Tuesday, May 26, 2020

What I'm Reading 5/26/2020 - SCADA Vulnerabilities Again

ZDNet - It's time to spin AWS out of Amazon: They regulate utilities, don't they? -
Now, I'd be surprised if AWS hasn't offered all kinds of promises and assurances that such critical competitive data isn't available to the rest of Amazon. But if centuries of corporate misbehavior have taught us anything, it is that companies are quite willing to lie for their own benefit, especially when the bottom line is threatened. Maybe not today, but when times get tough.

There's another competitive issue: Amazon runs on AWS, so it gains a competitive advantage not only from its own scale, but from the scale of AWS too. If you want to compete with Amazon, your webservice also has to compete with AWS. That isn't fair.

Finally, AWS has much higher profitability than Amazon's retail business. Why shouldn't Amazon's retail business have to compete without what is, in effect, the subsidy it gets from AWS income?
Sweden's controversial approach to fighting the coronavirus pandemic has so far failed to produce the expected results, and there are calls within the country for the government to change its strategy.

...

Unfortunately, Sweden's capital will not reach this milestone in May.

"No that will not happen," Tegnell said on Monday in an email to NPR. "Current investigations show different numbers, but [Stockholm's immunity rate] is likely lower [than 30%]. As you might be aware, there is a problem with measuring immunity for this virus."

The consequences could affect how quickly improved internet access is rolled out and how much it will cost. This a time when the country's economy is already in a precarious state because of the coronavirus pandemic.

...

"Removing Huawei would seriously delay 5G, costing the British economy up to £7bn," he added, citing a study published last year by Mobile UK, a trade group that represents UK network operators.

...

A study commissioned by Huawei last year claimed locking it out would increase a country's 5G investment costs by between 8% and 29% due to reduced competition.

A researcher from Kaspersky has identified several vulnerabilities in Emerson OpenEnterprise, a supervisory control and data acquisition (SCADA) solution designed for the oil and gas industry.

Roman Lozko, a researcher at Kaspersky’s ICS CERT unit, discovered four vulnerabilities in Emerson OpenEnterprise. The security flaws were reported to the vendor in December 2019 and patches were released a few months later.
Security Boulevard -  IEC 61850 Meets IEC 62351: Securing GOOSE Power Grid Weaknesses  -

IEC 61850, the international standard for digital substation architecture, tooling standardization, and protocols at electrical substations, is a big win for standardization and ICS security. It has been adopted worldwide, enabling utilities and operators to efficiently commission, interoperate and maintain new equipment.

However, one of its communication protocols, GOOSE, although effective, has displayed several security issues. While many researchers around the world have put forward proposals to address the problem, IEC has already defined a standard way to tackle such defects. 

...

IEC 62351-6 outlines a way to secure IEC 61850 protocols and GOOSE messages by adding a security extension section to the frames.

ZDNet - Turla hacker group steals antivirus logs to see if its malware was detected -
The January 2020 attacks, however, stood out due to the deployment of an updated version of the ComRAT malware, which ESET says contained some pretty clever new features.

...

The latest version, known as ComRAT v4, was first seen in 2017, however, in a report published today, ESET says they've spotted a variation of ComRAT v4 that includes two new features, such as the ability to exfiltrate antivirus logs and the ability to control the malware using a Gmail inbox.

YouTube is automatically deleting comments that contain certain Chinese-language phrases related to criticism of the country’s ruling Communist Party (CCP).

Comments left under videos or in live streams that contain the words “共匪” (“communist bandit”) or “五毛” (“50-cent party”) are automatically deleted in around 15 seconds, though their English language translations and Romanized Pinyin equivalents are not.

 

 

No comments: