Showing posts with label SCADA. Show all posts
Showing posts with label SCADA. Show all posts

Tuesday, 21 July 2015

32 Zero-Day Vulnerabilities Announced At Black Hat Conference


For another two weeks and then starts the American edition of the Black Hat conference, one of the most important conferences in the field of IT security. This year especially defense against malware and mobile technologies popular topics, but there will also be all sorts of unknown vulnerabilities are demonstrated.

"We have 32 different zero-day vulnerabilities disclosed during the event," said Stevie Wylie, general director of the conference, compared to eWeek . "The zero days come from a variety of areas, including mobile and SCADA (supervisory control and data acquisition) systems." In addition, the conference for the first time a study ( pdf ) published among 460 security experts. The experts suggest that refined attacks directly against the organization are focused and phishing and social engineering are the main concerns. Furthermore, the experts most daily time spent on vulnerabilities that are introduced by their own application developers.

When it comes to expenditure are incidental data leaks that cause end users because they do not follow the policy as well as targeted attacks, the greatest costs. When asked what the weakest link in the enterprise security indicates 33% of the surveyed experts to end users who violate security policy and easily be misled by social engineering attacks. According to Black Hat, the survey shows that the current IT security model of enterprises should be reconsidered and that security professionals do not spend their time and money to make the issues they are most concerned about.

Sunday, 11 January 2015

Factories Target Online Banking Malware


Trojans designed to steal money from online bank accounts are also used at industrial plants and factories, so has had a security researcher know. Kyle Wilhoit anti-virus firm Trend Micro discovered thirteen different types of malware that occurred as software in SCADA (supervisory control and data acquisition) environments used. It involves, for example, Siemens WinCC, GE Cimplicity, Advantech and other human machine interface (HMI) products.

Although attacks on industrial environments often with attacks by countries are linked, it would be here involve ordinary cybercriminals. "It's an interesting trend, traditional banking Trojans and no targeted attacks," Wilhoit as late versus Dark Reading know. According to the researcher criminals focus their sights on SCADA / ICS systems because they are unsafe.

Many HMI machines run on Windows and would not use a virus scanner or are not equipped with the latest signatures. Most malware Wilhoit encountered no problems would be detected by an up-to-date virus scanner. While targeted attacks are still at risk managers should also take into account normal "crimeware", as the consequences can be just as bad. HMI systems are very susceptible to interference. Infection by a banking Trojan can also just as easily get the system down.

Wilhoit saw in October for the first peak in the attacks, but does not know what the occasion is. The criminals behind the malware use spear phishing mails and drive-by downloads to infect computers. Fake websites are used on that instance, resemble those of Siemens and supposedly download a WinCC update, while it is actually malware. Wilhoit 32 recently discovered malware instances that occurred as WinCC software. Next week, the researcher during a conference SCADA give more details about his research.