BenjaminHCCarr, to China
@BenjaminHCCarr@hachyderm.io avatar

#FBI says #China's hackers preparing to attack #US infrastructure
Chinese government-linked hackers have burrowed into US #criticalinfrastructure and are waiting "for just the right moment to deal a devastating blow," FBI Director Christopher Wray said. An ongoing Chinese hacking campaign known as #VoltTyphoon has successfully gained access to numerous #American companies in telecommunications, energy, water and other critical sectors, with 23 pipeline operators targeted
https://www.reuters.com/technology/cybersecurity/fbi-says-chinese-hackers-preparing-attack-us-infrastructure-2024-04-18/

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

China is hacking Wi-Fi routers for attack on US electrical grid and water supplies, FBI warns. Hacks likened to “placing bombs in water treatment facilities, and power plants”

https://grahamcluley.com/china-is-hacking-wi-fi-routers-for-attack-on-us-electrical-grid-and-water-supplies-fbi-warns/

cybersecboardrm, to Cybersecurity
timokissel, to random

The ease with which we leave #criticalinfrastructure like our water supply systems open to Internet hacking reads like an article from The Onion, but it’s reality.

https://www.fastcompany.com/91002831/us-water-utilities-hacked-cybersecurity

mle, to Futurology

Another hack against a #water utility, this time in Ireland.

As an aside, the article calls out “Eurotronics” Israeli-made water pump system, but I’m having trouble finding a “Eurotronics” PLC or electronics manufacturer based in Israel. Possibly a misinterpretation of “Unitronics”? I see a Eurotronics circuit board manufacturer based in Belgium, but that doesn’t seem quite right. “Eurotronix” appears to be based in Spain. So 🤷‍♀️

#cybersecurity #security #criticalInfrastructure #CIKR

https://westernpeople.ie/news/hackers-hit-erris-water-in-stance-over-israel_arid-4982.html

cybersecboardrm, to Cybersecurity
simontsui, to iran

SentinelOne talks about the Iran-backed Cyber Av3ngers group who recently attacked a Pennsylvania water authority. They describe the background to these attacks and detail recent Cyber Av3ngers activity, exploring the wider implications for critical infrastructure security and how organizations can mitigate these cyber risks.
🔗 https://www.sentinelone.com/blog/iran-backed-cyber-av3ngers-escalates-campaigns-against-u-s-critical-infrastructure/

#Iran #CyberAv3ngers #criticalinfrastructure #Aliquippa

Geekmaster, to Israel

You know shits about to get super real when is reporting about it on

A in was hacked by simply because they used electronics made in . Obviously, they were just probing to gain for a future attack against a larger critical infrastructure target. Thankfully, no one was hurt, and the town's water supply isn't tainted. The even threatened that "Israel-made gear is fair game" pointing to continued aggressions.

Woke up to an advisory from on using in Water and Wastewater Systems: Cyber threat actors are targeting associated with facilities, including an identified Unitronics PLC, at a U.S. water facility.

https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems

PogoWasRight, to Cybersecurity

North Texas Municipal Water District hit by ransomware attack:

https://www.databreaches.net/north-texas-municipal-water-district-hit-by-ransomware-attack/

#DaixinTeeam gave me some additional info on this one. From what I have been able to determine and from the NTMWD's statement to DataBreaches.net, Daixin did not hit the water supply system, but got the business system.

But this is the second municipal water district attack in about a week. The first was politically motivated, or so the attackers claimed. This one is allegedly financially motivated.

