In-brief: Software security holes in widely used industrial equipment known as “power quality analysers” (sp) could enable remote attackers to disrupt or corrupt operations at firms across industries, according to a report released by the firm Applied Risk.
Search Results for "firmware"
Realtors, OTA Publish Provisioning Checklist for Smart Homes
In-brief: smart homes aren’t just sold – they must also be ‘de-provisioned’ by the seller and ‘re-provisioned’ by the buyer. The National Association of Realtors and the Online Trust Alliance have a new checklist for doing so.
House Committee to discuss Bill to outlaw Car Hacking
In-brief: The U.S. House of Representatives will take up proposed legislation on Wednesday that would make tampering with the software that runs connected vehicles a crime punishable with a $100,000 fine.
Vigilante botnet highlights woeful state of embedded device security
A mysterious piece of software, dubbed Wifatch, has been infecting tens of thousands of Linux-based home routers and, according to experts at Symantec, attempts to secure them from attack. But Wifatch’s benevolent intentions shouldn’t obscure its malicious actions, or the security problems that it takes advantage of. The malicious software runs on vulnerable, Linux-based home routers. There, it removes other malware infections, disables vulnerable services like Telnet and even prompts users to update their administrator user name and password to prevent compromise, according to a post on Symantec’s blog. But the malware is still spreading between vulnerable systems without the owners consent and could easily be pressed into service distributing spam or malicious software, experts note. According to Symantec, Wifatch is likely spreading between infected devices by targeting exposed Telnet interfaces and using brute force password attacks to gain access to the devices. Tens of thousands of devices may have been infected […]
Pentagon looks to analog monitoring to secure IoT
In-brief: DARPA is directing $36m for the first stage of a program called LADS – Leveraging the Analog Domain for Security, which is looking into analog methods of cyber threat detection, including power consumption monitoring.