Attackers Deploy 'Triton' Malware Against Industrial Safety Equipment (securityweek.com)
wiredmikey writes: A new piece of malware designed to target industrial control systems (ICS) has been used in an attack aimed at a critical infrastructure organization, FireEye said on Thursday. The malware, which has been dubbed "Triton," is designed to target Schneider Electric's Triconex Safety Instrumented System (SIS) controllers, which are used to monitor the state of a process and restore it to a safe state or safely shut it down if parameters indicate a potentially hazardous situation. The investigation found that the attackers shut down operations after causing the SIS controllers to initiate a safe shutdown, but they may have done it inadvertently while trying to determine how they could cause physical damage.
Why the hell do people have their critical infrastructure on networks which aren't isolated and locked down?
If you're vulnerable to this kind of attack without, maybe you're too damned stupid to run critical infrastructure?
Why not employ a PROM (programmable read only memory as much as you can. These guys ignore other instructions and follow the routine that was put into them.
kids eat all the candy left in front of them...
moral... don't be an idiot
Being such an authority on security, I would have expected more from Bruce Schneider
this is what they did to Iran when they sabotaged their nuclear power plants, and generally the kind of sabotage they focus on - shutting down power plants and other critical infrastructure remotely.
I hope Germany doesn't throw their own Schneider under the bus here, but do everything they can to stop America from doing this, diplomatic efforts included.
If this hacker ever gets caught, they need the death penalty, to highlight the seriousness of their actions!
The US government did the same type of thing with STUXNET so obviously it’s totally ok.
It seems like everyone just trusts each other at that level. Also, does it matter? Everything should be encrypted anyway, redirecting traffic should be expected if not by States, somewhere else on the line.
Custom electronics and digital signage for your business: www.evcircuits.com
Just fuck Islam already. Haven't they caused enough harm? Isn't it time to eradicate these vermin?