Showing posts with label cyberattack. Show all posts
Showing posts with label cyberattack. Show all posts

Thursday, June 24, 2021

U.S. National Guard Simulated A Cyberattack That Brought Down Utilities Nationwide

Marine Forces Reserve and Army National Guard personnel taking part in Cyber Yankee 2021. Marine Forces Reserve/LCpl Mitchell Collyer  

Warzone/The Drive: The National Guard Just Simulated A Cyberattack That Brought Down Utilities Nationwide 

This year's Cyber Yankee exercises simulated the increasingly likely scenario of cyberattacks crippling huge sections of the nation's infrastructure. 

National Guardsmen just completed a two-week training exercise which saw them respond to a simulated cyberattack that took out critical utilities across the United States. The exercises have become an annual event, but this year took on even more significance after coming on the heels of several major ransomware and cyber attacks that crippled large parts of American infrastructure in recent months. 

The exercises were part of the seventh Cyber Yankee, an training event that brings together guardsmen from throughout the New England region to test their responses against simulated cyberattacks. This year’s exercises simulated a cyber attack that targeted utilities on the West Coast before spreading east across the United States towards New England. In addition to offering hands-on training on how to respond to active cyberattacks, the exercise was also intended to build cyber defense collaboration between the National Guard and private sector partners, the FBI, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, the Federal Energy Regulatory Commission, and U.S. Cyber Command, among others.  

Read more ....  

WNU Editor: These exercises are far more useful than listening to the FBI Director begging companies to not pay ransoms .... FBI director Chris Wray urges companies stop paying ransoms to hackers (CNCBC/Reuters).

Thursday, May 13, 2021

Did China Launch A Successful Cyber-Attack Against Russia's Top Submarine Design Bureau?

A copy of the image into which the malware had been embedded, which was then sent to Rubin's Director-General Vilnit. The system shown is similar, if not identical to an unmanned underwater vehicle Rubin has been developing called Cephalopod. via Cybereason  

Warzone/The Drive: Top Russian Submarine Design Bureau Hit By Cyber Attack With Chinese Characteristics 

The Rubin Design Bureau has designed ballistic missile submarines, among other types, as well as advanced unmanned underwater vehicles. Russia's Rubin Design Bureau was the target of a cyber attack involving an image file with malicious software embedded inside it via a specific tool that has become a hallmark of multiple entities linked to the Chinese government. The file could have been used to create a backdoor into the networks at Rubin, a prolific designer of submarines and other underwater platforms. Its portfolio includes the ultra-quiet Borei class ballistic missile submarine, the unique Belgorod and Losharik special missions submarines, and the Poseidon nuclear-powered and nuclear-armed ultra-long-range 'doomsday' torpedo, among other work. 

Cybersecurity firm Cybereason first reported on the attack on April 30, 2021, but it's unclear when it was actually carried out. Metadata that the company provided along with its analysis says that the Rich Text Format (RTF) image in question was created in 2007, but the report says that this is almost certainly false and meant to help obfuscate its origins. Other portions of the metadata indicate that it was first accessed earlier in April, but that may just be when Cybereason first opened it up to assess it. It's also not clear if the attack was successful in any way.  

Read more ....  

WNU Editor: The Chinese are well known to conduct cyber operations against foreign governments and companies. Just because a company is Russian will not give it a pass.

Monday, May 10, 2021

President Biden Says Russia Bears ‘Some Responsibility’ For Colonial Pipeline Hack

 

 NBC: Biden says no evidence Russian government was involved in pipeline hack  

Biden said that Putin still bears "some responsibility" to respond since DarkSide, a cybercrime gang the FBI says is responsible for the attack on a U.S. gasoline line. 

WASHINGTON — President Joe Biden said Monday that there was no evidence that the Russian government was involved with the Colonial Pipeline ransomware attack that shut down a major United States fuel pipeline on Friday. 

"I'm going to have a conversation, I'm going to be meeting with President Putin," Biden said. "And, so far, there is no evidence based on, from our intelligence people, that Russia is involved, although there is evidence that the actor's ransomware is in Russia. They have some responsibility to deal with this."  

Read more ....  

