Ads 468x60px

Pages

Showing posts with label security news. Show all posts
Showing posts with label security news. Show all posts

Dec 18, 2020

SolarWinds Hack to Signal a new form of Warfare?

 The list keeps on growing... The new war. The new espionage. Call it what you will, but this was not a simple attack.




It started by manipulating SolarWinds Orion system updates hackers (state sponsored hackers, i.e. cyber warfare). This updated version allowed the hackers to access any of the servers which hosted the SolarWinds application, which is an IT monitoring and management tool used by administrators and network engineers. This allowed the hackers to have full administrator access to at least one server inside the victim's network, and download any additional malware they needed to get full access of the victims' networks. To set things in perspective, hackers breached the US nuclear weapons agency.

Source: Microsoft


The list of victims is huge. Till now, 40+ major companies or government departments and agencies have been identified. I expected the final number to reach at least a 100+ hi-profile victims. Hackers had around 9 months to do whatever they wanted without being caught. 80% of which are located in the United States, with the rest being spread across seven other countries —namely Canada, Mexico, Belgium, Spain, the UK, Israel, and the UAE. 


Companies breached so far:

- Microsoft
- SolarWinds
- Fireeye

Main US targets:

- The US Treasury Department
- The US Department of Commerce's National Telecommunications and Information Administration (NTIA)
- The Department of Health's National Institutes of Health (NIH)
- The Cybersecurity and Infrastructure Agency (CISA)
- The Department of Homeland Security (DHS)
- The US Department of State
- The National Nuclear Security Administration (NNSA)
- The US Department of Energy (DOE)
- Three US states
- City of Austin (also disclosed today)


While not the first attack of its kind, the fact that we are still at the tip of the iceberg in discovering the scale is worrisome. The types of victims, the amount of data that could have been stolen during a 9-month breach, and the fact that it is a state sponsored attack all indicate that the new wars will be fought online as well as with real weapons.


Finally, so many questions come to mind, and I am sure those would be answered within the coming days:

  1. How did the hackers bypass all internal SolarWinds controls, application controls and Quality Assurance to publish such a malicious update.
  2. How were they left undetected for 9 months.
  3. How many companies have been really breached and what type of data has been stolen
  4. What long lasting impact will this have on the cyber world, how can we ensure that software installed on our infrastructure is secure?
  5. Will the US retaliate?

Aug 22, 2020

Warning: A Google Drive 'Feature' Could Let Attackers Trick You Into Installing Malware

 


An unpatched security weakness in Google Drive could be exploited by malware attackers to distribute malicious files disguised as legitimate documents or images, enabling bad actors to perform spear-phishing attacks comparatively with a high success rate.

The latest security issue—of which Google is aware but, unfortunately, left unpatched—resides in the "manage versions" functionality offered by Google Drive that allows users to upload and manage different versions of a file, as well as in the way its interface provides a new version of the files to the users.

 

For more info, https://thehackernews.com/2020/08/google-drive-file-versions.html


Nov 20, 2011

Security News Update - 20/11/2011

So I have decided to add a new section to my blog, Information Security News updates....

 This could be done daily, weekly or monthly, depending on what's new... I will try to summarize all the news, and add links to extra details...

 * We are getting more and more reliant on computers in our lives, and actually many things we depend on and take for granted are based on computers... For example, hackers destroyed a pump used by a US water utility as explained in http://goo.gl/uWVUu.... How about that?

 ** Hackers also hit oil, gas, and defense companies in Norway Link: http://goo.gl/uuNdM

 *** There's a new campaign on Twitter, with #worstpassword ... Check out some of the worst passwords you could choose for your accounts, and then some "jokes"

 **** Facebook's new feature, the timeline, has been subject to an attack via XSS (cross-site scripting)... (I will explain what that is in some future blog) Link: http://goo.gl/UOYBc

Total Pageviews

On Top List

Online Marketing
Add blog to our blog directory

gob