Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Russian Cyber Espionage Under The Microscope
Newest First  |  Oldest First  |  Threaded View
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
11/24/2014 | 4:02:58 PM
Re: They have capacity
So true, @ODA155. How could we forget The Russian Business Network? 
ODA155
50%
50%
ODA155,
User Rank: Ninja
11/24/2014 | 3:41:29 PM
Re: They have capacity
@Kelly Jackson Higgins,... I believe the Russians have always been better at Cyber-theft espionage than the Chinese, remember The Russian Business Network (or RBN) from the early-mid 2000's when people in Russia were learning all about capitalism and the "free market"? The Chinese on the other hand are relatively new to the game but because of their large HUMINT capabilities were able to catch up quite quickly. The Russians have only recently turned their skills into cyber-spying, which they probably have\had an edge there too. But I think as with most things Russian it's all about money and China it's about the state.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/21/2014 | 2:04:38 PM
Re: Coordination is clearly in the realm of the possible
Unless news organizations are wrong, most recent attacks have somehow related to the word "Russian", there will certainly be overlap on certain attacks.
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
11/21/2014 | 2:02:52 PM
Re: They have capacity
Security researchers are saying they see Russia as more sophisticated in its cyber espionage than China. It may not be as pervasive as China, but it's definitely active and more stealthy.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/21/2014 | 2:02:16 PM
Re: Coordination is clearly in the realm of the possible
It may even be that case that other nationalities helping the hackers in Russia. The recent security breach is around web cams, there is tons of work to be done to capture it and present it in a web site.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/21/2014 | 1:59:54 PM
They have capacity
 

The more the Russian government is isolated the more aggressive they would get. I am not suggesting that government is involved but followers would be my best guess. Russians have pioneered many technological advancement especially in the space industry, they for sure have capabilities to orchestrate an attack.
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
11/21/2014 | 1:30:40 PM
Re: Coordination is clearly in the realm of the possible
@Charlie, there has been a lot of speculation and some signs that there is overlap. Here's a recent example w/attacks on Ukranian targets: 

http://www.darkreading.com/russian-cyberspies-hit-ukrainian-us-targets-with-windows-zero-day-attack/d/d-id/1316592?

Greg Hoglund of Outlier Security told me he has seen multiple casees of overlap between the two worlds:

"I had one case two years ago where there was a Zeus bot infection, and they [the victim organization] dismissed it as common malware," Hoglund says. "We examined the bot, and it had XLS, DOC, and all types of extensions specially [built] in plugins to grab those intellectual property documents. It was stealing [their] IP."
Charlie Babcock
50%
50%
Charlie Babcock,
User Rank: Ninja
11/20/2014 | 9:12:18 PM
Coordination is clearly in the realm of the possible
I doubt if the skills of the underground in Russia have gone unnoticed by officials above ground. I suspect there are some very high paying jobs for the enterprising and skilled malware writers in the underground. Above ground, they stick to the KGB method of operations, inventive in its own way at least where the truth is concerned, but not keeping up the same way.


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/14/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-6287
PUBLISHED: 2020-07-14
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create a...
CVE-2020-6289
PUBLISHED: 2020-07-14
SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site.
CVE-2020-6290
PUBLISHED: 2020-07-14
SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.
CVE-2020-6291
PUBLISHED: 2020-07-14
SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration
CVE-2020-6292
PUBLISHED: 2020-07-14
Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.