Back to news

September 14, 2018 | International, C4ISR

Really old computer viruses are still infecting new machines

By:

The biggest cyber threats governments and businesses face may not be the cutting edge hack from China, but a 10-year-old virus that infects a little-used computer.

Some of the most well-known viruses from the past decade are still infecting machines despite their well-documented nature, according to cyber research firms. Some viruses, such as WannaCry and Conficker, are still spreading, Sean Sullivan, a security adviser at F-Secure told Fifth Domain.

“It costs hackers nothing to keep using them,” Sullivan said.

These known vulnerabilities are still effective because older machines do not receive patches for updates, which can then infect an entire network. Hackers often bundle known hacks together because it increases their success rate with no downside, Sullivan said.

“Nothing is going to be 100 percent patched across organizations,” Sullivan, said. He described a network administrator's role as “triage.”

The 2017 WannaCry hack infected users in more than 150 countries and had an economic impact of anywhere from $4 billion to $8 billion. Although progress has been made to patch computers, WannaCry is still a top malware threat for customers, F-Stream said in a September report.

The Conficker hack targeted Windows systems and was first launched in 2008. It is reported to have cost as much as $9 billion in damage.

But much work remains. More than two-billion devices have not been patched to defend against BlueBorne, a Bluetooth vulnerability that allows an attacker to take over devices, according to the cyber protection company Armis. The devices are still vulnerable because they have not been updated or because an update does not exist, according to the company.

“Whether they're brought in by employees and contractors, or by guests using enterprise networks for temporary connectivity, these devices can expose enterprises to significant risks,” wrote Ben Seri, the vice president of research at Armis.

A previous version of this article said that two million devices have not been patched to defend against BlueBorne. It is two billion.

https://www.fifthdomain.com/industry/2018/09/13/really-old-computer-viruses-are-still-infecting-new-machines

