4 avril 2024 | International, Terrestre

New Phishing Campaign Targets Oil & Gas with Evolved Data-Stealing Malware

Oil & gas companies beware! Hackers are using the updated Rhadamanthys info-stealer in phishing attacks.

https://thehackernews.com/2024/04/new-phishing-campaign-targets-oil-gas.html

Sur le même sujet

  • EU’s top diplomat warns against defense cuts

    13 mai 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    EU’s top diplomat warns against defense cuts

    BRUSSELS — The European Union's top diplomat is warning member countries not to slash defense spending as their economies buckle under pressure from the coronavirus, as the disease could spark security challenges. After chairing a video conference of defense ministers on Tuesday, EU foreign policy chief Josep Borrell said it was clear the pandemic is very likely to deteriorate the security environment in the years ahead. Borrell said as the crisis also hits the economy, it's important to secure the necessary funding for security and defense. Talks between the 27 EU member countries over their next long-term budget have been blocked for more than a year, well before the coronavirus hit Europe. Cuts to defense funds in that spending package were already under consideration. Given the impact of the disease, that seems even more likely now. https://www.defensenews.com/global/europe/2020/05/12/eus-top-diplomat-warns-against-defense-cuts/

  • The Pentagon just got one step closer to awarding its $10 billion cloud contract

    27 juillet 2018 | International, C4ISR

    The Pentagon just got one step closer to awarding its $10 billion cloud contract

    Amanda Macias The Pentagon released its final request for proposal for the Joint Enterprise Defense Infrastructure, or JEDI, contract. The lucrative winner-take-all deal may be valued at as much as $10 billion. Amazon is considered the front-runner for the contract since the tech giant already services the cloud system used by U.S. intelligence agencies. The Defense Department took a large step forward Thursday in its march toward procuring a secure cloud software, an acquisition potentially worth up to $10 billion. After a nearly two-month delay, the Pentagon released its final request for proposal for the Joint Enterprise Defense Infrastructure, or JEDI, contract. The long-awaited final request for proposal simply outlines what companies will have to deliver in order to get the lucrative deal. The Pentagon's cloud project will transition massive amounts of data to a commercially operated secure cloud system. The deal is a "single-source" award, meaning that only one company will win the entirety of the contract. Amazon is considered the front-runner for the contract since the tech giant already services the cloud system used by U.S. intelligence agencies. Amazon's cloud boasts the highest possible security level, while many of its competitors' clouds do not. However, other cloud providers — such as IBM, Microsoft and Oracle — have worked with government agencies for many decades. That could help their chances of winning the decade-long JEDI contract. The DoD "has an incredibly unique and complex technology estate and finite set of talent and resources," Pentagon Chief Information Officer Dana Deasy said in a statement. "We need help learning how to put in place an enterprise cloud and the JEDI Cloud is a pathfinder effort that will help Department of Defense do that." Experts think the deal could be a seismic development in the defense-tech world. "This award could be market-shaping," Andrew Hunter, director of the Defense-Industrial Initiatives Group at the Center for Strategic and International Studies, said in an interview. "I think industry's concern is that this will be the premier cloud contract, the flagship one, and that other parts of DoD will gravitate to it," he added. "So, I think whoever wins the contract is likely to have a real advantage in the marketplace going forward but not necessarily a decisive one." The desire to award a multibillion-dollar, two-year cloud contract was largely set into motion after Secretary of Defense James Mattis visited Silicon Valley last year. Federal defense agencies widely use Microsoft's server software, which integrates easily with the company's Azure public cloud, and among employees, Windows is the most popular operating system, Leigh Madden, Microsoft's general manager of defense, told CNBC in a prior interview. "I think it certainly should make a difference," he said. Similarly, IBM has worked alongside the military for decades. "We look forward to submitting a thoughtful, comprehensive proposal for a JEDI cloud that will serve the long-term needs of America's men and women in uniform," Sam Gordy, IBM's Federal general manager, said in a statement. In the midst of all this, President Donald Trump has attacked Amazon on Twitter, particularly as he rails against The Washington Post, which is owned by Amazon CEO Jeff Bezos, for the newspaper's coverage of his administration. A Vanity Fair report said the Trump administration might try to "cancel Amazon's pending contract" with the Pentagon, but the department maintains that there has been no political pressure from the White House on who should win the multibillion-dollar deal. U.S. Navy Commander Patrick Evans, a Department of Defense spokesperson, reiterated that the Pentagon's process is "transparent" and will remain "a full and open competition." "No companies were pre-selected. We have no favorites, and we want the best solution for the department," Evans said. Similarly, chief Pentagon spokesperson Dana White also addressed speculation Thursday that Amazon was in the lead to take the lucrative defense contract. "The secretary has been very clear that we need to be good stewards of the American people's money," White said. "So, nothing is taken for granted and nothing is presumed. We will get a full, open and transparent competition, and this is the first of many competitions with respect to the cloud." The Pentagon is scheduled to award the contract in September. — CNBC's Jordan Novet contributed to this report. https://www.cnbc.com/2018/07/26/pentagon-takes-step-closer-to-awarding-10-billion-cloud-contract.html

