14 septembre 2018 | International, C4ISR

Really old computer viruses are still infecting new machines

By:

The biggest cyber threats governments and businesses face may not be the cutting edge hack from China, but a 10-year-old virus that infects a little-used computer.

Some of the most well-known viruses from the past decade are still infecting machines despite their well-documented nature, according to cyber research firms. Some viruses, such as WannaCry and Conficker, are still spreading, Sean Sullivan, a security adviser at F-Secure told Fifth Domain.

“It costs hackers nothing to keep using them,” Sullivan said.

These known vulnerabilities are still effective because older machines do not receive patches for updates, which can then infect an entire network. Hackers often bundle known hacks together because it increases their success rate with no downside, Sullivan said.

“Nothing is going to be 100 percent patched across organizations,” Sullivan, said. He described a network administrator's role as “triage.”

The 2017 WannaCry hack infected users in more than 150 countries and had an economic impact of anywhere from $4 billion to $8 billion. Although progress has been made to patch computers, WannaCry is still a top malware threat for customers, F-Stream said in a September report.

The Conficker hack targeted Windows systems and was first launched in 2008. It is reported to have cost as much as $9 billion in damage.

But much work remains. More than two-billion devices have not been patched to defend against BlueBorne, a Bluetooth vulnerability that allows an attacker to take over devices, according to the cyber protection company Armis. The devices are still vulnerable because they have not been updated or because an update does not exist, according to the company.

“Whether they're brought in by employees and contractors, or by guests using enterprise networks for temporary connectivity, these devices can expose enterprises to significant risks,” wrote Ben Seri, the vice president of research at Armis.

A previous version of this article said that two million devices have not been patched to defend against BlueBorne. It is two billion.

https://www.fifthdomain.com/industry/2018/09/13/really-old-computer-viruses-are-still-infecting-new-machines

Sur le même sujet

  • The US Navy’s new autonomous refueling drone takes historic first flight

    20 septembre 2019 | International, Aérospatial

    The US Navy’s new autonomous refueling drone takes historic first flight

    By: David B. Larter WASHINGTON — The U.S. Navy's MQ-25 Stingray refueling drone, destined to be the first carrier-launched autonomous unmanned aircraft integrated into the service's strike arm, took its first test flight from MidAmerica Airport in Illinois, Boeing announced Thursday. The two-hour flight, remotely controlled by Boeing pilots, tested the basic flight functions of the aircraft, a Boeing statement said. “The aircraft completed an autonomous taxi and takeoff and then flew a pre-determined route to validate the aircraft's basic flight functions and operations with the ground control station,” the release said. Boeing's project head said it was an important step toward getting the drone on the flight deck. “Seeing MQ-25 in the sky is a testament to our Boeing and Navy team working the technology, systems and processes that are helping get MQ-25 to the carrier,” MQ-25 Program Director Dave Bujold said in the release. “This aircraft and its flight test program ensures we're delivering the MQ-25 to the carrier fleet with the safety, reliability and capability the U.S. Navy needs to conduct its vital mission.” An $805 million contract awarded to Boeing last August covers the design, development, fabrication, test and delivery of four Stingray aircraft, a program the service expects will cost about $13 billion overall for 72 aircraft, said Navy acquisition boss James Geurts. The award to Boeing kicks off what the Navy would is aiming to be a six-year development effort moving toward a 2024 declaration of initial operational capability. At the end, it will mark a historic integration of drones into the Navy's carrier air wing. The MQ-25 flown Thursday is a Boeing-owned test asset and a predecessor to the first four engineering design model aircraft provided for under last year's contract. The model “is being used for early learning and discovery to meet the goals of the U.S. Navy's accelerated acquisition program,” the release said. The Stingray was a priority pushed by the Navy's previous chief of naval operations, Adm. John Richardson, who saw it as a chance to force a program through the system and field a new capability quickly. “The MQ-25 was really a signature program to test the limits and plow new ground in that direction,” Richardson told Defense News last April. "And so we brought industry in way earlier. I think that's key to getting the acquisition cycle faster, even in the refinement of the requirements phase. “And so that's where we've been with MQ-25, is to bring them in, see what they've got and see how fast they can get a prototype together to fly. One thing we did do was we locked down on requirements. We could probably get agreement from everybody that we need something to tank. It liberates a lot of our strike fighters from doing that mission and it's something that we can get done ― its relatively straightforward.” https://www.defensenews.com/naval/2019/09/19/the-us-navys-new-autonomous-refueling-drone-takes-historic-first-flight

  • NATO official warns EU force would be ‘unwise’

    19 novembre 2018 | International, Aérospatial, Naval, Terrestre, C4ISR

    NATO official warns EU force would be ‘unwise’

