Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Hackers Create Nuclear Bomb Scare

Realistic mushroom-cloud explosion causes stir in Czech Republic

On Sunday morning, viewers in the Czech Republic were enjoying "Panorama," a television show that features live views of ski resorts, mountains, and other scenery around the country. As they watched one view of the Bohemian mountains, a large mushroom cloud appeared -- the unmistakable signature of a nuclear explosion.

The scare shook many viewers, but the "live view" turned out to be a hoax. The Ztohoven "artistic group" had successfully broken into the Webcam used by Czech Television's CT2 channel and inserted a 30-second video showing a realistic-looking atomic explosion. The video even contains a link to the group's Web page.

Ztohoven subsequently released a statement in which they claim they are not terrorists or a political group -- they "just wanted to see what the reaction would be," according to one report.

Officials at CT2 didn't give details on how the group hacked the Webcam, which is operated by a contractor in the Krkonose Mountains. The perpetrators used "the Internet and other technologies," according to a spokesman, and law enforcement already has identified the Internet address that launched the hoax.

The television station already has filed a criminal complaint over the attack, charging the perpetrators with "damaging intellectual rights and scare mongering." If they are found, the attackers could face up to a year in jail.

Panorama, which is viewed mostly by skiers who want to check out the day's slopes, is watched by fewer than 50,000 people during the summer months, the spokesman said.

— Tim Wilson, Site Editor, Dark Reading

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11107
PUBLISHED: 2020-04-02
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
CVE-2020-11444
PUBLISHED: 2020-04-02
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
CVE-2020-7617
PUBLISHED: 2020-04-02
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
CVE-2020-8835
PUBLISHED: 2020-04-02
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the intr...
CVE-2020-8423
PUBLISHED: 2020-04-02
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.