Geekmaster, to Israel

You know shits about to get super real when is reporting about it on

A in was hacked by simply because they used electronics made in . Obviously, they were just probing to gain for a future attack against a larger critical infrastructure target. Thankfully, no one was hurt, and the town's water supply isn't tainted. The even threatened that "Israel-made gear is fair game" pointing to continued aggressions.

Woke up to an advisory from on using in Water and Wastewater Systems: Cyber threat actors are targeting associated with facilities, including an identified Unitronics PLC, at a U.S. water facility.

https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems

PogoWasRight, to Cybersecurity

North Texas Municipal Water District hit by ransomware attack:

https://www.databreaches.net/north-texas-municipal-water-district-hit-by-ransomware-attack/

#DaixinTeeam gave me some additional info on this one. From what I have been able to determine and from the NTMWD's statement to DataBreaches.net, Daixin did not hit the water supply system, but got the business system.

But this is the second municipal water district attack in about a week. The first was politically motivated, or so the attackers claimed. This one is allegedly financially motivated.

#databreach #ransomware infosec #cybersecurity #CriticalInfrastructure #HomelandSecurity

@brett @GossiTheDog @BleepingComputer @vxunderground

simontsui, to Russia

Denmark's CERT (SektorCERT) reported that 22 companies that operate parts of Danish energy infrastructure were compromised in a May 2023 coordinated attack, linked to SANDWORM actors. Sandworm is a state-sponsored APT publicly attributed to Russian General Staff Main Intelligence Directorate’s Russian (GRU’s) Main Centre for Special Technologies (GTsST) by the U.S. government. The attackers leveraged a Zyxel vulnerability CVE-2023-28771 (9.8 critical) to gain control of the firewall. SektorCERT's incident response report includes a detailed analysis and timeline of the attack, recommendations and IOC.
Link: https://media.licdn.com/dms/document/media/D4D1FAQG-Qsry8BH9dg/feedshare-document-pdf-analyzed/0/1699785104486?e=1700697600&v=beta&t=icNMQ-rDYgeSojoaax-1KpC7YrCF7MVtkrDClSFiKIY

#cyberespionage #GRU #SANDWORM #Russia #Denmark #criticalinfrastructure #APT #threatintel #IOC #CVE202328771 #Zyxel

PogoWasRight, to infosec

From BankInfoSecurity:

"Hackers potentially linked to the Russian GRU Main Intelligence Directorate carried out a series of highly coordinated cyberattacks targeting Danish critical infrastructure in the nation's largest cyber incident on record, according to a new report.

SektorCERT, a nonprofit cybersecurity center for critical sectors in Denmark, reported that attackers gained access to the systems of 22 companies overseeing various components of Danish energy infrastructure in May. The report published Sunday says hackers exploited zero-day vulnerabilities in Zyxel firewalls, which many Danish critical infrastructure operators use to protect their networks."

Read more: https://www.bankinfosecurity.com/denmark-hit-largest-cyberattack-on-record-a-23584

#CriticalInfrastructure #hack #zeroday #databreach #infosec #cybersecurity

@campuscodi @briankrebs @GossiTheDog @BleepingComputer

fifonetworks, to Cybersecurity

We're watching Secret City on Netflix. In episode 4, the air traffic control radio system is shut down by hackers. There is no clearer illustration of the dangers of using Software Defined Radio (SDR) for critical infrastructure systems and public safety systems. Traditional radio systems can be jammed at their specific geographic location, but they can't be compromised by someone sitting at a computer terminal in a hostile nation 5,000 miles away.

(Preemptive reply to the highly technical people who will feel like correcting me and saying, "But Bob, SDR can be done without an Internet connection." Yes, of course, but it almost never is. The large SDR systems are sold with centralized management as part of the package, and every agency wants to save money on administration. If you can tell me about a critical infrastructure SDR system that isn't centrally managed, I'll be overjoyed).

#callmeifyouneedme #fifonetworks

#cybersecurity #criticalinfrastructure #publicsafety

simontsui, to China

Security Week: Mandiant’s Chief analyst urges critical infrastructure defenders to work on finding and removing traces of Volt Typhoon. This Chinese state-sponsored APT targeted critical infrastructure in Guam and in the U.S.
Link: https://www.securityweek.com/mandiant-intelligence-chief-raises-alarm-over-chinas-volt-typhoon-hackers-in-us-critical-infrastructure/

#China #PRC #APT #cybersecuritynews #VoltTyphoon #cyberespionage #Guam #criticalinfrastructure

marcel, to random German
@marcel@waldvogel.family avatar

begrüsst seine Besucher des mit einem kleinen .

marcel,
@marcel@waldvogel.family avatar

@ChristinaLekati mentions that spy agencies are talking about campaigns, with a particular focus on .

