ICT Security-Sécurité PC et Internet
87.1K views | +0 today
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

Urgent11 security flaws impact routers, printers, SCADA, and many IoT devices | #CyberSecurity 

Urgent11 security flaws impact routers, printers, SCADA, and many IoT devices | #CyberSecurity  | ICT Security-Sécurité PC et Internet | Scoop.it

Security researchers have disclosed details today about 11 vulnerabilities known collectively as "Urgent11" that impact a wide range of devices, from routers to medical systems, and from printers to industrial equipment.

The vulnerabilities affect VxWorks, a real-time operating system created by Wind River.

Real-time operating systems (RTOSes) are simple pieces of software with very few features that are deployed on chipsets with access to a limited amount of resources, such as the chipsets used in modern Internet of Things (IoT) devices -- where the chipsets only need to manage input/output operations, with little data processing and no need for a visual interface.

Among all RTOS versions, VxWorks is today's most popular product, deployed on more than two billion devices, according to Wind River's website. However, in its 32-year history, only 13 security flaws with a MITRE-asigned CVE have been found in the VxWorks RTOS.

VxWorks' popularity and the lack of any attention from the security community were the two reasons why experts from IoT cybersecurity firm Armis decided to analyze the OS for security flaws, the company told ZDNet in a phone call last week.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet/?&tag=Urgent11

 

https://www.scoop.it/topic/securite-pc-et-internet

 

 

Gust MEES's insight:

Security researchers have disclosed details today about 11 vulnerabilities known collectively as "Urgent11" that impact a wide range of devices, from routers to medical systems, and from printers to industrial equipment.

The vulnerabilities affect VxWorks, a real-time operating system created by Wind River.

Real-time operating systems (RTOSes) are simple pieces of software with very few features that are deployed on chipsets with access to a limited amount of resources, such as the chipsets used in modern Internet of Things (IoT) devices -- where the chipsets only need to manage input/output operations, with little data processing and no need for a visual interface.

Among all RTOS versions, VxWorks is today's most popular product, deployed on more than two billion devices, according to Wind River's website. However, in its 32-year history, only 13 security flaws with a MITRE-asigned CVE have been found in the VxWorks RTOS.

VxWorks' popularity and the lack of any attention from the security community were the two reasons why experts from IoT cybersecurity firm Armis decided to analyze the OS for security flaws, the company told ZDNet in a phone call last week.

 

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet/?&tag=Urgent11

 

https://www.scoop.it/topic/securite-pc-et-internet

 

 

No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Cybersecurity de Système de contrôle SCADA – bilan d’un workshop international au Luxembourg

Cybersecurity de Système de contrôle SCADA – bilan d’un workshop international au Luxembourg | ICT Security-Sécurité PC et Internet | Scoop.it

Dans le cadre du projet Européen CockpitCI «Cybersecurity on SCADA: risk prediction, analysis and reaction tools for Critical Infrastructure», itrust consulting et CREOS, sous le patronage du ministre de l’Économie et du …


Aujourd’hui, les infrastructures critiques, comme les réseaux électriques, d’eau, de gaz, ne sont pas à l’abri des menaces de piratages informatiques. Le projet de recherche européen CockpitCI, démarré il y a deux ans, vise à concevoir un cadre et des outils permettant de détecter, d’analyser et d’échanger en temps réel des informations sur des cyberattaques, afin d’en évaluer les risques et d’éviter les effets redoutés de domino.


Les expérimentations (Aurora experiment) et récentes attaques (Stuxnet, Duqu, Red October) ont montré que les différents réseaux et les systèmes industriels de contrôle sous-jacents (souvent appelé SCADA, acronyme pour Supervisory Control And Data Acquisition) sont potentiellement menacés et que seules une vigilance et une supervision accrue et globale permettront de mettre en sécurité ces infrastructures indispensables au bon fonctionnement des institutions et de secteurs vitaux européens.


Il est donc essentiel que les opérateurs puissent rapidement identifier les risques potentiels à la qualité de service, afin de mettre en place des mesures de prévention et de confinement d’une attaque.



Gust MEES's insight:


Il est donc essentiel que les opérateurs puissent rapidement identifier les risques potentiels à la qualité de service, afin de mettre en place des mesures de prévention et de confinement d’une attaque.


Gust MEES's curator insight, March 26, 2014 1:43 PM


Il est donc essentiel que les opérateurs puissent rapidement identifier les risques potentiels à la qualité de service, afin de mettre en place des mesures de prévention et de confinement d’une attaque.


Scooped by Gust MEES
Scoop.it!

US warns over key computer systems

US warns over key computer systems | ICT Security-Sécurité PC et Internet | Scoop.it
Thousands of US companies are being told to beef up protection on computers that oversee critical infrastructure.
Gust MEES's insight:

In total, the survey uncovered more than 500,000 potential targets.


Scada (Supervisory Control and Data Acquisition) is the industry term for the computers behind the machinery in power plants, water treatment centres, traffic controls and other utilities.


                  ===> Be AWARE of the MALWARE! <===



No comment yet.
Scooped by Gust MEES
Scoop.it!

Warm welcome to the 3rd CockpitCI Workshop in Luxembourg - A European FP7 Project - CockpitCI

Warm welcome to the 3rd CockpitCI Workshop in Luxembourg - A European FP7 Project - CockpitCI | ICT Security-Sécurité PC et Internet | Scoop.it

The Luxembourg newspapers and magasines have reserved a warm welcome to the 3rd CockpitCI Workshop in Luxembourg. The cyber security and the Critical Infrastructure dependability are considered as an important...


Learn more:



Gust MEES's insight:


Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

SCADA password cracking code available

SCADA password cracking code available | ICT Security-Sécurité PC et Internet | Scoop.it

ICS-CERT has issued an alert about the existence and general availability of the proof-of-concept exploit code for a tool that can brute force passwords and thus gain access and control of programmable logic controllers (PLCs).

The authors of the Python code in question are Alexander Timorin and Dmitry Sklyarov of SCADA Strange Love research group, and have unfortunately made the code available before the Siemens had the opportunity patch the flaw or offer mitigations.


Gust MEES's insight:

ALERT!

 

No comment yet.