cybersecurity

Rockwell Micrologix security vulnerability disclosed--Rockwell works to fix the issue


The following was posted, among other places, on the SCADASEC listserv. Eyal Udassin, a well-known and well respected security researcher with significant experience with control system functional security has discovered a vulnerability in some of Rockwell's products, and he and Rockwell have moved quickly to fix the vulnerability.

 

Here's the text of Udassin's report:

From 'Unfettered Blog'

RISI inaugural newsletter #Pauto #Pautoup


Can IT Security and plant level security ever work together? #PAuto #PAutoUP


Walt Boyes interviewed Bjorn Gudehus of Bell Canada, who is both a security analyst and an automation professional, and who has a distinctive voice and opinion on this important question.


From 'Unfettered Blog'

More from Safecomp


John Eidar Simensen of Institute for Energy Technology offered a methodology using Baysian Belief Networks for estimating the complexity of critical instrumentation and control systems. This is an ongoing project which may provide the first real metrics for complexity after years of trying.

From 'Sound Off! Editors' Blog'

Greg Garcia speaks out on functional security for control systems-- #PAuto


Here is the link to an interview Garcia did earlier this week:

http://www.eweek.com/c/a/Security/Energy-Sector-in-Danger-of-Cyberattack/

Very interesting interview. In my opinion, Garcia does not spread FUD.

From 'Unfettered Blog'

Joe Weiss provides testimony to Congressional Committee -- again


Our indefatigable blogger and functional security expert, Joe Weiss, was asked to provide written testimony for the record for the House Homeland Security Committee on Emerging Threats, Cybersecurity, Science and Technology hearings on the cyber security of the electric grid for today's hearing. We've posted his testimony in our white paper library, and will be publishing it as an article on ControlGlobal.com later today.

From 'Unfettered Blog'

Melissa Hathaway on cybersecurity


From the White House blog this morning:

From 'Unfettered Blog'

RSA-- Joe is not alone


Got Conficker? Department of Homeland Security has help...


Well, tomorrow is the big day. It is Zero Day for Conficker, also called Downadup, and we're all trying to guess what the impact of this widely spread trojan will be.

If you're like me, you have already proactively scoured your computers with virus scans and removal tools. And you've kept up to date with the MS patch that is supposed to protect against the trojan.

From 'Unfettered Blog'

Wurldtech and Shell announce global cooperation for increased infrastructure protection


Wurldtech and Shell have announced a global partnership to ensure cyber security for all of Shell's infrastructure around the world.

What does this mean?

From 'Unfettered Blog'