ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

SCADA exploits circulating

criticalExploit / PoCimportance 60
Full article360 words · extracted from securelist.com · click to collapse

Industrial threats

Industrial threats

23 Mar 2011

minute read

Ever since Stuxnet hit the news last year, there has been an increased interest in the area of industrial control systems (ICS). This has been evidenced by the fact that we’ve seen a recent surge in public releases of zero-day (unpatched) vulnerabilities and exploits.

Earlier this week, we saw no less than 34 unpatched vulnerabilities posted to Bugtraq.
In the original article by The Register, there’s also mention of a SCADA exploit pack which is currently for sale to pen-testers.

I’m against full disclosure, but these developments clearly show that there’s a continued interest into these systems that are in charge of critical infrastructure — from traffic lights to power grids to airport control systems.

This field has some very interesting challenges. Reliability/uptime is the core focus in ICS/SCADA and security has been something of an afterthought.

There are companies out there who have uptimes of 28(+) years. That means they’re running an OS developed some 30 years ago. This also means that unless something changes it could take another decade (or two) before serious security changes are made.

Industrial Control Systems are right on the edge of the private-public line. Critical infrastructure is run by companies who serve the public. For many of these businesses, government regulation is driving their security effort.

Governments aren’t necessarily known for moving quickly, but the main push for better ICS/SCADA security will have to come from them.

Hopefully the media coverage around these vulnerabilities will help drive the issue.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/scada-exploits-circulating/29778/