Vulnerabilities / Threats

6/29/2017
06:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Kaspersky Lab Faces More U.S. Scrutiny Over Potential Russian Govt. Influence

Lawmaker proposes ban on DoD use of Moscow-based security vendor's products.

Moscow-based Kaspersky Lab this week found itself the subject of escalating concerns about the company's possible connections with the Russian government.

The immediate worries this time were prompted by news that FBI agents had questioned several of the security vendor's US-based employees at or near their residences Tuesday night.

The employees were apparently informed they were not the subjects of any formal criminal investigation and that they were being interviewed as part of an effort to get general information about the company's operations and communications with Moscow.

It is unclear at this time if the questioning had anything to do with Special Counsel Robert Mueller's broader investigation into potential Russian interference in the U.S. elections last year.

News of the FBI's apparent investigation of Kaspersky's activities prompted U.S. Senator Jeanne Shaheen [D-NH] to propose a total ban on the Pentagon's use of Kaspersky's products. In an amendment Wednesday to a Senate Armed Services Committee defense spending policy bill, Shaheen said the prohibition was required because of reports that Kaspersky Lab "might be vulnerable to Russian government interference."

A Kaspersky Lab spokeswoman said neither the company nor its founder and CEO Eugene Kaspersky had any ties to any government. "The company has never helped, nor will help, any government in the world with any cyber espionage efforts," the spokeswoman said in a statement to Dark Reading.

Kaspersky Lab has been an IT security vendor for 20 years and has adhered to ethical practices. "Kaspersky Lab believes it is completely unacceptable that the company is being unjustly accused without any hard evidence to back up these false allegations," the statement said.

John Pescatore, director of emerging security threats at the SANS Institute and a former NSA analyst says that so far at least there indeed doesn't appear to be any credible evidence that Kaspersky Lab's products have been compromised or contain hidden doors. "NSA and the UK GCHQ have had many years to look at Kaspersky’s products and I've seen no warnings before this," Pescatore says.

At the same time though, there's little doubt that Russian intelligence agencies are just as interested as the NSA in exploiting cyber techniques to infiltrate other countries.

"NSA knew of vulnerabilities in US security products and told no one. Russia may have known of similar vulnerabilities in Kaspersky's products and told no one," he says.

Just as the NSA might have influenced U.S. technology vendors to leave vulnerabilities in their products, the Russian government could have done the same with Kaspersky. "Russia went further, in economic espionage and trying to influence our presidential election, but there are many other similarities."

The takeaway for organizations is that all software needs to be checked for vulnerabilities and malicious capabilities, he said.

This week's developments add to the pressure that the $620 million Kaspersky Lab has been under in recent years about possible links with the Russian government and intelligence agencies. The company's products are relatively widely used in the US by consumers, commercial entities, and government organizations.

In May, U.S. intelligence officials said they were investigating the government's use of Kaspersky Lab products and whether those products could be used to attack American systems. At a U.S. Senate Select Committee on Intelligence hearing on Russian interference, the U.S. director of national intelligence and other intelligence officials unanimously expressed discomfort about US Kaspersky Lab products on their computers without explaining why. That time, as now, Kaspersky denied the company had any links with the Russian government and suggested it was being picked on for political reasons.

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Related content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-2668
PUBLISHED: 2018-06-22
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
CVE-2017-7466
PUBLISHED: 2018-06-22
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the An...
CVE-2018-12648
PUBLISHED: 2018-06-22
The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer dereference.
CVE-2018-12641
PUBLISHED: 2018-06-22
An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_arm_hp_template, demangle_class_name, demangle_fund_type, do_type, do_...
CVE-2018-12642
PUBLISHED: 2018-06-22
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.