CYBER NEWS SPOTLIGHT INSIGHT on CYBERSECURITY NEWS & TRENDS for CRITICAL INFRASTRUCTURE Op April 2014
Total Page:16
File Type:pdf, Size:1020Kb
DHS Office of Cybersecurity & Communications CYBER NEWS SPOTLIGHT INSIGHT ON CYBERSECURITY NEWS & TRENDS FOR CRITICAL INFRASTRUCTURE Op April 2014 TABLE OF CONTENTS CHEMICAL ............................................................................................ 2 COMMERCIAL FACILITIES ................................................................... 2 COMMUNICATIONS .............................................................................. 3 CRITICAL MANUFACTURING ............................................................... 5 DAMS .................................................................................................... 6 DEFENSE INDUSTRIAL BASE .............................................................. 6 EMERGENCY SERVICES ...................................................................... 7 ENERGY ................................................................................................. 8 FINANCIAL SERVICES ........................................................................ 10 FOOD & AGRICULTURE ..................................................................... 11 GOVERNMENT FACILITIES ................................................................ 12 HEALTHCARE & PUBLIC HEALTH ..................................................... 13 INFORMATION TECHNOLOGY ............................................................ 14 NUCLEAR ............................................................................................ 15 TRANSPORTATION ............................................................................. 16 WATER ................................................................................................ 17 CROSS SECTOR .................................................................................. 18 Department of Homeland Security Disclaimer - The Office of Cybersecurity & Communications Industry Engagement and Resilience Branch’s Cyber News Spotlight is a non-commercial publication intended to educate and inform personnel engaged in cyber infrastructure protection. Further reproduction or redistribution is subject to original copyright restrictions. DHS provides no warranties with respect to this Cyber News Spotlight, including no warranty of ownership of any original copyrights, or of accuracy with respect to the original source material. DHS does not endorse any resources linked to or referenced in this Cyber News Spotlight or the contents of such resources. CHEMICAL April 25, Wisconsin – Mass casualty exercise to take place in Portage Saturday, Portage Daily Register: http://www.wiscnews.com/news/local/article_0605d68a-3d65- 54d7-b8ff-b21e262672ee.html Context: A city in Wisconsin will test its disaster response preparedness in an exercise involving the explosion of a facility containing hazardous chemicals. The exercise is intended to test communications and coordination in the event of a real disaster. The exercise also displays how testing alert and information-sharing systems across multiple entities can help ensure a timely and effective response among chemical industry owners and operators, government leaders, emergency responders, and healthcare providers. April 23, United States – Chemical Safety Board releases preliminary findings in West Fertilizer investigation, BLR: http://safety.blr.com/workplace-safety-news/hazardous- substances-and-materials/chemical-hazards/Chemical-Safety-Board-releases-preliminary- finding/ Context: Since the Texas chemical plant explosion in 2013, both chemical safety and incident response have gained renewed interest among government agencies and first responders. This article reveals some of the key preliminary findings of the investigation, including the need to develop better guidance regarding the storage and handling of ammonium nitrate, the main chemical involved in the explosion. The article highlights the importance of previous guidance that calls for automatic sprinkler and fire detection systems, which can help monitor, alert, and communicate hazardous conditions to plant operators and emergency responders. COMMERCIAL FACILITIES April 23, United States – Phishers divert home loan earnest money, Krebs on Security: http://krebsonsecurity.com/2014/04/phishers-divert-home-loan-earnest-money/ Context: According to the article, cyber criminals have begun intercepting emails associated with housing down payments in order to steal money. The article states that the criminals send prospective borrowers phishing emails that mimic legitimate emails sent by a title insurance company to facilitate wire transactions. However, the emails change the company’s bank account information so that the money is sent to the criminals instead. This