#databreach #ransomware infosec #cybersecurity #CriticalInfrastructure #HomelandSecurity

@brett @GossiTheDog @BleepingComputer @vxunderground

simontsui, to Russia

Denmark's CERT (SektorCERT) reported that 22 companies that operate parts of Danish energy infrastructure were compromised in a May 2023 coordinated attack, linked to SANDWORM actors. Sandworm is a state-sponsored APT publicly attributed to Russian General Staff Main Intelligence Directorate’s Russian (GRU’s) Main Centre for Special Technologies (GTsST) by the U.S. government. The attackers leveraged a Zyxel vulnerability CVE-2023-28771 (9.8 critical) to gain control of the firewall. SektorCERT's incident response report includes a detailed analysis and timeline of the attack, recommendations and IOC.
Link: https://media.licdn.com/dms/document/media/D4D1FAQG-Qsry8BH9dg/feedshare-document-pdf-analyzed/0/1699785104486?e=1700697600&v=beta&t=icNMQ-rDYgeSojoaax-1KpC7YrCF7MVtkrDClSFiKIY

#cyberespionage #GRU #SANDWORM #Russia #Denmark #criticalinfrastructure #APT #threatintel #IOC #CVE202328771 #Zyxel

PogoWasRight, to infosec

From BankInfoSecurity:

"Hackers potentially linked to the Russian GRU Main Intelligence Directorate carried out a series of highly coordinated cyberattacks targeting Danish critical infrastructure in the nation's largest cyber incident on record, according to a new report.

SektorCERT, a nonprofit cybersecurity center for critical sectors in Denmark, reported that attackers gained access to the systems of 22 companies overseeing various components of Danish energy infrastructure in May. The report published Sunday says hackers exploited zero-day vulnerabilities in Zyxel firewalls, which many Danish critical infrastructure operators use to protect their networks."

Read more: https://www.bankinfosecurity.com/denmark-hit-largest-cyberattack-on-record-a-23584

#CriticalInfrastructure #hack #zeroday #databreach #infosec #cybersecurity

@campuscodi @briankrebs @GossiTheDog @BleepingComputer

simontsui, to China

Security Week: Mandiant’s Chief analyst urges critical infrastructure defenders to work on finding and removing traces of Volt Typhoon. This Chinese state-sponsored APT targeted critical infrastructure in Guam and in the U.S.
Link: https://www.securityweek.com/mandiant-intelligence-chief-raises-alarm-over-chinas-volt-typhoon-hackers-in-us-critical-infrastructure/

#China #PRC #APT #cybersecuritynews #VoltTyphoon #cyberespionage #Guam #criticalinfrastructure

numericcitizen, to Montreal
@numericcitizen@pixelfed.social avatar

I like structures, geometric forms, and anything that will make a composition very graphical. This is the Victoria Bridge linking the south shore to Montreal.
#montreal #montrealphoto #architecture #structure #criticalinfrastructure #infrastructure #blackandwhite

gcluley, to random
@gcluley@mastodon.green avatar

Charming Kitten targets critical infrastructure in US and elsewhere with BellaCiao malware.

Read more in my article on the Tripwire blog:

https://www.tripwire.com/state-of-security/charming-kitten-targets-critical-infrastructure-us-and-elsewhere-bellaciao

#cybersecurity #malware #iran #criticalinfrastructure

br00t4c, to China
@br00t4c@mastodon.social avatar
0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

