IM
IronMonkey Threat Research
LIVE
|
Articles 28,671
|
CVEs 366,425
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,639 articles — Page 270 of 955
Kaspersky ICS CERT (English) ·

The Satori botnet has used embedded exploits to attack ports 37215 and 52869. After reaching the size of 280,000 active bots, the botnet has suddenly folded its operations.

Publications
Kaspersky ICS CERT (English) ·

Remote Code Execution in Moxa ThingsPro IIoT Gateway and Device Management Software.

Advisories
Kaspersky ICS CERT (English) ·

The TRITON attack demonstrates an important property of attacks on industrial enterprises: they may show no signs of malicious computer activity.

Publications
Kaspersky ICS CERT (English) ·

ENISA has released a new study: “Good Practices for Security of Internet of Things in the context of Smart Manufacturing. Kaspersky Lab ICS CERT experts contributed to the study.

Critical Manufacturing Publications
Kaspersky ICS CERT (English) ·

Attackers can take advantage of vulnerabilities in the PAN-OS management interface to execute arbitrary code with superuser privileges.

Publications
Kaspersky ICS CERT (English) ·

Vulnerabilities in Intel, ARM64 and AMD processors allow unauthorized access to virtual memory contents. Vulnerable devices include industrial equipment.

Publications
Kaspersky ICS CERT (English) ·

Exploitation of vulnerabilities in Siemens SINUMERIK controllers cold allow remote code execution, privilege escalation and device denial-of-service conditions

Publications
Kaspersky ICS CERT (English) ·

LibVNCServer before a 0.9.12 release contains a heap out-of-bound write vulnerability in the server code of the file transfer extension, which can result in remote code execution.

Advisories
Kaspersky ICS CERT (English) ·

An improper input validation vulnerability has been identified in the Nari PCS-9611 protection relay. Although an exploit for the vulnerability exists, the vendor has so far not commented on the problem.

Publications
Kaspersky ICS CERT (English) ·

A few months ago, while undertaking unrelated research into online connected devices, we uncovered something surprising and realized almost immediately that we could be looking at a critical...

Energy Publications
Kaspersky ICS CERT (English) ·

LibVNCServer before a 0.9.12 release contains multiple heap out-of-bound write vulnerabilities in VNC client code, which can result in remote code execution.

Advisories
Kaspersky ICS CERT (English) ·

Remote exploitation of discovered vulnerabilities lead to full compromise the system with Saperion webclient.

Critical Manufacturing Advisories
Kaspersky ICS CERT (English) ·

A new variant of the Mirai botnet can set up proxy servers on infected IoT devices

Publications
Kaspersky ICS CERT (English) ·

LibVNCServer before a 0.9.12 release contains a heap out-of-bound write vulnerability in a structure in VNC client code, which can result in remote code execution.

Advisories
Kaspersky ICS CERT (English) ·

28 industrial solutions by Siemens are affected by vulnerabilities in Intel ME, SPS and TXE technologies. The vendor has released patches for all of these products and made these patches available...

Publications
Kaspersky ICS CERT (English) ·

LibVNCServer before a 0.9.12 release contains a CWE-835: Infinite Loop vulnerability in VNC client code. The vulnerability could allow an attacker to consume an excessive amount of resources, such...

Advisories
Kaspersky ICS CERT (English) ·

The researchers at Kaspersky Lab ICS CERT decided to check the popular smart camera to see how well protected it is against cyber abuses.

Publications
Kaspersky ICS CERT (English) ·

In this report, Kaspersky Lab Industrial Control Systems Cyber Emergency Response Team (Kaspersky Lab ICS CERT) publishes the findings of its research on the threat landscape for industrial...

Critical Manufacturing Publications
Kaspersky ICS CERT (English) ·

LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple CWE-665: Improper Initialization weaknesses in VNC client code, which could allow an attacker to read stack memory and can...

Advisories
Kaspersky ICS CERT (English) ·

LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains a CWE-665: Improper Initialization vulnerability in VNC Repeater client code, which could allow an attacker to read stack memory and...

Advisories
Kaspersky ICS CERT (English) ·

A critical vulnerability in Moxa AWK-3131A industrial access point could allow an unauthorized attacker to execute arbitrary code by injecting system commands

Publications
Kaspersky ICS CERT (English) ·

LibVNCServer before a 0.9.12 release contains a null pointer dereference in VNC client code, which can result in denial-of-service condition.

Advisories
Kaspersky ICS CERT (English) ·

The Industrial Internet Consortium has announced the publication of an official Internet of Things Security Maturity Model description.

Publications
Kaspersky ICS CERT (English) ·

Kaspersky Lab today announced it is working with the Cybersecurity at MIT Sloan Consortium (CAMS) to host the “Cybersecurity Insight” seminar, offering participants an opportunity to learn about...

Critical Manufacturing Events
Kaspersky ICS CERT (English) ·

The security of products such as IIoT requires special attention. This time, the subject of our research was the ThingsPro Suite, an IIoT gateway and device manager from Moxa.

Transportation Systems Publications
Kaspersky ICS CERT (English) ·

Zebrocy is the name given to a subset of the Sofacy group (aka Fancy Bear, Sednit, APT28, Tsar Team, etc.). GreyEnergy and Zebrocy used the same servers at the same time and attacked the same organization.

Publications
Kaspersky ICS CERT (English) ·

Kaspersky Lab presented its latest findings on CoDeSys Runtime vulnerabilities at the S4x19 conference, in what was a successful debut among competing industrial cybersecurity vendors

Critical Manufacturing Events
Kaspersky ICS CERT (English) ·

An attacker with network access to the affected distributed control system (DCS) workstation can bypass the authentication of a maintenance port via brute-force, because number of login attempts...

Transportation Systems Advisories
Kaspersky ICS CERT (English) ·

AVEVA Wonderware System Platform vulnerability leading to Unauthorized Access to Credentials.

Advisories
Kaspersky ICS CERT (English) ·

UltraVNC Viewer before 1.2.2.4 has a buffer underflow vulnerability, which can potentially result in code execution.

Advisories