On the same subject

  • Contract Awards by US Department of Defense - June 23, 2020

    June 25, 2020 | International, Aerospace, Naval, Land, C4ISR, Security

    Contract Awards by US Department of Defense - June 23, 2020

    DEFENSE LOGISTICS AGENCY Steris Corp., Mentor, Ohio, has been awarded a maximum $225,000,000 fixed-price with economic-price-adjustment, indefinite-delivery/indefinite-quantity contract for patient monitoring and capital equipment systems and accessories. This was a competitive acquisition with 41 offers received. This is a five-year base contract with one five-year option period. Location of performance is Ohio, with a June 22, 2025, ordering period end date. Using customers are Army, Navy, Air Force, Marine Corps and federal civilian agencies. Type of appropriation is fiscal 2020 through 2025 defense working capital funds. The contracting activity is the Defense Logistics Agency Troop Support, Philadelphia, Pennsylvania (SPE2D1-20-D-0008). Thales Defense & Security Inc., Clarksburg, Maryland, has been awarded a maximum $81,800,432 firm-fixed-price contract for Airborne Low Frequency Sonar spare parts. This was a sole-source acquisition using justification 10 U.S. Code 2304 (c)(1), as stated in Federal Acquisition Regulation 6.302-1. This is a five-year one-month contract with no option periods. Location of performance is Maryland, with a July 30, 2025, performance completion date. Using military service is Navy. Type of appropriation is fiscal 2020 through 2025 Navy working capital funds. The contracting activity is the Defense Logistics Agency Aviation, Philadelphia, Pennsylvania (SPRPA1-20-C-Y043). Simmonds Precision Sensors & Integrated Systems, Vergennes, Vermont, has been awarded a maximum $9,052,524 firm-fixed-price contract for vehicle flight system management spare parts. This was a sole-source acquisition using justification 10 U.S. Code 2304 (c)(1), as stated in Federal Acquisition Regulation 6.302-1. This is a two-year one-month contract with no option periods. Location of performance is Vermont, with a July 30, 2022, performance completion date. Using customers are Navy and Danish military forces. Type of appropriation is fiscal 2020 through 2022 Navy working capital funds and Foreign Military Sales. The contracting activity is the Defense Logistics Agency Aviation, Philadelphia, Pennsylvania (SPRPA1-20-E-F02). NAVY Jacobs/B&V JV (Federal Services), Honolulu, Hawaii, is awarded $85,000,000 for an indefinite-delivery/indefinite-quantity contract with a maximum amount of $85,000,000 for architect-engineer services for various projects primarily under the cognizance of Naval Facilities Engineering Command (NAVFAC), Hawaii. Work will be performed at various Navy, Marine Corp and other government facilities within the NAVFAC Hawaii area of responsibility, including Hawaii (95%); and other South Pacific Islands (5%). The work to be performed provides for architect-engineer services to include, but are not limited to, utility projects; the execution and delivery of military construction (MILCON) project documentation; functional analysis and concept development workshops, design charrettes; design-build request for proposal solicitation documents; design-bid-build design contract documents; cost estimates; technical surveys and reports including concept studies, site engineering investigations and surveys; collateral equipment buy packages; comprehensive interior design, to include structural interior design; furniture, fixtures and equipment packages; and post construction award services. Work is expected to be completed by June 2025, and the term of the contract is not to exceed 60 months. No task orders are being issued at this time. Fiscal 2020 operations and maintenance (Navy) contract funds for the minimum guarantee in the amount of $10,000 are obligated on this award and will expire at the end of the current fiscal year. Future task orders will be primarily funded by MILCON planning and design funds. This contract was competitively procured via the beta SAM website, and four proposals were received. The Naval Facilities Engineering Command, Joint Base Pearl Harbor-Hickam, Hawaii, is the contracting activity (N62478-20-D-5036). Lockheed Martin Corp., Liverpool, New York, is awarded a $22,433,508 modification (P00001) to firm-fixed-price order N00019-20-F-0535 against basic ordering agreement N00019-19-G-0029. This order exercises options to procure 12 retrofit advanced radar processor systems for the E-2D Advanced Hawkeye aircraft. Work will be performed in Liverpool, New York (54%); and Andover, Massachusetts (46%), and is expected to be completed by November 2023. Fiscal 2019 aircraft procurement (Navy) funds in the amount of $3,738,918; and fiscal 2020 aircraft procurement (Navy) funds in the amount of 18,694,590 will be obligated at time of award, none of which will expire at the end of the current fiscal year. The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. Mercury Defense Systems Inc., Cypress, California, is awarded an $11,734,623 firm-fixed-price order N68335-20-F-0243 against previously issued basic ordering agreement N683350-17-G-0017. This order provides for non-recurring engineering associated with the hardware and software design and development of the Type II Advanced Digital Radio Frequency Memories (DRFM) as well as the production and delivery of 22 DRFMs for the Navy and the Air Force under Small Business Innovation Research Topic N06-036 titled, “Advanced Techniques for Digital Radio Frequency Memories (DRFM).” Work will be performed in Cypress, California (73%); and West Caldwell, New Jersey (27%), and is expected to be completed by November 2021. Fiscal 2020 aircraft procurement (Air Force) funds in the amount of $4,800,528; fiscal 2020 research, development, test and evaluations (Navy) funds in the amount of $$4,267,136; and fiscal 2020 weapons procurement (Navy) funds in the amount of $2,666,960 will be obligated at time of award, none of which will expire at the end of the current fiscal year. The Naval Air Warfare Center Aircraft