АНУ-ын ус хангамжийн байгууллагууд нууц үг хулгайлах хортой програмын эрсдэлд оржээ

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

Кибер аюулгүй байдлын SpyCloud компанийн судалгаагаар АНУ-ын ус болон бохир усны менежмент эрхэлдэг 1,700 гаруй байгууллагын ажилтнуудын нэвтрэх эрх алдагдсан нь тогтоогдсон байна.

SpyCloud компани АНУ-ын Байгаль орчныг хамгаалах агентлагт бүртгэлтэй 10,000 орчим байгууллагын мэдээлэлд дүн шинжилгээ хийхэд 1,787 байгууллагын нууц үг, нэвтрэх эрх “infostealer” буюу мэдээлэл хулгайлдаг хортой програмын халдлагад өртсөнийг илрүүлжээ. Үүнээс 250 орчим байгууллагын нэвтрэх эрх нь усны насос болон урсгалыг хянах үйл ажиллагааны сүлжээнд нэвтрэх боломжийг хакеруудад олгож болзошгүй байгаа аж.

Тус судалгаагаар усны тоолуур нийлүүлэгч нэгэн компанийн сүлжээнд халдсан хортой программ нь тус үйлчилгээг ашигладаг 167 ус хангамжийн байгууллагын итгэмжлэлийг хулгайлсан тохиолдол бүртгэгдсэн байна. SpyCloud-ын мөрдөн шалгах албаны дарга Жейсон Ланкастерын тайлбарласнаар, энэ төрлийн ганцхан халдлага нь хоорондоо хамааралгүй олон байгууллагын системд нэвтрэх түлхүүрийг гэмт хэрэгтнүүдийн гарт өгөх аюултай юм.

Мэдээлэл хулгайлдаг хортой програмууд нь зөвхөн нууц үг төдийгүй нэвтрэлт идэвхтэй байх хугацааг тодорхойлогч “session token”-ийг хулгайлдаг тул олон хүчин зүйлт баталгаажуулалтыг (MFA) тойрч гарах боломжийг хакеруудад олгодог. Энэхүү судалгаа нь сүүлийн үед АНУ-ын дэд бүтцийн байгууллагууд руу чиглэсэн кибер халдлагууд нэмэгдэж байгаатай холбоотой бөгөөд засгийн газрын зүгээс эдгээр халдлагыг Ираны талтай холбоотой байж болзошгүй хэмээн үзэж байгаа юм.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

New security research has found that well over a thousand U.S. water and wastewater providers are exposed to hacks due to malware that’s capable of stealing their employees’ passwords and active logged-in sessions.

The findings by cybersecurity defense firm SpyCloud underscore how water providers and other critical infrastructure can be compromised with relative ease amidst a wave of hacks targeting the water supplies of dozens of communities across the United States.

While password-stealing malware is not new, the research highlights how stolen passwords offer hackers an easy route to break into an organization’s network without using AI tools.

SpyCloud said it built a database of more than 66,000 public-facing systems that are registered with the U.S. Environmental Protection Agency, amounting to 10,000 organizations. The company found password-stealing malware had swiped passwords and credentials from 1,787 organizations, or nearly two in ten providers they checked. The firm noted at least 250 organizations had credentials exposed that appeared to allow access to their operational networks and remote-access systems, which control the physical pumps and water flows.

The analysis covered an unnamed metering tech provider, which had a device on its network that was infected with password-stealing malware. The malware stole reams of credentials, including passwords for 167 U.S. utility companies that rely on the metering tech provider.

SpyCloud chief investigations officer Jason Lancaster said in the post that this single breach handed criminals the keys to access “a hundred otherwise unrelated organizations.”

Password-stealing malware, also known as infostealers, allow hackers to steal a person’s stored passwords as well as the session tokens that are used to keep them logged in. These session tokens can allow a hacker to log in as if they were the legitimate user, and can often bypass multi-factor authentication systems. Hackers regularly trade stolen credentials in order to obtain passwords or session tokens for accessing specific organizations.

This research comes weeks after a spate of hacks targeting water providers around the United States, which the U.S. government has privately tied to Iran-backed hackers. SpyCloud said it found no evidence that those Iran-linked hacks relied on stolen passwords. In those cases, the signs point to security weaknesses, such as manufacturer-set default passwords, in the mechanical switches and physical controllers used by critical infrastructure, SpyCloud said, echoing earlier findings from U.S. cybersecurity agency CISA.

Rather, the researchers note that stolen passwords are a major source of access to “whoever wants to buy or find it,” in parallel to the known security risks with critical infrastructure tech. Lancaster said that the water-sector “has to hold both stories at once.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img