Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Black Hat USA
August 1-6, 2020
Las Vegas, NV, USA
Black Hat Asia
September 29 - October 2, 2020
Singapore
Black Hat Europe
November 9-12, 2020
London UK
8/2/2019
09:00 AM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Learn to Safeguard Critical Industrial Targets at Black Hat USA

Cybersecurity experts will share their latest insights and strategies for protecting industrial sites and equipment, from electric motors to satellites.

Some of the most grievous cybersecurity breaches happen at industrial facilities responsible for providing critical services like power, so it pays to stay on top of what’s happening in the field of industrial security. Black Hat USA offers an entire track of Smart Grid and Industrial Security Briefings that will help you do just that. As you prepare to attend the event next week in Las Vegas be sure not to overlook some of the most promising industrial cybersecurity Briefings.

Sensor and Process Fingerprinting in Industrial Control Systems will equip you with a full understanding of the most common cyber and cyber-physical attack vectors to critical infrastructure. You’ll learn practical detection and defense strategies for both cyber and physical attacks on industrial targets and enjoy full video walkthroughs of attacks and defenses in a state-of-the-art water treatment testbed.

Attacking Electric Motors for Fun and Profit is another great Briefing to check out because it promises a useful breakdown of electric motor vulnerabilities and defense strategies, based on a wide analysis of electric motors used in everything from cars to industrial robots to phones. It’s rare to see this level of cybersecurity analysis for electric motors, so expect to walk away with a better understanding of how to compromise motors using techniques like pin-control attacks disrupting PWM, DOS or injection network attacks, sensor attacks, and exploiting the lack of security controls of software libraries on electric motor controllers.

For a broader perspective on industrial system cybersecurity make time for Cybersecurity Risk Assessment for Safety-Critical Systems, a Briefing from Honeywell on the vulnerabilities of truly critical infrastructure. Much of this Briefing is focused on space, so you can expect to learn all about the weak points in the satellite systems and networks that support agriculture, transportation, and the military. Plus, you’ll learn about a new technique for assessing security risks for safety-critical systems like space systems and enjoy a discussion on what the next steps should be in advancing cybersecurity for space systems.

Black Hat USA returns to the Mandalay Bay in Las Vegas August 3-8, 2019. For more information on what’s happening at the event and how to register, check out the Black Hat website.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/28/2020
Stay-at-Home Orders Coincide With Massive DNS Surge
Robert Lemos, Contributing Writer,  5/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11844
PUBLISHED: 2020-05-29
There is an Incorrect Authorization vulnerability in Micro Focus Service Management Automation (SMA) product affecting version 2018.05 to 2020.02. The vulnerability could be exploited to provide unauthorized access to the Container Deployment Foundation.
CVE-2020-6937
PUBLISHED: 2020-05-29
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
CVE-2020-7648
PUBLISHED: 2020-05-29
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. `#package.json`
CVE-2020-7650
PUBLISHED: 2020-05-29
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
CVE-2020-7654
PUBLISHED: 2020-05-29
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.