Urgent.News

What's breaking now, across thousands of outlets.

Tech

The CISA Alert: Security Beyond Solitary Confinement

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning about the dangers of having operational technology (OT) connected to the public Internet. They emphasize that immediate action is required to remove OT connections, change default passwords, restrict remote access, and enhance authentication and network protections. However, simply eliminating this connectivity may not always be feasible, and there are other, less resource-intensive methods to mitigate the threat.

Observing internet-exposed OT devices, CISA has found that they face relentless attacks, including port scans, connection probes, login attempts, and protocol fingerprinting. Most of these automated activities go unnoticed, but they can significantly impact the performance of OT controllers, especially when strong security measures are in place.

While strong login credentials are crucial, an attacker only needs to consume the controller's resources to create problems. Sustained password attacks can consume significant processor resources and contribute to a denial-of-service (DoS) situation. The attacker does not need to successfully log in; simply making the controller perform unnecessary tasks is part of the threat.

Distinguishing between targeted attacks, like the Stuxnet malware, and indiscriminate malicious activity, CISA highlights that most Internet traffic is low-level, automated scanning for vulnerabilities and weak credentials. These attacks impose costs on OT controllers, even if the attacker's intention is not to cause immediate harm. The challenge lies in defending against both determined adversaries and the constant background traffic on the Internet without overburdening the controllers' finite resources.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at jnior.com →

More in Tech

SSH Key Permissions: Fix “Too Open” Errors Without Guesswork

SSH refusing to use a private key with a “too open” warning is a security check, not a cosmetic complaint. If another local account can read your private key, it could use that key to authenticate to…

  • SSH key permission errors indicate too open warning
  • Fix by setting private key permissions to chmod 600
  • Adjust ownership if permissions don't resolve issue

More from Sunday 4 October →