China-based Campaign Breached Satellite Operators, Defense Contractors and Telecommunications Companies in US: Symantec (reuters.com)
A sophisticated hacking campaign launched from computers in China burrowed deeply into satellite operators, defense contractors and telecommunications companies in the United States and southeast Asia, security researchers at Symantec Corp said on Tuesday. Reuters: Symantec said the effort appeared to be driven by national espionage goals, such as the interception of military and civilian communications. Such interception capabilities are rare but not unheard of, and the researchers could not say what communications, if any, were taken. More disturbingly in this case, the hackers infected computers that controlled the satellites, so that they could have changed the positions of the orbiting devices and disrupted data traffic, Symantec said. "Disruption to satellites could leave civilian as well as military installations subject to huge [real world] disruptions," said Vikram Thakur, technical director at Symantec. "We are extremely dependent on their functionality." Satellites are critical to phone and some internet links as well as mapping and positioning data. Symantec, based in Mountain View, California, described its findings to Reuters exclusively ahead of a planned public release. It said the hackers had been removed from infected systems.
What happens from this announcement, that Symantec cares about, is that their name is in the headlines. Free advertising.
Policy makers, the President and Congressional committees, already know from classified (an unclassified) intelligence that China is spying on the US all over the place. This latest marketing announcement by Symantec isn't going to make much difference to policy makers. Symantec doesn't care that much anyway - they don't have a major Chinese competitor they are trying to get rid of.
The free advertising is what Symantec cares about. If my company had uncovered this incident, we would absolutely put out a press release right away, in order to get our name in the press.
Heck, look at any of my CVEs, such as 2012-0206.
https://www.securityfocus.com/...
Do you think I thought about what the president was doing when I found and reported that? No, but I do very much like the first three words in the official description of the vulnerability.
Christ almighty pull the jack already. It makes no sense at all that this type of stuff is connected to the internet.