➝ 🔓 Support Portal Exposed Customer Device Info
➝ 🔓 🇹🇭 Major in Exposes Personal Data of 20 Million Elderly Citizens
➝ 🔓 🇫🇷 Millions at risk of fraud after massive health data hack in
➝ 🔓 🇺🇸 employee inadvertently leaks data of 63 thousand colleagues
➝ 🔓 🖥️ Hacked: Revokes Passwords, Certificates in Response
➝ 🔓 🇺🇸 says caused $49 million in expenses
➝ 💸 📈 Payments Exceed $1 Billion in 2023, Hitting Record High After 2022 Decline
➝ 🇺🇸 💰 US offers $10 million for tips on ransomware leadership
➝ 🇨🇳 🇺🇸 -backed Volt Typhoon hackers have lurked inside US for ‘at least five years’
➝ 🇨🇳 🇳🇱 Chinese Hackers Exploited Flaw to Breach Dutch Network
➝ 🇮🇷 🇮🇱 accelerates cyber ops against from chaotic start
➝ 🇧🇾 🇺🇸 Belarusian National Linked to BTC-e Faces 25 Years for $4 Billion Money Laundering
➝ 🇭🇰 💸 worker pays out $25 million after video call with ‘chief financial officer’
➝ 🇺🇦 is Creating a ‘Cyber Diplomat’ Post
➝ 🇩🇰 orders schools to stop sending student data to
➝ 🇪🇺 ⚖️ proposes criminalizing AI-generated child sexual abuse and deepfakes
➝ 🇳🇱 💰 Fined 10 Million Euros by Dutch Data Regulator
➝ 🇺🇸 🛂 US to Roll Out Visa Restrictions on People Who Misuse to Target Journalists, Activists
➝ 🦠 💬 Raspberry Robin Upgrades with Spread and New Exploits
➝ 🦠 🍎 New Backdoor Linked to Prominent Ransomware Groups
🦠 🪥 Surprising 3 Million Hacked Story Goes Viral—Is It True?
➝ 🇨🇦 🐬 declares public enemy No. 1 in car-theft crackdown
➝ 🩹 : Patch new Connect Secure auth bypass bug immediately
➝ 🐛 📍 Security flaw in a popular smart helmet allowed silent location tracking
➝ 🩹 Critical Patches Released for New Flaws in , , Products
➝ 🐛 🐧 Critical Boot Loader in Shim Impacts Nearly All Distros
➝ 🐛 ✈️ App Vulnerability Introduced Aircraft Safety Risk
➝ 🩹 Patches High-Severity Bugs in QTS, Qsync Central

--

📚 This week's recommended reading is: "x86 Software Reverse-Engineering, Cracking, and Counter-Measure" by Stephanie Domas & Christopher Domas

--

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-062024

br00t4c, to random
@br00t4c@mastodon.social avatar
itnewsbot, to security

US prescription market hamstrung for 9 days (so far) by ransomware attack - Enlarge (credit: Getty Images)

Nine days after a Russian-speak... - https://arstechnica.com/?p=2007373 #criticalinfrastructure #healthcare #ransomware #security #biz#alphv

br00t4c, to random
@br00t4c@mastodon.social avatar

FBI v the bots: Feds urge denial-of-service defense after critical infrastructure alert

#criticalinfrastructure #fbi

https://go.theregister.com/feed/www.theregister.com/2024/03/21/fbi_ddos_advice/

br00t4c, to baltimore
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to China
@br00t4c@mastodon.social avatar

America's enemies targeting US critical infrastructure should be 'wake-up call'

#china #criticalinfrastructure

https://go.theregister.com/feed/www.theregister.com/2024/05/09/china_russia_iran_infrastructure/

itnewsbot, to science

East Coast land continues to collapse at a worrying rate - Enlarge / Lower Manhattan and One World Trade Center in New York City a... - https://arstechnica.com/?p=1994147 #criticalinfrastructure #syndication #subsidence #eastcoast #science

gregorni, to Cybersecurity
@gregorni@fosstodon.org avatar

I really like the latest blog post of the @sovtechfund! It not only gives a quick overview of the basic technologies our world runs on (I didn't know what TLS was, and my knowledge of the DNS needed refreshing), but it also has a great takeaway: Memory safety is not like a silver bullet, but more like a smallpox vaccine (nice analogy!)

https://www.sovereigntechfund.de/news/on-rust-memory-safety-open-source-infrastructure

#STF #SovereignTechFund #CriticalInfrastructure #infrastructure #Cybersecurity #MemorySafety

br00t4c, to random
@br00t4c@mastodon.social avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • Durango
  • DreamBathrooms
  • osvaldo12
  • InstantRegret
  • ngwrru68w68
  • magazineikmin
  • mdbf
  • thenastyranch
  • Youngstown
  • slotface
  • everett
  • kavyap
  • ethstaker
  • megavids
  • tester
  • GTA5RPClips
  • tacticalgear
  • modclub
  • khanakhh
  • rosin
  • cisconetworking
  • normalnudes
  • provamag3
  • Leos
  • cubers
  • anitta
  • lostlight
  • All magazines