Hackers Have Infiltrated the US Power Grid's Control Networks (lasvegassun.com)
davidwr writes: A security researcher and the Associated Press are reporting that hackers have infiltrated many of the United States' power grid networks. "About a dozen times in the last decade, sophisticated foreign hackers have gained enough remote access to control the operations networks that keep the lights on, according to top experts who spoke only on condition of anonymity due to the sensitive nature of the subject matter." Exfiltrated data included engineering plans and other non-public information that could aid an attacker later, as well as account credentials. Multiple companies were affected, but one of the more notable ones was the energy provider Calpine. "Circumstantial evidence such as snippets of Persian comments in the code helped investigators conclude that Iran was the source of the attacks. Calpine didn't know its information had been compromised until it was informed by Cylance, Kerr said."
That's one of the reasons why I'm having trouble believing TFA. There isn't much skill needed to crack most organizations I've seen.
Anyway, from TFA:
1. Guy working on thing for A notices that A has been cracked. ok
2. Guy tracks crack back to open FTP servers. ok
3. Guy finds lots of other stuff on open FTP servers. ok
4. Guy does magic to find next time malware attacks someone. um, not ok
So Iranian "hackers" in Canada deploy malware via Tehran servers?
And unless he uploaded a hacked version of their malware to those cracked FTP servers ... how did he know?
Maybe he moved one of his cracked machines to a "honey-net"?
But then, why would any competent crackers deploy from servers in Iran? Particularly if they live in Canada and elsewhere?
This reads more like fear-mongering. IRAN IS ATTACKING US! BE AFRAID! EVIL IRANIANS! (and some canadians).