Attackers ranging from state-sponsored, Cyber Criminals, Competitors, but also Hacktivists.

Her advice: "Be careful, especially if your organization is involved in , important technology , , , or targeted by ."

skip, to infosec

This won't end well. #infosec

"The European Union's Cyber Resilience Act's requirement to disclose vulnerabilities within 24 hours of exploitation could potentially expose organizations to attacks from adversaries or government surveillance."

https://www.darkreading.com/edge/security-pros-warn-that-eu-vulnerability-disclosure-rule-is-risky

kkarhan,

@skip @EU_Commission At least for #CCSS where this is feasible.

Also I think #CriticalInfrastructure should mandate #OpenSourceHardware and #OpenSourceSoftware for everything wothout exceptioms, including the requirement to provide free, unrestructed and non-paywalled #APIs that are dpculented to interface with required systems.

Because neither #DATEV nor #meDoc or anyone else should have the de-facto national #monopoly as #TaxReporting and #TaxFiling Software!

BrodieOnLinux, to linux
@BrodieOnLinux@linuxrocks.online avatar

Whenever I see comments like this about I always have to ask, who do you think would be developing this new protocol? Every single graphics developers agrees that Wayland is where we're going, the problem is nobody agrees on how it should look

kkarhan,

@rdfhrn @BrodieOnLinux #HPUX and #Solaris are rounding errors AFAICT both are only on life support due to existing contracts and not because #HPE or #Oracle actually want to improve them.

That being said I've seen Solaris & HP-UX in #CriticalInfrastructure (sadly can't say where due to NDAs!) but not as a #Desktop, so I'm pretty shure they don't even have #Xorg installed at all...

itnewsbot, to microsoft

Microsoft finds vulnerabilities it says could be used to shut down power plants - Enlarge (credit: Rockwell Automation)

On Friday, Microsoft dis... - https://arstechnica.com/?p=1960538 #industrialcontrolsystems #criticalinfrastructure #microsoft #security #codesys #biz&it

rail, to random

If you have your users access critical systems like infrastructure or anything that in case of a breach could result in a catastrophe for your organization

For the love of god don't use passwords

Use certificates, hardware-based passwordless factors, and maybe then also passwords

But for the love of god not just passwords

kkarhan,

@rail That sadly will be less likely than migrating all systems to #Linux because a lot of #CriticalInfrastructure doesn't support anything BUT #Passwords...

br00t4c, to Facebook
@br00t4c@mastodon.social avatar

Facebook posts - The White House did not issue 'official' warning about imminent attack to critical infrastructure

#criticalinfrastructure #facebook

http://www.politifact.com/factchecks/2023/aug/02/facebook-posts/the-white-house-did-not-issue-official-warning-abo/

numericcitizen, to Montreal
@numericcitizen@pixelfed.social avatar

I like structures, geometric forms, and anything that will make a composition very graphical. This is the Victoria Bridge linking the south shore to Montreal.
#montreal #montrealphoto #architecture #structure #criticalinfrastructure #infrastructure #blackandwhite

itnewsbot, to random

There’s Finally a Way to Improve Cloud Container Registry Security - “Container registries” are ubiquitous software clearinghouses, but they've been exposed f... - https://www.wired.com/story/container-registry-security-chainguard/ #security/cyberattacksandhacks #criticalinfrastructure #security/securitynews #security

gcluley, to random
@gcluley@mastodon.green avatar

Charming Kitten targets critical infrastructure in US and elsewhere with BellaCiao malware.

Read more in my article on the Tripwire blog:

https://www.tripwire.com/state-of-security/charming-kitten-targets-critical-infrastructure-us-and-elsewhere-bellaciao

#cybersecurity #malware #iran #criticalinfrastructure

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • mdbf
  • magazineikmin
  • tacticalgear
  • thenastyranch
  • ethstaker
  • rosin
  • love
  • Youngstown
  • slotface
  • ngwrru68w68
  • kavyap
  • osvaldo12
  • DreamBathrooms
  • Leos
  • everett
  • InstantRegret
  • cubers
  • modclub
  • tester
  • khanakhh
  • GTA5RPClips
  • cisconetworking
  • Durango
  • normalnudes
  • provamag3
  • anitta
  • JUstTest
  • All magazines