Cyber Vulnerability

Cyber Threat to Control Systems: Are Companies Expecting Too Much Info?


The industry uses the general term "threat information," but during more detailed discussions, it seems that the information companies seek is more like the traditional military concept of "tactical information."

Read this article and let us know if you agree.

From 'Sound Off! Editors' Blog'

And Another Link to Siemens WinCC/Simatic Virus Info


Here's a link to a page on the Siemens site containing information on the Trojan that has affected Siemens software. The good news is that so far, apparently only one site has actually been hit. We will provide more updates as they become available.

From 'Unfettered Blog'

We Knew It Was Only a Matter of Time


Coming to work on a Monday and finding an email outlining the report of a major cyber security breach affecting an important supplier and its customers is never a good way to start the week. But that's what happened this morning. Late last week and into the weekend, reports began trickling out about a piece of malware apparently targeted at Siemens systems.

From 'Sound Off! Editors' Blog'

Rockwell Micrologix security vulnerability disclosed--Rockwell works to fix the issue


The following was posted, among other places, on the SCADASEC listserv. Eyal Udassin, a well-known and well respected security researcher with significant experience with control system functional security has discovered a vulnerability in some of Rockwell's products, and he and Rockwell have moved quickly to fix the vulnerability.

 

Here's the text of Udassin's report:

From 'Unfettered Blog'