Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » New findings challenge attribution of cyberattack on Danish energy sector
    Cyber Security

    New findings challenge attribution of cyberattack on Danish energy sector

    techempireBy techempire3 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 14, 2024Editorial DepartmentCyber ​​attacks/vulnerabilities

    Danish energy sector cyber attack

    Latest findings from Forescout suggest that the Russian-linked Sandworm hacking group may not have been involved in last year’s cyberattack on Denmark’s energy sector.

    These intrusions targeted approximately 22 Danish energy organizations in May 2023 and occurred in two separate waves, one of which exploited a security vulnerability in the Zyxel firewall (CVE-2023-28771) and another subsequent wave. In the active cluster, the attacker deployed the Mirai botnet to carry out variants on infected hosts through unknown initial access vectors.

    Internet security

    The first wave occurred on May 11 and the second wave lasts from May 22 to 31, 2023. In one such attack detected on May 24, infected systems were observed communicating with the IP address (217.57.80[.]18 and 70.62.153[.]174) was previously used as command and control (C2) for the now-dismantled Cyclops Blink botnet.

    Danish energy sector cyber attack

    However, Forescout’s closer examination of the attack activity shows that not only are the two waves of attacks unrelated, but they are also unlikely to be the work of state-sponsored groups, as the second wave of attacks targeted unpatched Zyxel more broadly. part of a massive campaign of exploitation. Firewall. It is unclear who is behind both attacks.

    “The campaign has been described as a ‘second wave’ of attacks on Denmark, which started before and continued after [the 10-day time period]targeting firewalls indiscriminately in a very similar manner, except for periodically replacing temporary servers,” the company said in a report titled “Clearing the Fog of War.”

    Internet security

    There is evidence that attacks may have begun as early as February 16 using other known flaws in Zyxel devices (CVE-2020-9054 and CVE-2022-30525) as well as CVE-2023-28771 and continued into October 2023.The campaign selected various entities in Europe and the United States

    Forescout added: “This is further evidence that the exploitation of CVE-2023-27881 is not limited to Danish critical infrastructure, but persists and targets exposed devices, some of which happen to be Zyxel firewalls protecting critical infrastructure organizations.”

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Pokémon Trading Card Website Making 100k!

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    GTA 6 Release Date

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.