br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to China
@br00t4c@mastodon.social avatar

America's enemies targeting US critical infrastructure should be 'wake-up call'

#china #criticalinfrastructure

https://go.theregister.com/feed/www.theregister.com/2024/05/09/china_russia_iran_infrastructure/

BenjaminHCCarr, to China
@BenjaminHCCarr@hachyderm.io avatar

says 's hackers preparing to attack infrastructure
Chinese government-linked hackers have burrowed into US and are waiting "for just the right moment to deal a devastating blow," FBI Director Christopher Wray said. An ongoing Chinese hacking campaign known as has successfully gained access to numerous companies in telecommunications, energy, water and other critical sectors, with 23 pipeline operators targeted
https://www.reuters.com/technology/cybersecurity/fbi-says-chinese-hackers-preparing-attack-us-infrastructure-2024-04-18/

br00t4c, to baltimore
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar

FBI v the bots: Feds urge denial-of-service defense after critical infrastructure alert

#criticalinfrastructure #fbi

https://go.theregister.com/feed/www.theregister.com/2024/03/21/fbi_ddos_advice/

itnewsbot, to security
@itnewsbot@schleuss.online avatar

US prescription market hamstrung for 9 days (so far) by ransomware attack - Enlarge (credit: Getty Images)

Nine days after a Russian-speak... - https://arstechnica.com/?p=2007373 #criticalinfrastructure #healthcare #ransomware #security #biz#alphv

br00t4c, to random
@br00t4c@mastodon.social avatar
0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

➝ 🔓 Support Portal Exposed Customer Device Info
➝ 🔓 🇹🇭 Major in Exposes Personal Data of 20 Million Elderly Citizens
➝ 🔓 🇫🇷 Millions at risk of fraud after massive health data hack in
➝ 🔓 🇺🇸 employee inadvertently leaks data of 63 thousand colleagues
➝ 🔓 🖥️ Hacked: Revokes Passwords, Certificates in Response
➝ 🔓 🇺🇸 says caused $49 million in expenses
➝ 💸 📈 Payments Exceed $1 Billion in 2023, Hitting Record High After 2022 Decline
➝ 🇺🇸 💰 US offers $10 million for tips on ransomware leadership
➝ 🇨🇳 🇺🇸 -backed Volt Typhoon hackers have lurked inside US for ‘at least five years’
➝ 🇨🇳 🇳🇱 Chinese Hackers Exploited Flaw to Breach Dutch Network
➝ 🇮🇷 🇮🇱 accelerates cyber ops against from chaotic start
➝ 🇧🇾 🇺🇸 Belarusian National Linked to BTC-e Faces 25 Years for $4 Billion Money Laundering
➝ 🇭🇰 💸 worker pays out $25 million after video call with ‘chief financial officer’
➝ 🇺🇦 is Creating a ‘Cyber Diplomat’ Post
➝ 🇩🇰 orders schools to stop sending student data to
➝ 🇪🇺 ⚖️ proposes criminalizing AI-generated child sexual abuse and deepfakes
➝ 🇳🇱 💰 Fined 10 Million Euros by Dutch Data Regulator
➝ 🇺🇸 🛂 US to Roll Out Visa Restrictions on People Who Misuse to Target Journalists, Activists
➝ 🦠 💬 Raspberry Robin Upgrades with Spread and New Exploits
➝ 🦠 🍎 New Backdoor Linked to Prominent Ransomware Groups
🦠 🪥 Surprising 3 Million Hacked Story Goes Viral—Is It True?
➝ 🇨🇦 🐬 declares public enemy No. 1 in car-theft crackdown
➝ 🩹 : Patch new Connect Secure auth bypass bug immediately
➝ 🐛 📍 Security flaw in a popular smart helmet allowed silent location tracking
➝ 🩹 Critical Patches Released for New Flaws in , , Products
➝ 🐛 🐧 Critical Boot Loader in Shim Impacts Nearly All Distros
➝ 🐛 ✈️ App Vulnerability Introduced Aircraft Safety Risk
➝ 🩹 Patches High-Severity Bugs in QTS, Qsync Central

--

📚 This week's recommended reading is: "x86 Software Reverse-Engineering, Cracking, and Counter-Measure" by Stephanie Domas & Christopher Domas

--

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-062024

br00t4c, to China
@br00t4c@mastodon.social avatar
gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

China is hacking Wi-Fi routers for attack on US electrical grid and water supplies, FBI warns. Hacks likened to “placing bombs in water treatment facilities, and power plants”

https://grahamcluley.com/china-is-hacking-wi-fi-routers-for-attack-on-us-electrical-grid-and-water-supplies-fbi-warns/

#cybersecurity #vulnerability #router #patching #china #criticalinfrastructure

cybersecboardrm, to Cybersecurity
itnewsbot, to science
@itnewsbot@schleuss.online avatar

East Coast land continues to collapse at a worrying rate - Enlarge / Lower Manhattan and One World Trade Center in New York City a... - https://arstechnica.com/?p=1994147 #criticalinfrastructure #syndication #subsidence #eastcoast #science

br00t4c, to random
@br00t4c@mastodon.social avatar
NuanceRhymesWithOrange, to VintageOSes
@NuanceRhymesWithOrange@mstdn.social avatar

Worst idea ever? Using Windows 98 as an embedded operating system for an oscilloscope. It takes five minutes for the oscilloscope to boot. DID YOU NOT NOTICE THAT, TEKTRONIX? Anyway... Yeah. I fell sorry for the engineer who had to implement that idea. #RetroTechnology #EmbeddedSystems #BadIdea #Windows98

kkarhan,
@kkarhan@mstdn.social avatar

@NuanceRhymesWithOrange there's even worse shit in #EmbeddedSystems espechally in #CriticalInfrastructure like #electricalGrids and #MedicalIT...

