Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

9/27/2010
04:10 PM
Connect Directly
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Iran Denies Stuxnet Worm Hurt Nuclear Plant

The malware appears to have been designed to target a specific facility or control process.

An Iranian official on Sunday acknowledged that the stuxnet worm had affected personal computers at the Bushehr nuclear plant but asserted that the malware had not caused major damage.

Stuxnet is believed to have been created last year and was first detected by a security firm in Belarus in June, according to ICSA Labs. Once introduced to a computer system via a USB drive, among other attack vectors, it is designed to exploit as many as four different vulnerabilities in various versions of Microsoft Windows and to infect Supervisory Control and Data Acquisition control systems (SCADA) made by Siemens. These systems control critical infrastructure at facilities like power plants.

To date, Microsoft has patched two vulnerabilities exploited by stuxnet.

The malware has been characterized as being exceptionally sophisticated, prompting speculation that it could only be the product of an organization backed by a nation-state, such as an intelligence agency.

No proof of such claims has yet been made public.

The targeted nature of the malware, in the opinion of Siemens, means that it was created to attack a specific facility or industrial process.

"Stuxnet is obviously targeting a specific process or a plant and not a particular brand or process technology and not the majority of industrial applications," the company said in updated information it posted last week.

Symantec, which plans to present a paper on stuxnet at the Virus Bulletin Conference on September 29th, said in June that the majority of stuxnet infections it could detect (59%) were in Iran.

Attacks on critical infrastructure like the Bushehr nuclear plant are just the sort of cyber warfare that U.S. officials have long feared could occur in the U.S. and have sought to prevent through funding and legislation.

The Pentagon has refused to comment on whether or not it launched the stuxnet attack.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-26030
PUBLISHED: 2021-04-14
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page
CVE-2021-26031
PUBLISHED: 2021-04-14
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI.
CVE-2021-27710
PUBLISHED: 2021-04-14
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system funct...
CVE-2021-28484
PUBLISHED: 2021-04-14
An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of the request, which can lead to a state where yubihsm-connector becomes stuck in a loop waiting for the YubiHSM to send i...
CVE-2021-29654
PUBLISHED: 2021-04-14
AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.