News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

CRITICISM: OT and IoT network anomalies are ubiquitous 
CRITICISM: OT and IoT network anomalies are omnipresent - Image by Gerd Altmann on Pixabay

A new report shows that network anomalies and attacks are the most common threats to OT and IoT environments, especially in the area of ​​critical infrastructure. Vulnerabilities in critical production areas have increased by 230 percent. Nozomi Networks has released its latest Networks Labs OT & IoT Security Report. The experts' analysis shows that network anomalies and attacks represent the greatest threat to OT and IoT environments. Another reason for concern: vulnerabilities in critical production areas have increased by 230 percent. Therefore, cybercriminals have many more opportunities to access networks and cause these anomalies. Collected telemetry data…

Read more

China: Companies must report vulnerabilities – hackers are already waiting
B2B Cyber ​​Security ShortNews

By law, companies in China - including foreign ones - are obliged to immediately report vulnerabilities in systems and errors in codes to a government agency. However, experts warn that China uses state-controlled hackers and could use the information about the vulnerabilities to gain almost unhindered access to companies' systems. The Atlantic Council think tank has published a report analyzing the new Chinese regulation that requires companies to report security vulnerabilities and errors in code to a government Ministry of Industry and Information Technology (MIIT) within 48 hours.

Read more

Identified: Risky OT and ICS devices in KRITIS

Armis identifies and publishes a study on the most risky OT and ICS devices in critical infrastructure. It shows the threats to critical infrastructure in manufacturing, utilities and transportation. Data analyzed by the Armis Asset Intelligence and Security platform, which monitors more than three billion assets, revealed that the operational technology (OT) and industrial control systems (ICS) devices that pose the greatest risk to these industries are technical workstations , SCADA servers, automation servers, data historians and programmable logic controllers (PLCs). Prioritization and vulnerability management remain an issue Research found that technical workstations…

Read more

Slight decrease in attacks on industrial systems
Kaspersky_news

Kaspersky has evaluated the data from its industrial cybersecurity solutions (ICS-Cert). In the second half of 2, over 2022 malware families were detected and blocked. Overall, this is a slight decline compared to the first half of the year. Most attacks started with malicious scripts, phishing sites or spyware. In the second half of 1.300, Kaspersky's security solutions blocked malware from 1 different families on industrial systems in the areas of building automation, automotive, oil and gas, energy or mechanical engineering in the DACH region. Compared to the previous half year (2022 percent) and the second half of 1.292 (16 percent), the number has decreased. The…

Read more

Data feed to find vulnerabilities
Data feed to find vulnerabilities

Kaspersky Threat Intelligence now with expanded capabilities for threat data feed, threat analysis and brand protection. Introduced new Industrial Vulnerability Data Feed for detecting vulnerabilities. Kaspersky has added new features to its threat intelligence service. The new version of Kaspersky Threat Intelligence now offers a set of streamlined feeds that help better understand cybercriminal behavior, tactics, techniques and procedures, regardless of region and language. In addition, new functions have been integrated that enable the protection of corporate brands in social networks and online marketplaces. Vulnerabilities and Threat Analysis Cyber ​​criminals often unnoticed...

Read more

Novel OT and IoT endpoint security sensor
Novel OT and IoT endpoint security sensor

A new OT and IoT endpoint security sensor aims to provide more security. Nozomi Networks introduces the first security sensor for this area of ​​application, which is intended to drastically reduce operational reliability. Nozomi Arc aims to be the industry's first OT and IoT sensor to bring more security to the endpoint. This sensor dramatically shortens the time it takes to develop significantly higher resilience in operational use. Nozomi Arc is designed to be automatically deployed across a large number of locations and devices wherever a business needs more visibility. The new sensor also provides important data...

Read more

Thousands of solar and wind turbines with security gaps
B2B Cyber ​​Security ShortNews

Based on research by the Plusminus magazine, the Tagesschau published under the title “Easy game for hackers” that solar and wind power plants sometimes have massive security gaps. Above all, medium-sized and small systems are said to be poorly protected against hackers, which is also documented live in the article. In the contribution of the ARD magazine Plusminus, an expert from the field of renewable energies shows how poorly small and medium-sized solar and wind power plants are protected against hack attacks. For the contribution, the system expert searched partly live for vulnerable systems and quickly found what he was looking for. In minutes: access to wind farm for 50.000…

Read more

Detection of vulnerabilities in control systems
Kaspersky_news

More threat intelligence for industry: Kaspersky introduces new data feed for detecting vulnerabilities in SCADA and control systems. The feed contains damage control guides. It is delivered in XML format and integrates with vulnerability management solutions. Kaspersky now offers a machine-readable Open Vulnerability and Assessment Language (OVAL) data feed for the automatic detection of vulnerabilities in operational technology (OT) software. The Kaspersky Industrial OVAL Data Feed for Windows provides comprehensive information about vulnerabilities in the most popular SCADA and distributed control systems (DCS) based on data…

Read more

More spyware and phishing against industrial companies
More spyware and phishing against industrial companies

In the first half of 2022, malicious objects were blocked on 12 percent of OT (operational technology) computers in Germany, as current analyzes by Kaspersky ICS CERT show. Worldwide it was 32 percent. Building automation infrastructures are the most vulnerable. Malicious scripts and phishing sites (JS and HTML) were the most common victims of industrial companies. Above all, the infrastructure for building automation is confronted with these threats: About half of the computers worldwide (42 percent) were dealing with them in the first half of the year. This is believed to be because these systems may not be fully supported by…

Read more

Attacks on military-industrial organizations in Eastern Europe
Kaspersky_news

Kaspersky already identified attacks on military-industrial organizations and public institutions in Eastern Europe and Afghanistan in early August. The malware used is similar to that of a Chinese-speaking APT group. Kaspersky ICS CERT has identified a series of targeted attacks against industrial plants, research institutes, government agencies, ministries and offices in several Eastern European countries, including Russia, Ukraine and Belarus, as well as in Afghanistan. The APT actors were able to take control of the victims' entire IT infrastructure and engage in industrial espionage. Attacks on military companies and organizations In January 2022, Kaspersky experts discovered several advanced attacks on military companies and public organizations,…

Read more