article highlights how consumers can be vulnerable to spoofed emails during real estate transactions, especially involving online money transfers. April 21, United Kingdom – Web scam attacks target World Cup ticket buyers, Internet experts warn, Metro: http://metro.co.uk/2014/04/21/web-scam-attacks-target-world-cup- ticket-buyers-internet-experts-warn-4704809/ Context: Soccer fans looking for World Cup merchandise and tickets are encountering fraudulent websites that pose a cybersecurity threat. The article states that fraudulent websites and mobile applications claiming to be associated with the World Cup have appeared and could be used to distribute malware to steal personal information. The article demonstrates how major sporting events can be used by malicious actors to conduct cyber crime. PAGE 2 April 14, Massachusetts – U.S. retailers to share cyber threat data after Target attack, Chicago Tribune: http://www.chicagotribune.com/business/sns-rt-us-retail-cybersecurity- 20140414,0,6201954.story Context: The National Retail Federation plans to form an Information Sharing and Analysis Center (ISAC) focused on the retail industry that will be operational by June 2014. According to the article, retailers experienced problems obtaining information about cyber attacks after a major breach of a large retailer occurred in late 2013. This article highlights how retailers are collaborating to share information among themselves to identify threats faced by the entire industry. April 8, New Jersey – Judge rules FTC can sue Wyndham over cyber security lapses, Fox Business: http://www.foxbusiness.com/industries/2014/04/08/us-ftc-can-sue-hotel- group-over-poor-data-security-court-rules/ Context: A judge ruled that a U.S.-based hotel chain can be sued by the Federal Trade Commission (FTC) over cyber security lapses. According to the article, the FTC suit alleges that the hotel chain’s inadequate cybersecurity led directly to the theft of customer data. The article demonstrates that businesses could be subject to litigation in addition to the costs directly associated with the cyber incidents. Additional Reading: April 23, United States – Media and entertainment industry targeted in cyberattacks, CSO: http://www.csoonline.com/article/2146983/media-and-entertainment-industry-targeted-in-cyberattacks.html April 17, United States – 3 million customer credit, debit cards stolen in Michaels, Aaron Brothers breaches, Krebs on Security: http://krebsonsecurity.com/2014/04/3-million-customer-credit-debit-cards- stolen-in-michaels-aaron-brothers-breaches/ April 17, Washington, D.C. – Agency: Target hackers may take years to find, Associated Press: http://www.usatoday.com/story/money/business/2014/04/17/target-breach-investigation-secret- service/7830893/ April 7, United States – Neiman Marcus breach linked to Russians who eluded U.S., Bloomberg: http://www.bloomberg.com/news/2014-04-07/neiman-marcus-breach-linked-to-russians-who-eluded-u-s- .html April 2, United Kingdom – Manchester City become first Premier League club to offer free WIFI at their stadium, Express: http://www.express.co.uk/news/science-technology/468273/Manchester-City-become- first-Premier-League-club-to-offer-free-WIFI-at-their-stadium COMMUNICATIONS April 25, International – Mobile bots grow 1,000% in 2013, Infosecurity: http://www.infosecurity-magazine.com/view/38135/mobile-bots-grow-1000-in-2013/ Context: A report found an increase of 1,000 percent in mobile botnet traffic in 2013. According to the article, the improvement in LTE networks and the rise in smartphone usage have facilitated the growth in mobile botnets, which use increasing amounts of bandwidth. This finding reflects how the rising number of mobile botnets and the growing volume of traffic they generate will continue to be a problem of mobile network operators and their ability to provide reliable mobile services. PAGE 3 April 25, International – Vulnerability in Viber allows intercept of images, videos, Threatpost: http://threatpost.com/vulnerability-in-viber-allows-intercept-of-images- videos/105705 Context: Researchers discovered a vulnerability in a popular voice-over-IP application that would leave users’ video and picture messages open to interception. Although user text messages are encrypted, the article states that video and picture messages were unencrypted and did not need authentication to be accessed. This discovery highlights the role of encryption and authentication in protecting the privacy of users’ communications. April 17, International – Satellite communications wide open to hackers, Dark Reading: http://www.darkreading.com/vulnerabilities---threats/satellite-communications- wide-open-to-hackers/d/d-id/1204539 Context: A report found that some satellite terminals have vulnerabilities associated with encryption, passwords, and backdoors that could be