    By: Joe Gould HALIFAX, Canada — A top uniformed NATO official warned Friday the European Union army concept endorsed by French President Emmanuel Macron and German Chancellor Angela Merkel would be “duplicative” and “unwise.” In an interview at the Halifax International Security Forum, UK Air Marshal Sir Stuart Peach, chairman of the NATO Military Committee, pointed to NATO's strength as a single set of forces, with a unique command and control network and planning process. “It's not rhetoric based. It's real planning based on real data,” Peach said. “And therefore, why would you wish to duplicate or replicate the strengths of an existing strong alliance.” The comments came after Merkel on Tuesday floated the idea of a “real, true European army,” to compliment NATO during a speech before a session of the European Parliament. Those remarks virtually echoed Macron's call a week earlier, in an interview with Europe 1. U.S. President Donald Trump called Macron's comments “very insulting” in a spate of Twitter posts as the two held a meeting last week in Paris. Trump himself has tested the strained bonds with some of America's closest allies by pressuring NATO allies to rely less on the U.S. and dedicate a greater percentage of their gross domestic products to defense. On Tuesday, NATO Secretary General Jens Stoltenberg alluded the proposal of a European force at a NATO conference in Berlin, saying he welcomed, “increased EU efforts on defense, because I think that can actually help to strengthen NATO.” European allied militaries can act without the U.S. so long as they use NATO command structures, Stoltenberg said. “It will be not a wise decision by all those nations who are members of both NATO and the European Union to start to have two sets of command structures, or duplicate what NATO is doing,” Stoltenberg said. On Friday, Peach referred to Stoltenberg's remarks, saying, “Of course, as chairman of the military committee, I agree with [Stoltenberg]. It's unwise to duplicate.” Peach emphasized that NATO has a, “single set of forces, and in our processes, those forces are trained, and assured and certified by NATO.” At the conference, Peach had a broader message that the alliance's 29 members member remain committed to it — and that it is adapting with the times. “Throughout the history of the alliance there have been inevitable tussles about how to go forward,” Peach said. “But throughout as a military alliance, we have adapted our command and control structure, responded to new challenges, embraced new members and continued to adapt to new types of warfare and new threats.” Separately, Finland and Norway intend to launch diplomatic discussions with Moscow over suspected GPS signal-jamming by Russia's military, which overlapped with NATO's Trident Juncture exercises, the largest maneuvers in the High North since the end of the Cold War. Peach on Friday would not confirm the interference took place, but called the principle of freedom of navigation, “very, very important, both to NATO and the International community.” “Freedom of navigation is not just freedom of navigation at sea, so we need to analyze claims with data. And anything that interrupts freedom of navigation is important to be reported," he said. How to manage and operate within the electromagnetic spectrum are important topics that deserve more attention, he said. https://www.defensenews.com/global/europe/2018/11/17/nato-official-warns-eu-force-would-be-unwise/

  • The military wants many systems to share one language

    11 février 2019 | International, C4ISR

    The military wants many systems to share one language

    By: Mark Pomerleau The Army, Navy and Air Force secretaries recently signed a memorandum that would establish common standards of information in future weapon systems, a move that will allow for greater coordination on a future battlefield that will require faster decision making. As the military is shifting its focus to so-called great powers and simultaneously each pursing its own version of multidomain operations — a concept of operating more seamlessly across the five domains of warfare — there is a recognition for the need for closer cooperation. According to an Air Force release Feb. 8, older weapon systems were not developed with common interface standards, which made interoperability more difficult. “This is vital to our success,” said Mark Esper, the secretary of the Army. “After reviewing the capabilities of common standards, we have collectively determined that continued implementation, and further development of modular open systems approaches are necessary to keep our competitive advantage.” In recent years, the services have developed, demonstrated and validated common data standards through a cooperative partnership with industry and academia to allow for a modular open systems approach, the release said. When the services follow the standards, contractors can build interoperable systems. This approach can lead significantly reduce development timelines and shrink costs by as much as 70 percent, the release said. “The ability for our systems and forces to exchange information and communicate effectively gives our war fighters the best capabilities to deliver the fight tonight,” Richard Spencer, the secretary of the Navy, said. “This reform will make us a highly integrated and more lethal fighting force.” With new approaches, such as multidomain operations, Pentagon leaders say it is critical for systems and forces to communicate across domains as well as cyber and land systems. "Victory in future conflict will in part be determined by our ability to rapidly share information across domains and platforms," Heather Wilson, secretary of the Air Force, said. "Sharing information from machine to machine requires common standards." Some in industry are helping the military answer some tough problems. “How do you take all the platforms that are out there and link them together and then be able to create decisions that happen a lot faster or get to decisions that you couldn't have gotten to if you were looking at each of the domains independently,” Rob Smith, vice president of C4ISR & UAS, Rotary and Mission Systems at Lockheed Martin, told reporters in July. While linking systems together may sound easy, Smith said differences in planning cycles, technologies and classifications is challenging. Going forward, the Air Force release said the joint memorandum directs service acquisition executives to publish specific implementation guidance for acquisition programs, continue to identify gaps and develop new standards when needed. Additionally, capability requirements officers must write modular open systems into future requirements documents as to be able to communicate across domains. https://www.c4isrnet.com/c2-comms/2019/02/08/the-military-wants-many-systems-to-share-one-language

Toutes les nouvelles