CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

Threats Targeting UPS Units | Avast

admin by admin
April 5, 2022
in Information Security
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


These threats demonstrate how attackers can take advantage of just about anything with an internet connection.

Security researchers have uncovered a new series of threats that are targeting uninterrupted power supply (UPS) units. These threats can result in malware attacking the computers connected to the same networks through a variety of clever mechanisms. The US Cybersecurity and Infrastructure Security Agency (CISA) has discovered that the attacks have already been reported to the US Department of Energy.

The modern UPS is more than just a big battery that switches on to power up computers in emergencies⁠ — on the contrary, it has sophisticated circuitry along with network connections and software that works in conjunction with cloud-based management tools to report on its status. These functionalities also make it possible for IT managers to observe the status of a UPS unit and control its operation. As a result, many modern UPS units have internet access, which makes them vulnerable to cyberattacks.

Researchers found a new series of attacks called TLStorm-WP, which is documented with vulnerabilities CVE-2022-22805, CVE-2022-0715 and CVE-2022-22806. The name references weaknesses in the TLS (Transport Layer Security) protocol used for the UPS units’ internet connection. The attacks affect most of the Smart-UPS devices with the SmartConnect feature sold by APC, a major UPS manufacturer.

Attackers can leverage UPS units’ internet connection and trick the UPS into updating its firmware with something that includes malware to allow untrusted remote code execution. This serves as the entry point to an enterprise’s network. Another potential threat is that a compromised UPS unit could deliver power that could destroy connected computers.

The following diagram shows how the three attacks are related:

TLStormBugsImage credit: Bleepstatic

These issues highlight the risks that come along with large-scale IoT devices and how attackers can take advantage of just about anything with an internet connection. As is stated in Bleeping Computer, “Considering that vulnerable APC UPS units are used in about eight out of 10 companies and the sensitive environments they serve, such as medical facilities and server rooms, the implications can have significant physical consequences.”

What should you do if your UPS unit has been affected?

CISA recommends the following actions if you own a compromised UPS unit:



Source link

Previous Post

Best practices: Securing your Amazon Location Service resources

Next Post

KFC: Remodeling the fast food experience for a pandemic-impacted world

Related Posts

Information Security

New Bluetooth Hack Could Let Attackers Remotely Unlock Smart Locks and Cars

by admin
May 19, 2022
Information Security

When Your Smart ID Card Reader Comes With Malware – Krebs on Security

by admin
May 19, 2022
Information Security

Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover

by admin
May 19, 2022
Information Security

Just because an iPhone is powered off doesn’t mean it’s safe

by admin
May 19, 2022
Information Security

Researchers Expose Inner Workings of Billion-Dollar Wizard Spider Cybercrime Gang

by admin
May 18, 2022
Next Post

KFC: Remodeling the fast food experience for a pandemic-impacted world

Leave Comment

Recommended

Microsoft drops emergency patch after Patch Tuesday screw up

May 20, 2022

Chinese cyber spooks exploit western sanctions on Russia

May 20, 2022

Former Welsh steelworks becomes ‘living’ cyber lab

May 20, 2022

Healthcare through the crisis: The accelerating pace of digital transformation at the NHS

May 20, 2022

New Bluetooth Hack Could Let Attackers Remotely Unlock Smart Locks and Cars

May 19, 2022

When Your Smart ID Card Reader Comes With Malware – Krebs on Security

May 19, 2022

© 2022 CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 JNews - Premium WordPress news & magazine theme by Jegtheme.