Energy, telecom, finance, and water infrastructures continue to expand, but how well are they protected? Explore the latest advances and vulnerabilities in the frameworks that keep your organization up and running, whether it’s a regional network or the national power grid.
Intel and McAfee welcome European Union resolve to fight cyber threats By David Hoffman, Raj Samani and Christoph Luykx Today, the European Commission and the EU’s External Action Service (EEAS) presented its response to the growing threats presented in cyberspace by releasing a policy document (the “Communication”), outlining the longer term required actions together with Read more…
Tags: Cybercrime, cybersecurity, EMEA, global threat intelligence, public policy, Public-Private partnerships
Cloud computing continues to be a hot topic. But so what if people are talking about it, who is actually adopting it? One of the questions I have been asking myself is, ‘Will cloud be adopted for critical infrastructure? And what is the security perspective on this? Naturally a blog to answer that question will Read more…
Iranian infrastructure has been on the radar of cyberattackers for a couple of years. We have already witnessed organized and sophisticated attacks such as Stuxnet, Duqu, and similar assaults. Now we have seen yet another attack against Iran, this one primarily targeting the Microsoft SQL Server databases of some Iranian financial software. This attack has Read more…
Tags: Data Protection, financial software, Iran, malware, McAfee Labs, Microsoft SQL Server database, Narilam, trojan
Late last week, reports began to surface that the Israeli police (along with other regional law enforcement) were targeted by a malware attack. The entry vector was described as a phishing campaign sent from Benny Gantz (head of the Israeli Defense Forces). Initially, details and indicators around the malware were beyond sparse. Aside from the FROM: address, Read more…
Tags: antivirus, Cyber Security Mom, Endpoint Protection, global threat intelligence, internet security, Israel, labs, malware, McAfee Labs, Network Security, phishing, security, spam, ValidEdge, web protection, XtremeRAT
News broke today of a large data breach against Yahoo Voices, resulting in more than 400,000 username/password combinations being posted in clear text. The compromise involved a basic SQL-injection attack against an exposed Yahoo server (dbb1.ac.bf1.yahoo.com). Similar to other recent events, the account data was reportedly stored in an unencrypted state. We see this type of attack Read more…
Tags: Database, sql attacks, SQL Injection, Yahoo!
The ICS-CERT recently released the “ICS-CERT Incident Response Summary Report,” which quantifies known industrial control system cyber security incidents from 2009 to 2011. The report offers a very useful summary of threats, and provides some eye-opening metrics. One finding across all reported incidents was that “an organization’s technology can result in cyber security gaps,” which Read more…
Tags: critical infrastructure, energy
Earlier this year I was given the opportunity of presenting the concept of cloud computing to delegates from the Chemical industry. I remember when I put the title slide up, and then made the bold claim that – Cloud computing, and in particular public Cloud Service Providers should be considered for ALL sectors even those Read more…
Tags: cloud, critical infrastructure
Applying cyber security measures to industrial control systems represents some unique challenges. How do you obtain situational awareness across zones while enforcing the maximum possible level of network separation? How do you protect against malware while limiting the application of patches and updates to real-time systems? If a system is compromised in some way, how Read more…
Tags: critical infrastructure, energy, substation
McAfee has developed an Anti Virus solution to protect our customer’s data storage devices. Jim Waggoner, CISSP, Director of Product Management for McAfee discusses the new McAfee AV solution developed for NetApp ONTAP 8.1 which is pre loaded on every NetApp ONTAP device. Read about this exciting new development at the NetApp Community Forum! How to Read more…
In early April, I wrote about the famed “LizaMoon” SQL-injection attacks. I said it then, and I’ll say it again now: SQL-injection (SQLi) attacks are a constant. Some of these attacks are more visible than others. Some adversaries find intelligent ways to hide their tracks so as not to splatter evidence of their misdeeds all over various search Read more…
Tags: Cybercrime, Data Protection, database security, enterprise, lizamoon, malware, mass sql injection, Network Security, sql attacks, SQL Injection, urchin.js
Posts in Critical Infrastructure Protection