I really wished I could go deeper but then I'd violate multiple #NDAs and ruin my reputation for being discrete...

timokissel, to random
@timokissel@mastodon.world avatar

The ease with which we leave like our water supply systems open to Internet hacking reads like an article from The Onion, but it’s reality.

https://www.fastcompany.com/91002831/us-water-utilities-hacked-cybersecurity

metacurity, to random

"In one of the coolest and more outrageous repair stories in quite some time, four white-hat hackers helped a regional rail company in southwest Poland unbrick a train that had been artificially rendered inoperable by the train’s manufacturer after an independent maintenance company worked on it."
https://www.404media.co/polish-hackers-repaired-trains-the-manufacturer-artificially-bricked-now-the-train-company-is-threatening-them/?ref=daily-stories-newsletter

kkarhan,
@kkarhan@mstdn.social avatar

@metacurity TBH, this #AntiRepair #malware should be penalized by authorities as the #sabotage if not #terrorism plot against #CriticalInfrastructure (which #Railways & #PublicTransport are!) it really is...

Anything else would be undue leniency towards #Enshittification and tge fact that this literally #bricket #trains!

#WhatYouAllowIsWhatWillContinue

mle, to Futurology

Another hack against a #water utility, this time in Ireland.

As an aside, the article calls out “Eurotronics” Israeli-made water pump system, but I’m having trouble finding a “Eurotronics” PLC or electronics manufacturer based in Israel. Possibly a misinterpretation of “Unitronics”? I see a Eurotronics circuit board manufacturer based in Belgium, but that doesn’t seem quite right. “Eurotronix” appears to be based in Spain. So 🤷‍♀️

#cybersecurity #security #criticalInfrastructure #CIKR

https://westernpeople.ie/news/hackers-hit-erris-water-in-stance-over-israel_arid-4982.html

benjamingeer, to Trains
@benjamingeer@zirk.us avatar

Polish hackers figured out that a train manufacturer had programmed its trains to break down after certain dates, or if they were serviced at another company's workshop.

https://badcyber.com/dieselgate-but-for-trains-some-heavyweight-hardware-hacking/

attn @jon @echo_pbreyer

kkarhan,
@kkarhan@mstdn.social avatar

@benjamingeer @jon @echo_pbreyer I really hope this will have consequences by regulators like @EU_Commission and @BNetzA and @bsi because this is #Sabotage of #PublicInfrastructure with #Malware and should be treated as the #terrorism against #CriticalInfrastructure it is!

https://mstdn.social/@kkarhan/111528207495414359

br00t4c, to random
@br00t4c@mastodon.social avatar
kkarhan, to random
@kkarhan@mstdn.social avatar

Someone asked me in regards to OS/1337 "why don't you just use mkroot from @landley ?"

https://landley.net/toybox/downloads/binaries/mkroot/latest/

And that is a valid question.

To sum it up:

  1. for requires 3MiB of storage and thus is not an option for the 1440kB target size of the current, minimalist system.

  2. shure I could instead make a but that feels like cheating...

  3. In the end the idea of OS/1337 is to build a -based that can be built to run on everything.

kkarhan,
@kkarhan@mstdn.social avatar

...or some old #ThinClients that can't even do @bunsenlabs or #PorteusKiosk but otherwise are still useable as "#FatClients" in the sense of just using a slimmed-down OS to work with.

Also OS/1337 intents to be fully transparent in the sense that it can be used for #CriticalInfrastructure by virtue of being fully-automateable "#BuildFromSource" so on fully #airgapped systems and networks it can be deployed after it went through the ardourous #audit pipeline said users demand.

cybersecboardrm, to Cybersecurity
simontsui, to iran

SentinelOne talks about the Iran-backed Cyber Av3ngers group who recently attacked a Pennsylvania water authority. They describe the background to these attacks and detail recent Cyber Av3ngers activity, exploring the wider implications for critical infrastructure security and how organizations can mitigate these cyber risks.
🔗 https://www.sentinelone.com/blog/iran-backed-cyber-av3ngers-escalates-campaigns-against-u-s-critical-infrastructure/

#Iran #CyberAv3ngers #criticalinfrastructure #Aliquippa

PogoWasRight, to infosec

Daixin Team leaked the rest of the North Texas Municipal Water District data. As they had indicated to me, there doesn't seem to be residents' data in the dump. It is mostly internal documents, but some of the files do have employee info.

As a reminder: thankfully, they did not hit the water supply system.

bgd: https://www.databreaches.net/north-texas-municipal-water-district-hit-by-ransomware-attack/

Geekmaster, to Israel

You know shits about to get super real when is reporting about it on

A in was hacked by simply because they used electronics made in . Obviously, they were just probing to gain for a future attack against a larger critical infrastructure target. Thankfully, no one was hurt, and the town's water supply isn't tainted. The even threatened that "Israel-made gear is fair game" pointing to continued aggressions.

Woke up to an advisory from on using in Water and Wastewater Systems: Cyber threat actors are targeting associated with facilities, including an identified Unitronics PLC, at a U.S. water facility.

https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Leos
  • rosin
  • InstantRegret
  • ethstaker
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • thenastyranch
  • Youngstown
  • tacticalgear
  • slotface
  • Durango
  • khanakhh
  • kavyap
  • megavids
  • everett
  • vwfavf
  • normalnudes
  • osvaldo12
  • cubers
  • GTA5RPClips
  • cisconetworking
  • ngwrru68w68
  • anitta
  • provamag3
  • tester
  • modclub
  • JUstTest
  • All magazines