Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Microsoft Says Attackers Are Hacking Energy Grids By Exploiting Decades-Old Software

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Microsoft Says Attackers Are Hacking Energy Grids By Exploiting Decades-Old Software


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: it.slashdot.org

An anonymous reader quotes a report from TechCrunch: Microsoft has warned that malicious hackers are exploiting a discontinued web server found in common Internet of Things (IoT) devices to target organizations in the energy sector. In an analysis published on Tuesday, Microsoft researchers said they had discovered a vulnerable open-source component in the Boa web server, which is still widely used in a range of routers and security cameras, as well as popular software development kits (SDKs), despite the software's retirement in 2005. The technology giant identified the component while investigating a suspected Indian electric grid intrusion first detailed by Recorded Future in April, where Chinese state-sponsored attackers used IoT devices to gain a foothold on operational technology (OT) networks, used to monitor and control physical industrial systems. Microsoft said it has identified one million internet-exposed Boa server components globally over the span of a one-week period, warning that the vulnerable component poses a "supply chain risk that may affect millions of organizations and devices." The company added that it continues to see attackers attempting to exploit Boa flaws, which include a high-severity information disclosure bug (CVE-2021-33558) and another arbitrary file access flaw (CVE-2017-9833). "The known [vulnerabilities] impacting such components can allow an attacker to collect information about network assets before initiating attacks, and to gain access to a network undetected by obtaining valid credentials," Microsoft said, adding that this can allow the attackers to have a "much greater impact" once the attack is initiated. "The company has warned that mitigating these Boa flaws is difficult due to both the continued popularity of the now-defunct web server and the complex nature of how it is built into the IoT device supply chain," reports TechCrunch. "Microsoft recommends that organizations and network operators patch vulnerable devices where possible, identify devices with vulnerable components, and to configure detection rules to identify malicious activity."

Read more of this story at Slashdot.

...



๐Ÿ“Œ Cybersecurity Is Necessary for Mission-Critical Energy Grids


๐Ÿ“ˆ 30.39 Punkte

๐Ÿ“Œ What Are the Top 7 DDoS Mitigation Tactics for Energy Grids?


๐Ÿ“ˆ 30.39 Punkte

๐Ÿ“Œ An Energy Breakthrough Could Store Solar Power For Decades


๐Ÿ“ˆ 27.4 Punkte

๐Ÿ“Œ Energy Bills To Rise More Than Predicted, Says UK Energy Regulator Ofgem Boss


๐Ÿ“ˆ 26.38 Punkte

๐Ÿ“Œ Dewan Chowdhury on Hacking Power Grids


๐Ÿ“ˆ 26.31 Punkte

๐Ÿ“Œ Dewan Chowdhury on Hacking Power Grids


๐Ÿ“ˆ 26.31 Punkte

๐Ÿ“Œ Highly Dangerous Hacking Group Is Now Targeting Power Grids


๐Ÿ“ˆ 26.31 Punkte

๐Ÿ“Œ GALLIUM Hacking Group Attack Telecom Networks Using Publicly Available Hacking Tools & Exploiting Unpatched Vulnerabilities


๐Ÿ“ˆ 23.33 Punkte

๐Ÿ“Œ Russian Cybercriminal Faces Decades in Prison for Hacking and Trading Operation


๐Ÿ“ˆ 23.33 Punkte

๐Ÿ“Œ Billionaire Jack Ma Says CEOs Could Be Robots in 30 Years, Warns of Decades of 'Pain' From AI


๐Ÿ“ˆ 23.21 Punkte

๐Ÿ“Œ Lossmaking Giant Uber, Hoping To Stay Around For Decades, Says It is Aiming For 100% Zero-Emission Transport by 2040


๐Ÿ“ˆ 23.21 Punkte

๐Ÿ“Œ Microsoft Warns Attackers Are Exploiting Zero Day In Internet Explorer Scripting Engine


๐Ÿ“ˆ 22.54 Punkte

๐Ÿ“Œ In Hacking Competitions (or in Real Life), What Stops Red Team From Exploiting Blue Team's Detection Software and/or Computer?


๐Ÿ“ˆ 21.55 Punkte

๐Ÿ“Œ After almost two decades, the Mars Express gets a software update


๐Ÿ“ˆ 21.55 Punkte

๐Ÿ“Œ Ransomware Attack Hits Ukrainian Energy Ministry, Exploiting Drupalgeddon2


๐Ÿ“ˆ 21.29 Punkte

๐Ÿ“Œ Attackers Actively Exploiting Android StrandHogg Vulnerability To Steal Banking Credentials


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers Exploiting High-Severity Network Security Flaw, Cisco Warns


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers Exploiting High-Severity Network Security Flaw, Cisco Warns


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers exploiting the Instagram verification program to steal userโ€™s data


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers are exploiting a linux exim critical flaw to execute remote commands, download crypto miners and sniff out other vulnerable servers.


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ It didn't take long for attackers to start exploiting the recently publicly revealed exim vulnerability (cve-2019-10149).


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers exploiting a zero-day in Sophos firewalls, have yours been hit?


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attivo Networksโ€™ enhanced EDN solution prevents attackers from seeing or exploiting production data


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers are exploiting Cisco ASA/FTD flaw in search for sensitive data


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers Are Already Exploiting ChatGPT to Write Malicious Code


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ North Korean Attackers Exploiting Critical CI/CD Vulnerability


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers Exploiting Critical F5 BIG-IP Vulnerability


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers are exploiting two zero-day flaws in Cisco enterprise-grade routers


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers Exploiting WebLogic Servers via CVE-2020-14882 to install Cobalt Strike, (Tue, Nov 3rd)


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ Attackers are exploiting zero-day in Pulse Secure VPNs to breach orgs (CVE-2021-22893)


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ CISA warns of attackers now exploiting Windows Print Spooler bug


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ How attackers are exploiting corporate IoT


๐Ÿ“ˆ 20.61 Punkte

๐Ÿ“Œ State-sponsored attackers actively exploiting RCE in Citrix devices, patch ASAP! (CVE-2022-27518)


๐Ÿ“ˆ 20.61 Punkte











matomo