Update #1: Biden: ‘No evidence’ Russia hacked Colonial Pipeline, but Putin needs to act (NYPost) Update #2: Biden to discuss Russian ransomware hackers with Putin and suggests Moscow bears ‘some responsibility’ (The Independent)  

WNU Editor: The FBI is saying a criminal gang is responsible for this Colonial Pipeline cyberattack .... Cyberattack on US pipeline carried out by criminal gang, says FBI (DW).

President Biden Declares State Of Emergency Over Fuel Cyber-Attack

 

Financial Times: US uses emergency powers to keep fuel flowing after cyber attack 

Fears of rising prices after ransomware strike shuts Colonial Pipeline system 

The US government enacted emergency powers on Sunday in a bid to keep fuel supply lines open as fears of shortages rose following the shutdown of an essential pipeline. 

The move lifted various limits on the transport of fuels by road to ease the fallout from the continuing closure of the Colonial pipeline, which carries almost half the fuel consumed on the US east coast, following a ransomware cyber attack on Friday. 

“This Declaration addresses the emergency conditions creating a need for immediate transportation of gasoline, diesel, jet fuel and other refined petroleum products and provides necessary relief,” the Department of Transportation said.  

Read more ....  

WNU Editor: This shutdown is going to last a few days .... Hacked Pipeline May Stay Shut for Days, Raising Concerns About Fuel Supply (New York Times). 

More News On President Biden Declaring A State Of Emergency Over Fuel Cyber-Attack  

Federal agency issues emergency declaration over fuel pipeline cyberattack -- Axios  

US passes emergency waiver over fuel pipeline cyber-attack -- BBC  

Regional emergency declaration issued over pipeline shut down after cyberattack -- The Hill  

US government declared a state of emergency over fuel pipeline cyber-attack -- Forex Live

Saturday, May 8, 2021

Cyberattack Forces Shutdown Of The Largest Gasoline Pipeline In The U.S.

 

CNBC: Ransomware attack forces shutdown of largest fuel pipeline in the U.S. 

* Colonial Pipeline fell victim to a cybersecurity attack on Friday that involved ransomware, forcing it to temporarily shut down all pipeline operations. 

* Colonial transports nearly half of the East Coast’s fuel supply through a system that spans over 5,500 miles between Texas and New Jersey. 

* The pipeline transports gasoline, diesel, home heating oil and jet fuel. It also supplies the military. 

* Colonial said it has contacted law enforcement and other federal agencies and is working to restore service. 

* President Joe Biden was briefed on the incident Saturday morning, according to the White House. 

The operator of the country’s largest fuel pipeline, Colonial Pipeline, fell victim to a cybersecurity attack on Friday that involved ransomware, forcing it to temporarily shut down all pipeline operations, the company said in a statement on Saturday. 

The firm has hired a third-party cybersecurity firm to launch a probe into the incident and has contacted law enforcement and other federal agencies. 

The cyberattack has affected some of its IT systems too. Colonial Pipeline, which transports nearly half of the East Coast’s fuel supply, said it is “taking steps to understand and resolve this issue.”  

Read more ....  

WNU Editor: No mention on how much this ransomware group wants, but what a wake-up call for Colonial Pipeline and their inadequate network security. 

 More News On A Cyberattack Forcing The Shutdown Of The Largest Gasoline Pipeline In The U.S.  

Major US pipeline halts operations after ransomware attack -- AP  

Cyber attack shuts down top U.S. fuel pipeline network -- Reuters  

Major US pipeline shut by ransomware attack -- AFP 

2-Cyber attack shuts down U.S. fuel pipeline 'jugular,' Biden briefed -- Reuters  

Ransomware attack leads to shutdown of key pipeline that transports 100 million of gallons of fuel a day through a 5,500-mile pipeline between Texas and New Jersey -- AP  

Cyberattack forces major US fuel pipeline to shut down -- CNN  

Major US pipeline shuts fuel lines after cyberattack -- DW  

Cyberattack Forces Shutdown Of Largest Gasoline Pipeline In United States -- Zero Hedge  

U.S. says monitoring fuel supplies after big pipeline shut by cyber attack -- Reuters

History of shutdowns on top U.S. fuel pipeline -- Reuters  

Largest US pipeline halts all operations after cyber-attack -- RT