Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Report: In Huge Hack, Chinese Manufacturer Sneaks Backdoors Onto Motherboards

If true, the attack using Supermicro motherboards could be the most comprehensive cyber breach in history.



According to a new article in Bloomberg BusinessWeek, manufacturing plants in China implanted tiny network monitoring and control chips on motherboards made for U.S. manufacturer Supermicro. Supermicro motherboards are commonly used in white-box servers, including those purchased for data center use by companies like Amazon and Apple.

The article says that the chips were discovered during a due-diligence security survey conducted on computers manufactured by Elemental, a company making systems for high-speed data streaming. Worse yet, according to Bloomberg, "Elemental’s servers could be found in Department of Defense data centers, the CIA’s drone operations, and the onboard networks of Navy warships. And Elemental was just one of hundreds of Supermicro customers."

Security researchers quoted in the piece say that the purpose of the chips is to change the operating system core so that it will accept externally sourced changes, opening a backdoor into the system that can be used for a variety of purposes. Amazon, Apple, and Supermicro have all denied the details of the article, though Bloomberg is standing behind its reporting and says that critical details have been corroborated by current and former government employees.

In a statement to Dark Reading, Joseph Carson, chief security scientist at Thycotic, said: "We are one step away from a major cyber conflict or retaliation that could result in serious implications. However, what is clear is that it is a government behind this cyber espionage and I believe it is compromised employees with privileged access that are acting as malicious insiders selecting specific targets so the supply chain has been victim of being compromised. The motive will not be clear until exact details of the hardware chip is reversed to know what it is capable of and who are the victims since no one is owning up from any of the Supermicro’s customers."

Dark Reading will continue to follow this story as it develops.

For more, read here

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
10/5/2018 | 3:09:48 PM
Made in China - it's cheaper
For years, American manufacturing firms have let Chinese workers build a wide range of products, consumer and tech intensive and for those years we have freely given them our technology to replicate, study and use.  Every laptop that went to the old Olympic game came back with malware.  Every one.  Nobody talks of that nor the blatant opportunity to just COPY what we give them.  And for this we are now surprised!!!   They are NOT friendly to us - get that!!!   Neither Russia and host of other countries.  This tech achievement is impressive in scope but should have been expected all along.   We are blind on many things.  
Alexandre Cagnoni
50%
50%
Alexandre Cagnoni,
User Rank: Author
10/5/2018 | 5:29:08 PM
Economic effects as well
This could have major economic impacts beyond the obvious security ones. If true, it could change the way the world has to manufacture and buy computers if the country that is responsible for 90% of computer hardware is doing this. That's a major shift in manufacturing that we are not prepared for!
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: He still insists that security by obscurity is the way to go.
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-9681
PUBLISHED: 2019-09-17
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X...
CVE-2019-9009
PUBLISHED: 2019-09-17
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
CVE-2018-20336
PUBLISHED: 2019-09-17
An issue was discovered in Asuswrt-Merlin 384.6. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a long string over UDP, which may lead to an information leak.
CVE-2019-12755
PUBLISHED: 2019-09-17
Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.
CVE-2019-14826
PUBLISHED: 2019-09-17
A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.