Division, Lakehurst, New Jersey, is the contracting activity. ARMY Hardwire LLC,* Pocomoke, Maryland (W91CRB-20-D-0026); Leading Technology Composites Inc.,* Wichita, Kansas (W91CRB-20-D-0027); and Point Blank Enterprises Inc., Pompano Beach, Florida (W91CRB-20-D-0028), will compete for each order of the $57,914,467 firm-fixed-price contract for the procurement of small arms protective inserts. Bids were solicited via the internet with four received. Work locations and funding will be determined with each order, with an estimated completion date of June 22, 2025. U.S. Army Contracting Command, Aberdeen Proving Ground, Maryland, is the contracting activity. Avon Protection Systems Inc., Cadillac, Michigan, was awarded a $49,621,502 firm-fixed-price contract for the purchase of the Joint Service General Purpose Mask systems and spare components. Bids were solicited via the internet with one received. Work locations and funding will be determined with each order, with an estimated completion date of June 22, 2025. U.S. Army Contracting Command, Detroit Arsenal, Michigan, is the contracting activity (W56HZV-20-D-0078). CORRECTION: The multiple award task order contract issued on April 22, 2020, listed eight contractors. In addition to them, CES-RESCON LLC,* Anchorage, Alaska (W911KB-20-D-0016), will compete for each order of the $140,000,000 firm-fixed-price contract. AIR FORCE Advanced Electronics Co. Ltd., Riyadh, Saudi Arabia, has been awarded a $12,374,760 firm-fixed-price and cost-reimbursable modification (P00030) to contract FA8730-16-C-0019 for the Royal Saudi Air Force (RSAF) F-15SA Cyber Protection System (CPS) and Related Facilities program. This modification provides for implementation and delivery of end-user training for the CPS for two years. The scope of this contract effort will include custom contractor-developed training and original equipment manufacturer training. This is a Foreign Military Sales (FMS) acquisition between the U.S. government and the Kingdom of Saudi Arabia. This FMS is for the total package of acquisition and fielding of 84 F-15A aircraft; the upgrade of 70 F-15SA aircraft to the F-154SA configuration; the procurement of associated equipment, weapons and spares; and the construction, refurbishment and infrastructure improvements of support facilities for the F-15SA in the Kingdom of Saudi Arabia. Work will be performed at RSAF facilities in the Kingdom of Saudi Arabia and is expected to be completed by June 1, 2022. This award is the result of a sole-source acquisition and FMS funds in the full amount will be obligated at the time of the award. Total cumulative face value of the contract is $165,863,230. The Air Force Life Cycle Management Center, Hanscom Air Force Base, Massachusetts, is the contracting activity. Compunetix Inc., Monroeville, Pennsylvania, has been awarded a $9,600,000 firm-fixed-price, indefinite-delivery/indefinite-quantity contract for equipment to upgrade mission control rooms (MCR) at the Ridley Mission Control Center, the Birk Flight Test Facility and MCRs at Eglin Air Force Base, Florida. Work will be performed at Edwards AFB, California; and Eglin AFB, and is expected to be completed June 30, 2025. This award is the result of a sole-source acquisition. Fiscal 2020 research, development, test and evaluation funds in the amount of $50,000 are being obligated at the time of award. Air Force Test Center, Edwards AFB, is the contracting activity (FA9302-20-D-0010). The Boeing Co., Oklahoma City, Oklahoma; San Antonio, Texas; and Hamamatsu, Japan, has been awarded an $8,471,689 firm-fixed-price, cost-plus-fixed-fee and cost-plus-incentive-fee modification (P00005) to contract FA8730-18-C-0001 for the Japan Airborne Warning and Control System (AWACS) mission computing upgrade (MCU) installation and checkout (I&CO) and Automatic Dependent Surveillance Broadcast Out (ADS-B Out). The contract modification is to upgrade its fleet of four aircraft with the ADS-B Out capability. ADS-B Out is a software and hardware update to the Raytheon APX-119 transponder that includes the addition of a Global Positioning System (GPS) card. Under the E-767 AWACS I&CO program, the GPS card is to be installed within the four aircraft and updating the three ground support facilities. Work will be performed in Oklahoma City, Oklahoma; San Antonio, Texas; and Hamamatsu, Japan, and is expected to be completed Dec. 23, 2023. This modification involves Foreign Military Sales (FMS) to the Japan Air Self-Defense Force. FMS funds in the full amount are being obligated at the time of award. Total cumulative face value of the contract is $227,688,995. Air Force Life Cycle Management Center, Hanscom Air Force Base, Massachusetts, is the contracting activity. CORRECTION: The following contract numbers were omitted from a June 19, 2020, announcement of a multiple-award contract to provide equipment, training and product support to approximately 3,500 Air Force Special Warfare operators, as well as authorized users in support of Special Warfare mission requirements: Federal Resources, Stevensville, Maryland (FA8629-20-D-5003); W.S. Darley & Co., Itasca, Illinois (FA8629-20-D-5052); US21 Inc., Fairfax, Virginia (FA8629-20-D-5053); Atlantic Diving Supply Inc., Virginia Beach, Virginia (FA8629-20-D-5054); and Tactical & Survival Specialties Inc., Harrisonburg, Virginia (FA8629-20-D-5055). *Small Business https://www.defense.gov/Newsroom/Contracts/Contract/Article/2229945/source/GovDelivery/

  • New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection

    October 23, 2024 | International, Land

    New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection

    New variants of Grandoreiro malware emerge, using advanced tactics to evade detection and targeting banks globally.

  • Romania to buy 54 howitzers from South Korea’s Hanwha Aerospace

    June 23, 2024 | International, Aerospace

    Romania to buy 54 howitzers from South Korea’s Hanwha Aerospace

    Other bidders reportedly included Germany’s Krauss-Maffei Wegmann with the Panzerhaubitze 2000 and Turkey's BMC with its T-155 Fırtına.

All news