Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
41–50 of 404 posts
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#42Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#43Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…
Edit to say: this is for MS files like Excel docs
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#44Earlier quoted context omitted.
Wasn't the internet literally created by the military for military comms? The decentralized routing was in part to ensure that comms could survive some areas being taken out by nuclear weapons.
As the effect of yesterday's AWS event demonstrates, the major Amazon, Microsoft, and Google data centers are surely top tier targets in every adversary's war plans. The decentralized internet is less of a reality today than it was years ago.
The web though I agree isn't very decentralized.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#45Earlier quoted context omitted.
Every public IPv4 address is port scanned multiple times a day.
Watching my website's firewall and ssh logs show all the various hacking attempts is calming in the same way that watching waves crash on to the shore is.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#46Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#47There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.
> OT cybersecurity specialists interviewed by CSO say that KCNSC’s production systems are likely air-gapped or otherwise isolated from corporate IT networks, significantly reducing the risk of direct crossover. Nevertheless, they caution against assuming such isolation guarantees safety.
This was also not a nuclear facility, however. The article says it makes "non-nuclear components".
In my experience auditing critical infrastructure, most facilities are "air gapped". I put that in quotes because while you can't browse the Internet from the control network(s), there are ways to exfiltrate data. The managers, engineers, regulators, and vendors need to know what is going on in real-time. Back in the day this could've been a serial port connecting two systems for a one-way feed. Now I imagine it's something far more sophisticated and probably more susceptible to abuse.
As an example, you might have a collection of turbines manufactured by GE and GE needs to have real-time data coming from them for safety monitoring and maintenance. The turbines might have one connection for control traffic and another for monitoring. How to secure these vendor connections was always a debate.
Btw, there are strong cybersecurity regulations around critical infrastructure. CIP-005-07 covers security perimeters. You can view them here: https://www.nerc.com/pa/Stand/Reliability%20Standards%20Comp...
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#48Earlier quoted context omitted.
Which really isn't a problem, unless you're being scanned so much your bandwidth is being overwhelmed. Certainly not the case for me, despite having port 80 and 443 open
I have a server that has a slow (5s) response to unknown pages, returns it as 200, and makes the next failing request even slower (for unauthenticated users). That seems to keep the number of requests limited. Perhaps I should just drop the connection after a certain number of requests. BTW, quite a few of these port scanners are companies that offer to scan your ports for vulnerabilities. Temu pen testing, so to spe…
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#49Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#50Then according to this report, 'sometime in August' the exploit is used against the Honeywell-managed nuclear facility, since it wasn't patched, if I read correctly? So it really could have been anyone, and it's hardly just Russia and China who have a record of conducting nuclear espionage in the USA using their nation-state cybercapabilities (Israel?). As the article notes:
> "The transition from zero-day to N-day status, they say, opened a window for secondary actors to exploit systems that had not yet applied the patches."
Also this sounds like basically everything that goes into modern nuclear weapons, including the design blueprints. Incredible levels of incompetence here.
> "Located in Missouri, the KCNSC manufactures non-nuclear mechanical, electronic, and engineered material components used in US nuclear defense systems."