Nation-state hackers hit Cisco switches

Hackers, some of them backed by a nation-state, have attacked Cisco switches in multiple countries, the tech giant’s cyberthreat intelligence division has revealed. Some of the attacks “are believed to be associated with nation-state actors, such as those described” in a recent Department of Homeland Security report that said Russian government hackers were targeting multiple U.S. industries, Cisco said. The campaign disclosed by Cisco exploits a protocol in a tool called Cisco Smart Install Client that installs switches. The protocol can be abused to conduct a series of actions, including modifying a server setting, to let an attacker execute Cisco networking software commands. Cisco used the scanning tool Shodan to identify more than 168,000 systems that could be vulnerable to this attack. A March 15 DHS report blamed Russian government hackers for a multi-stage hacking campaign against the nuclear, critical manufacturing, and other U.S. sectors. The U.S. effort to call out alleged […]

The post Nation-state hackers hit Cisco switches appeared first on Cyberscoop.

Continue reading Nation-state hackers hit Cisco switches

White House email domains are sitting ducks for phishing attacks: study

The White House’s delay in implementing an important email security protocol leaves its domain names vulnerable to being used in a large-scale phishing attack, according to a new study. Only one of the 26 email domains managed by the Executive Office of the President (EOP) uses the Domain-based Message, Authentication, Reporting and Conformance (DMARC) protocol to block phishing attempts, the nonprofit Global Cyber Alliance said. Eighteen of those domains haven’t started deploying DMARC. A Department of Homeland Security directive gave federal agencies until Jan. 15 to implement DMARC, which creates a public record for checking whether an email sender is authorized to transmit a message on behalf of a domain. Spokespeople for DHS and the National Security Council did not respond to questions on whether the directive applies to the EOP. The White House has previously claimed it was exempt from a governmentwide-reporting requirement under an IT security law. Email domains […]

The post White House email domains are sitting ducks for phishing attacks: study appeared first on Cyberscoop.

Continue reading White House email domains are sitting ducks for phishing attacks: study

DARPA is looking to avoid another version of Meltdown or Spectre

The Defense Advanced Research Projects Agency has contracted Tortuga Logic to develop hardware security tools that use commercial testing platforms to catch vulnerabilities in computer chips before they are deployed, the firm announced. The goal of the contract, awarded by the Pentagon’s R&D arm, is to prevent a repeat of Meltdown and Spectre, the security vulnerabilities revealed in January that affected virtually all modern computer chips. The contract is part of a DARPA hardware and firmware program that strives to make chips more secure at the “microarchitecture level.” DARPA says the program, which is tackling seven classes of hardware vulnerabilities, supports security methods that limit “hardware to states that are assured to be secure while maintaining the performance and power required for system operation.” Tortuga Logic says it can verify hardware security throughout the design process, arguing in a recent white paper that such verification is much more common in […]

The post DARPA is looking to avoid another version of Meltdown or Spectre appeared first on Cyberscoop.

Continue reading DARPA is looking to avoid another version of Meltdown or Spectre

DHS says unauthorized Stingrays could be in D.C. area

The Department of Homeland Security has acknowledged the presence of what appear to be unauthorized  mobile surveillance devices in the Washington, D.C. area and elsewhere in the United States that could be exploited by foreign spies to track and intercept phone calls. The devices, often referred to as Stingrays after a popular model made by Harris Corp., imitate a cell tower to capture caller location and other associated data. While they have been used by U.S. law enforcement for years, their use for foreign espionage in the U.S. has been a source of speculation. In a March 26 letter to Sen. Ron Wyden, D-Ore., obtained by CyberScoop and other news outlets, DHS’s National Protection and Programs Directorate said the department has observed “anomalous activity” in or near the nation’s capital that “appears to be consistent” with such surveillance devices, which are also called international mobile subscriber identity (IMSI) catchers. The NPPD has not validated or attributed […]

The post DHS says unauthorized Stingrays could be in D.C. area appeared first on Cyberscoop.

Continue reading DHS says unauthorized Stingrays could be in D.C. area

Major U.S. pipeline disrupted by cyberattack on transaction software

A supply chain cyberattack has disrupted a chain of U.S. natural gas companies, according to multiple news reports. It affected a software platform, developed by a company named Energy Services Group LLC, that is used to process customer transactions, according to Bloomberg News. Such data-exchange software is widely used in the gas industry, though the attack was limited to the Energy Services platform. The attack on the billing platform impacted Texas-based Energy Transfer Partners LP, which owns more than 71,000 miles of pipelines containing natural gas, crude oil and other commodities. The Texas firm’s subsidiaries include the Panhandle Eastern Pipe Line Co., whose pipelines run from the Gulf Coast to the Midwest. “There was an attack on a third-party service provider,” a Energy Transfer Partners spokesperson confirmed in an email to CyberScoop. “This situation has not impacted our operations as we are handling all scheduling in-house during this time.” The […]

The post Major U.S. pipeline disrupted by cyberattack on transaction software appeared first on Cyberscoop.

