Critical Infrastructure

Spear phishing campaign targeted energy sector

By

The unsuccessful attacks were the result of email addresses being publicly posted on an electric company's website.

Experiment shows how often hackers want to attack critical infrastructure

Experiment shows how often hackers want to attack critical infrastructure By

Honeypots installed by researchers at security firm Trend Micro provided bait for 39 attacks on simulated ICS environments over the course of a month.

Waking the sleeping giant: Critical infrastructure

Waking the sleeping giant: Critical infrastructure By

For the last several years, security experts have been stressing the vulnerability of industrial control systems. Now, with attacks like Stuxnet proof of the risk, the big question is: How will industry respond?

Natural gas giant RasGas targeted in cyber attack

By

A virus has reportedly shut down the energy company's website and email servers, giving rise to questions of whether the Shamoon virus is to blame.

Saudi oil company back online after cyber sabotage attempt

By

Oil company Saudi Aramco has yet to confirm whether a virus, which struck 30,000 of its workstations, is Shamoon -- malware said to be targeting the Middle East energy sector.

Data-wiping Shamoon targeting Middle East energy sector

By

Shamoon, malware that overwrites files to the point of making computers unusable, has been described as a targeted, yet damaging threat.

First: Define critical infrastructure

First: Define critical infrastructure

Consensus needs to be developed around how critical infrastructure is defined, says Mark Clancy, managing director and CISO for The Depository Trust & Clearing Corp.

New partnerships required

New partnerships required

Only through collaboration can government and the private sector thwart cyber attacks, says Raymond Choo.

Data sharing, standards pose challenges to power grid

By

Better coordination, actionable information, and risk awareness are needed to protect the country's critical infrastructure, especially the power grid, according a congressional watchdog report.

Natural gas pipeline companies under siege, DHS arm warns

By

A sustained attack against the nation's natural gas pipelines, apparently orchestrated by the same malicious party, is proving difficult to quell.

Anonymous says power grid concerns are U.S. gov't spin

By

The head of the National Security Agency is warning that Anonymous may be developing capabilities to target the U.S. power grid, but members of the hacktivist collective called such claims nothing more than fear mongering.

New cyber security bill is bipartisan, but has its critics

By

A new version of a federal law designed to protect the nation's critical assets is toned-down from previous cyber security proposals, but business and privacy leaders have concerns.

Some 2M possibly affected by NYSEG, RG&E data compromise

By

Unauthorized individuals gained access to the personal data belonging to customers of New York State Electric & Gas (NYSEG) and Rochester Gas & Electric (RG&E), which are owned by Iberdrola USA.

APTs in critical infrastructure organizations

APTs in critical infrastructure organizations

Many managers of utilities companies don't understand or appreciate the value of IT security...at their, the facilities' and the community's peril.

Energy Department to analyze power grid cyber threats

By

The proposal is helpful, but still doesn't answer the question: who to call when an attack happens.

MIT researchers suggest power grid security oversight

By

While a number of entities have a stake in maintaining the cyber security of the U.S. electric grid, no single organization is currently responsible for overseeing protection across all aspects of grid operations.

Illinois water pump failure not a cyberattack

By

An Illinois water utility pump failure may have been an accident caused by an employee -- not the work of foreign hackers.

Water utilities in Illinois, Houston reportedly hacked

By

Hackers reportedly breached the systems of a company that makes supervisory control and data acquisition (SCADA) systems, used to manage operations at critical infrastructure facilitates, and stole customer usernames and passwords.

U.S. and EU partner for security response exercise

U.S. and EU partner for security response exercise By

"Cyber Atlantic 2011" aimed to clarify how the two nations can best communicate about cyber incidents that occur on government systems or critical infrastructure.

Microsoft issues workaround for Duqu malware

By

Microsoft issued a temporary fix for a vulnerability in the Windows kernel used to spread Duqu, the so-called "son of Stuxnet" trojan.

"Nitro" attacks target 29 firms in chemical sector

By

Hackers over the summer targeted at least 29 companies in the chemical sector during an attack campaign aimed at stealing intellectual property.

Duqu underscores trouble AV industry has in stopping threats

By

The slowness by which an offspring of Stuxnet was discovered may be further proof that attackers have a significant leg up on the security community.

The government has it wrong on Anonymous and critical infrastructure

By

When it comes to stopping individuals who want to compromise industrial control systems, the Anonymous group is certainly not Enemy No. 1.

Sponsored video: Pan Kamal of AlertEnterprise on SCADA

By

Fresh off the Stuxnet attack, critical infrastructure environments must evolve to meet the growing threat, Pan Kamal, VP of marketing at AlertEnterprise, tells SC Magazine Executive Editor Dan Kaplan.

Researcher again discloses multiple SCADA flaws

By

An Italian analyst said he spent little time finding a new batch of vulnerabilities impacting industrial control systems.

White House proposals include breach notification law

By

The White House on Thursday unveiled sweeping cybersecurity legislative recommendations to Congress.

Industrial control systems at risk, ICS-CERT warns

By

Software products used to manage critical infrastructure facilities contain a vulnerability that could allow an attacker to take control of affected systems, the ICS-CERT warned.

Despite threats, security not enough of priority at utilities

By

Critical infrastructure providers have been slow to respond to an increasing number of threats targeting industries such as power, oil, gas and water, according to a new report.

Exxon, Shell, BP targeted in operation "Night Dragon"

By

Exxon Mobil, Royal Dutch Shell and BP were among the oil companies targeted by hackers believed to be from China to steal proprietary information about oil and gas field bids and operations, according to Bloomberg News. McAfee earlier this month disclosed details about the intrusions, dubbed "Night Dragon." The security firm, however, did not list any of the victim companies. According to Bloomberg, citing unnamed individuals familiar with the investigations, the list of targeted companies also includes Marathon Oil, ConocoPhillips and Baker Hughes. — AM

Has cyberwar happened? Interview with Mikko Hypponen, chief research officer of F-Secure

By

Mikko Hypponen, chief research officer of F-Secure, distinguishes among cyberwar and everything else, explains why the anti-virus industry failed when it came to detecting and preventing Stuxnet, discusses why critical infrastructure is at major risk to attack and reveals how he tracked down the authors of the first PC virus, which turns 25 years old this year. SC Magazine Executive Editor Dan Kaplan spoke with Hypponen following a media luncheon at the RSA Conference in San Francisco.

Sign up for our newsletters

POLL