Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
6 Things To Know About the Ransomware That Hit Norsk Hydro
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
michaelmaloney
50%
50%
michaelmaloney,
User Rank: Apprentice
4/9/2019 | 3:13:41 AM
Different scales
It is essential to know that attacks do not often target finances alone. Sometimes their intention is just to destroy or at least slow down operations. This is basically the reason why we need to stop any potential attacks regardless of their individual scale before they can even hit.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
4/1/2019 | 3:43:26 PM
Re: Pending Review
Testing a plan has a real purpose beyond finding out what works and does not work.  These are critical of course but i will guarantee you that making such discoveries at 2:30 AM when nobody is thinking is FAR harder than finding out in the afternoon under a planned environment.  I'm not awake at that hour.  Nobody is.  And when you have real work to do make sure it is a known variable.  Because if it is not tested, then mistakes will happen and a recovery plan can destroy even more material than intended.   Or make it impossible even to recover.  At 2:30 am I am on a serious coffee burn!!!!
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 2:29:42 PM
Re: Pending Review
restore NAS's Kill the power to the building to insure that the on-site generator kicks in and the auto cut-over operates nominally. Yes. Testing the plan is important. Things do not go the way planned.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 2:28:08 PM
Re: More Definitive Security Required
fileless attack protection and a full-scale memory defense. It sounds like fileless attacks are becoming common. Good point.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 2:27:07 PM
Re: Pending Review
I have said this a thousand times here. HAVE A PLAN, TEST AND UPDATE. That makes sense. Another important is to keep it updated.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 2:25:11 PM
Re: Pending Review
TEST the plan ensures that staff knows what they ARE doing This is a good advice. If it does not work when you need it it is too late.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 2:24:10 PM
Re: Pending Review
Disaster Recovery plan. Business continuity. Your six points do not address this one. BC should play role in all incidents, most organizations do not have one unfortunately.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 2:22:45 PM
AD
An example is where an attacker might have access to the Active Directory infrastructure Once you ave AD access you can even deploy ransomware to other part of the network.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 2:20:25 PM
Copy files
"indicates the actors simply manually copy files from computer to computer," They would need network interface for that to work.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 2:18:16 PM
re-imaging
The goal is "to further isolate the affected computer and to complicate recovery, necessitating direct local intervention." This beings up image to my mind. Less about recovery more about re-imaging.
Page 1 / 2   >   >>


Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
State of SMB Insecurity by the Numbers
Ericka Chickowski, Contributing Writer,  10/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11674
PUBLISHED: 2019-10-22
Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.
CVE-2019-12967
PUBLISHED: 2019-10-22
Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.
CVE-2019-17189
PUBLISHED: 2019-10-22
totemodata 3.0.0_b936 has XSS via a folder name.
CVE-2019-4523
PUBLISHED: 2019-10-22
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 165481.
CVE-2019-17424
PUBLISHED: 2019-10-22
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.