CERT has identified an overlap between GreyEnergy and a Sofacy subset called “Zebrocy”. The Zebrocy activity was named after malware that Sofacy group began to use since mid-November 2015 for the post-exploitation stage of attacks on its victims. Zebrocy’s targets are widely spread across the Middle East, Europe and Asia and the targets’ profiles are mostly government-related.
Security research: ThingsPro Suite – IIoT gateway and device manager by Moxa
It is obvious that the security of products that are part of the industrial internet of things (IIoT) ecosystem requires special attention. This time, our research focused on ThingsPro Suite – an IIoT gateway and device manager by Moxa.
Challenges of industrial cybersecurity
The danger posed by cyber-physical technologies to the industrial process and equipment is increasingly acknowledged by specialists working at industrial enterprises, information security researchers and government agencies of most countries.
Threats posed by using RATs in ICS
The paper provides an analysis of the prevalence of remote administration tools on OT networks and the threats associated with their use.
Threat landscape for industrial automation systems: H1 2018
In this report, Kaspersky Lab Industrial Control Systems Cyber Emergency Response Team (Kaspersky Lab ICS CERT) publishes the findings of its research on the threat landscape for industrial automation systems conducted during the first half of 2018.
Attacks on industrial enterprises using RMS and TeamViewer
Kaspersky Lab ICS CERT has identified a new wave of phishing emails with malicious attachments targeting primarily companies and organizations that are, in one way or another, associated with industrial production.
The State of Industrial Cybersecurity 2018: findings of joint survey by Kaspersky Lab and PAC
Kaspersky Lab has published the results of The State of Industrial Cybersecurity study carried out in collaboration with PAC, a CXP Group Company, and based on a survey of 320 professionals representing companies from such sectors as manufacturing and industrial production, energy, mining, transport, and logistics.