Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

10/4/2018
03:30 PM
50%
50%

Report: In Huge Hack, Chinese Manufacturer Sneaks Backdoors Onto Motherboards

If true, the attack using Supermicro motherboards could be the most comprehensive cyber breach in history.

According to a new article in Bloomberg BusinessWeek, manufacturing plants in China implanted tiny network monitoring and control chips on motherboards made for U.S. manufacturer Supermicro. Supermicro motherboards are commonly used in white-box servers, including those purchased for data center use by companies like Amazon and Apple.

The article says that the chips were discovered during a due-diligence security survey conducted on computers manufactured by Elemental, a company making systems for high-speed data streaming. Worse yet, according to Bloomberg, "Elemental’s servers could be found in Department of Defense data centers, the CIA’s drone operations, and the onboard networks of Navy warships. And Elemental was just one of hundreds of Supermicro customers."

Security researchers quoted in the piece say that the purpose of the chips is to change the operating system core so that it will accept externally sourced changes, opening a backdoor into the system that can be used for a variety of purposes. Amazon, Apple, and Supermicro have all denied the details of the article, though Bloomberg is standing behind its reporting and says that critical details have been corroborated by current and former government employees.

In a statement to Dark Reading, Joseph Carson, chief security scientist at Thycotic, said: "We are one step away from a major cyber conflict or retaliation that could result in serious implications. However, what is clear is that it is a government behind this cyber espionage and I believe it is compromised employees with privileged access that are acting as malicious insiders selecting specific targets so the supply chain has been victim of being compromised. The motive will not be clear until exact details of the hardware chip is reversed to know what it is capable of and who are the victims since no one is owning up from any of the Supermicro’s customers."

Dark Reading will continue to follow this story as it develops.

For more, read here

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
10/5/2018 | 3:09:48 PM
Made in China - it's cheaper
For years, American manufacturing firms have let Chinese workers build a wide range of products, consumer and tech intensive and for those years we have freely given them our technology to replicate, study and use.  Every laptop that went to the old Olympic game came back with malware.  Every one.  Nobody talks of that nor the blatant opportunity to just COPY what we give them.  And for this we are now surprised!!!   They are NOT friendly to us - get that!!!   Neither Russia and host of other countries.  This tech achievement is impressive in scope but should have been expected all along.   We are blind on many things.  
Alexandre Cagnoni
50%
50%
Alexandre Cagnoni,
User Rank: Author
10/5/2018 | 5:29:08 PM
Economic effects as well
This could have major economic impacts beyond the obvious security ones. If true, it could change the way the world has to manufacture and buy computers if the country that is responsible for 90% of computer hardware is doing this. That's a major shift in manufacturing that we are not prepared for!
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25747
PUBLISHED: 2020-09-25
The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightn...
CVE-2020-25748
PUBLISHED: 2020-09-25
A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencrypted form. One can also modify responses from NTP and RTSP s...
CVE-2020-25749
PUBLISHED: 2020-09-25
The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet...
CVE-2020-24592
PUBLISHED: 2020-09-25
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.
CVE-2020-24593
PUBLISHED: 2020-09-25
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.