  • DARPA Explores New Computing Architectures to Deliver Verifiable Data Assurances

    17 janvier 2019 | International, C4ISR, Sécurité

    DARPA Explores New Computing Architectures to Deliver Verifiable Data Assurances

    Program seeks to create new software and hardware architectures that provide physically provable assurances around data security and privacy Whether a piece of information is private, proprietary, or sensitive to national security, systems owners and users have little guarantees about where their information resides or of its movements between systems. When a user enters information on a phone, for example, it is difficult to provably track that the data remains on the phone or whether it is uploaded to a server beyond the device. The national defense and security communities are similarly left with few options when it comes to ensuring that sensitive information is appropriately isolated, particularly when it's loaded to an internet-connected system. “As cloud systems proliferate, most people still have some information that they want to physically track – not just entrust to the ether,” said Walter Weiss, DARPA program manager. “Users should be able to trust their devices to keep their information private and isolated.” Keeping a system completely disconnected from all means of information transfer is an unrealistic security tactic. Modern computing systems must be able to communicate with other systems, including those with different security requirements. Today, commercial and defense organizations often leverage a series of air-gaps, or breaks between systems, to keep the most sensitive computing devices and information secure. However, interfaces to such air-gapped systems are typically added in after the fact and are exceedingly complex, placing undue burden on systems operators as they implement or manage them. To create scalable solutions that provide safe, verifiable methods of tracking information and communications between systems, DARPA launched the Guaranteed Architecture for Physical Security (GAPS) program. The goal of GAPS is to develop hardware and software architectures that can provide physically provable guarantees around high-risk transactions, or where data moves between systems of different security levels. DARPA wants to ensure that these transactions are isolated and that the systems they move across are enabled with the necessary data security assertions. The intended outputs of this program are hardware and software co-design tools that allow data separation requirements to be defined during design, and protections that can be physically enforced at system runtime. GAPS is divided into three research areas that will address: 1) the creation of hardware components and interfaces; 2) the development of software co-design tools; and, 3) the integration of these components and tools, as well as their validation against exemplar Department of Defense (DoD) systems. The new hardware components and interfaces are designed to provide system designers with a library of hardware tools to securely isolate data during transactions. The software co-design tools could someday allow developers to easily employ GAPS hardware components without requiring changes to their existing development processes and frameworks. Finally, the integration and validation of the hardware and software architectures on DoD systems could be used to demonstrate the capability and maturity of the GAPS approach for the kinds of problems DoD system integrators currently face, and expect to see in the future. Commercializing the resulting technologies is also an objective of the program. The verifiable security properties created under GAPS may also help create safer commercial systems that could be used for preserving proprietary information and protecting consumer privacy. GAPS is part of the second phase of DARPA's Electronics Resurgence Initiative (ERI) - a five-year, upwards of $1.5 billion investment in the future of domestic, U.S. government and defense electronics systems. Under ERI Phase II, DARPA is exploring the development of trusted electronics components, including the advancement of electronics that can enforce security and privacy protections. GAPS will help address the DoD's unique requirements for assured electronics while helping to move forward ERI's broader mission of creating a more robust, secure and heavily automated electronics industry. DARPA will hold a Proposers Day on January 23, 2019 from 9:00am to 2:30pm (EST) at the DARPA Conference Center, located at 675 North Randolph Street, Arlington, Virginia 22203, to provide more information about GAPS and answer questions from potential proposers. For details on the event, including registration requirements, please visit: http://www.cvent.com/events/gaps-proposers-day/event-summary-34cbadc0ab2248bb860db3df8223a2f6.aspx. A Broad Agency Announcement that fully describes the GAPS program structure and objectives can be found here: https://www.fbo.gov/index?s=opportunity&mode=form&id=cfecfe762954149924ec59c95ec6a7b8&tab=core&_cview=1. https://www.darpa.mil/news-events/2019-01-16

Toutes les nouvelles