Continue reading Major U.S. pipeline disrupted by cyberattack on transaction software

Electric grid hacking exercise reveals shortfalls of security clearance shortage

As foreign hackers continue to probe the U.S. grid for weaknesses, a cyber exercise for the North American energy sector has shown that many utility personnel still lack access to the classified information needed to stay on top of the threat. Not enough utility employees had the clearances needed to share threat information for a serious cyberattack scenario rehearsed during the exercise, according to a report published Friday by regulator North American Electric Reliability Corp. (NERC). “Government should plan to quickly declassify information that utilities need to prevent or respond to attacks,” the report states. During the two-day exercise, which took place in November, government officials and utility executives worked together to respond to simulated “cyber and physical attacks” against control systems and generation and transmission facilities “that caused widespread and prolonged power outages,” the report notes. Energy industry officials have long urged the U.S. government to expedite the clearance […]

The post Electric grid hacking exercise reveals shortfalls of security clearance shortage appeared first on Cyberscoop.

Continue reading Electric grid hacking exercise reveals shortfalls of security clearance shortage

Here’s how much money states will receive for election security upgrades

The Trump administration has told states exactly how much of a $380 million fund they will get to make their voting systems more cyber-secure ahead of the 2018 midterm elections. The funding, made available through a $1.3 trillion omnibus package passed last week, is one of Congress’s first major steps to prevent a repeat of Russian hackers’ meddling in U.S. elections. The money can be used to upgrade state computer systems and offer cybersecurity training to election officials, among other things. California, Florida, New York and Texas together will get a quarter of the cash, with California leading the pack with about $35 million. A full breakdown of the funding can be found here. The money is a “breakthrough for election security and the health of our country’s democracy,” said Lawrence Norden of the Brennan Center for Justice at NYU Law. Lawmakers hailed their slice of the pie. “This federal […]

The post Here’s how much money states will receive for election security upgrades appeared first on Cyberscoop.

Continue reading Here’s how much money states will receive for election security upgrades

Microsoft’s Meltdown patches introduced a whole new vulnerability

Microsoft’s early patches for the Meltdown chip flaw have introduced an even more serious vulnerability in Windows 7 that allows attackers to read kernel memory much faster and to write their own memory, according to an independent security researcher. The discovery is the latest twist in a monthslong saga around Meltdown and Spectre, which together have affected virtually all modern computer chips. The researcher, Ulf Frisk, discovered that the Microsoft-issued Windows 7 patches could allow an attacker to access every user-level computing process running on a machine. Normally, the hierarchy of Microsoft’s memory management would keep a number of operations secured on the kernel level. An attacker would need a foothold into a computing system in order to exploit the vulnerability. But once that foothold is established, “no fancy exploits” are needed, Frisk said. “Windows 7 already did the hard work of mapping in the required memory into every running […]

The post Microsoft’s Meltdown patches introduced a whole new vulnerability appeared first on Cyberscoop.

Continue reading Microsoft’s Meltdown patches introduced a whole new vulnerability

Potential for backdoors in foreign telecom gear draws FCC’s attention

Federal Communications Commission Chairman Ajit Pai wants to inhibit U.S. telecommunications providers from buying equipment and services he says could give foreign-government hackers a foothold in U.S. networks. A draft FCC proposal, released Tuesday, would prevent companies from using the commission’s $8.5 billion Universal Service Fund (USF) to buy routers, switches, and other gear from companies that “pose a national security threat to United States communications networks or the communications supply chain,” the FCC said in a statement. Backdoors in networking equipment “can provide an avenue for hostile governments to inject viruses, launch denial-of-service attacks, steal data, and more,” Pai said. The USF helps telecoms companies provide service in high-cost and rural areas in the U.S. The FCC plans to vote on the proposal April 17.  The proposal wouldn’t be a blanket ban on buying such gear, because telecoms could use their own funds to do so rather than drawing from the USF, an FCC […]

The post Potential for backdoors in foreign telecom gear draws FCC’s attention appeared first on Cyberscoop.

Continue reading Potential for backdoors in foreign telecom gear draws FCC’s attention