• About
  • Privacy & Policy
  • Contact
  • Write for us
Today Headline
  • HOME
  • NEWS
    • POLITICS
  • FINANCE
  • Video
  • ENTERPRISE
  • TECHNOLOGY
  • ENTERTAINMENT
  • LIFESTYLE
    • TRAVEL
    • HEALTH
  • AUTOMOTIVE
  • SPORTS
  • Write for us
  • HOME
  • NEWS
    • POLITICS
  • FINANCE
  • Video
  • ENTERPRISE
  • TECHNOLOGY
  • ENTERTAINMENT
  • LIFESTYLE
    • TRAVEL
    • HEALTH
  • AUTOMOTIVE
  • SPORTS
  • Write for us
No Result
View All Result
TodayHeadline
No Result
View All Result
Home Enterprise

Following Oldsmar attack, FBI warns about using TeamViewer and Windows 7

February 10, 2021
in Enterprise
0
Following Oldsmar attack, FBI warns about using TeamViewer and Windows 7
0
SHARES
6
VIEWS
Share on FacebookShare on Twitter


fbi-alert-oldsmar.png

Image: ZDNet

In the aftermath of the Oldsmar incident, where an unidentified attacker gained access to a water treatment plant’s network and modified chemical dosages to dangerous levels, the FBI has sent out an alert on Tuesday, raising attention to three security issues that have been seen on the plant’s network following last week’s hack.

The alert, called a Private Industry Notification, or FBI PIN, warns about the use of out-of-date Windows 7 systems, poor passwords, and desktop sharing software TeamViewer, urging private companies and federal and government organizations to review internal networks and access policies accordingly.

TeamViewer considered the point of entry

The FBI PIN specifically names TeamViewer as a desktop sharing software to watch out for after the app was confirmed as the attacker’s entry point into the Oldsmar water treatment plant’s network.

According to a Reuters report, officials said the intruder connected to a computer on the Oldsmar water treatment plant’s network via TeamViewer on two occasions last Friday.

In the second one, the attacker actively took control of the operator’s mouse, moved it on screen, and made changes to sodium hydroxide (lye) levels that were being added to drinking water.

While the operator reversed the changes the hacker made almost immediately, the incident became an instant point of contention and discussion among security professionals.

Among the most common point brought up in online discussions was the use of the TeamViewer app to access resources on US critical infrastructure.

In a Motherboard report published on Tuesday, several well-known security experts criticized companies and workers who often use the software for remote work, calling it insecure and inadequate for managing sensitive resources.

While the FBI PIN alert doesn’t take a critical tone or stance against TeamViewer, the FBI would like federal and private sector organizations to take note of the app.

“Beyond its legitimate uses, TeamViewer allows cyber actors to exercise remote control over computer systems and drop files onto victim computers, making it functionally similar to Remote Access Trojans (RATs),” the FBI said.

“TeamViewer’s legitimate use, however, makes anomalous activity less suspicious to end users and system administrators compared to typical RATs.

The FBI alert doesn’t specifically tell organizations to uninstall TeamViewer or any other type of desktop sharing software but warns that TeamViewer and other similar software can be abused if attackers gain access to employee account credentials or if remote access accounts (such as those used for Windows RDP access) are secured with weak passwords.

FBI warns about Windows 7 use… again

In addition, the FBI alert also warns about the continued use of Windows 7, an operating system that has reached end-of-life last year, on January 14, 2020, an issue the FBI also warned US companies about last year.

This part of the warning was included because the Oldsmar water treatment plant was still using Windows 7 systems on its network.

While there is no evidence to suggest the attackers abused Windows 7-specific bugs, the FBI says that continuing to use the old operating system is dangerous as the OS is unsupported and does not receive security updates, which currently leaves many systems exposed to attacks via newly discovered vulnerabilities.

However, a Cyberscoop report published today highlights the fact that the Oldsmar plant, along with many other US water treatment facilities are often underfunded and understaffed.

While the FBI warns against the use of Windows 7 for good reasons, many companies and US federal and state agencies might not be able to do anything about it, barring a serious financial investment into modernizing IT infrastructure from upper management, something that’s not expected anytime soon in many locations.

In these cases, the FBI recommends a series of basic security best practices as an intermediary way to mitigate threats, such as:

  • Use multi-factor authentication;
  • Use strong passwords to protect Remote Desktop Protocol (RDP) credentials;
  • Ensureanti-virus, spam filters, and firewalls are up to date, properly configured, and secure;
  • Audit network configurations and isolate computer systems that cannot be updated;
  • Audit your network for systems using RDP, closing unused RDP ports, applying two-factor authentication wherever possible, and logging RDP login attempts;
  • Audit logs for all remote connection protocols;
  • Train users to identify and report attempts at social engineering;
  • Identify and suspend access of users exhibiting unusual activity;
  • Keep software updated.
 
 
   
Previous Post

Michelle Trachtenberg talks Joss Whedon: ‘Not appropriate’

Next Post

California finds first cases of coronavirus variant from South Africa

Next Post
California finds first cases of coronavirus variant from South Africa

California finds first cases of coronavirus variant from South Africa

  • Trending
  • Comments
  • Latest
PS5 restock UK: New PS5 console stock update for John Lewis, Smyths, Argos, Currys | Gaming | Entertainment

PS5 restock UK: New PS5 console stock update for John Lewis, Smyths, Argos, Currys | Gaming | Entertainment

March 6, 2021

M&S Bank to shut all current accounts and in-store branches | Money

March 6, 2021
Biden says $1,400 stimulus checks will start being sent ‘this month’

Biden says $1,400 stimulus checks will start being sent ‘this month’

March 7, 2021

Tesla share price plunge knocks $267bn off market value | Business

March 6, 2021
Nicolas Cage marries fifth wife, Riko Shibata

Nicolas Cage marries fifth wife, Riko Shibata

March 6, 2021
Doctor’s note lets Defence Minister Linda Reynolds skip parliament – and Senate grilling – for another month

Doctor’s note lets Defence Minister Linda Reynolds skip parliament – and Senate grilling – for another month

March 7, 2021
The lessons WGA learned from its battle with agencies

The lessons WGA learned from its battle with agencies

March 7, 2021
Roundup: No. 17 Oklahoma State defeats No. 6 West Virginia

Roundup: No. 17 Oklahoma State defeats No. 6 West Virginia

March 7, 2021
Threats to call ICE lobbed at Picos Mexican restaurant after it required masks

Threats to call ICE lobbed at Picos Mexican restaurant after it required masks

March 7, 2021
Nikola dropped claim on truck weight after US investigations began

Nikola dropped claim on truck weight after US investigations began

March 7, 2021

About Us

Todayheadline the independent news and topics discovery
A home-grown and independent news and topic aggregation . displays breaking news linking to news websites all around the world.

Follow Us

Latest News

Doctor’s note lets Defence Minister Linda Reynolds skip parliament – and Senate grilling – for another month

Doctor’s note lets Defence Minister Linda Reynolds skip parliament – and Senate grilling – for another month

March 7, 2021
The lessons WGA learned from its battle with agencies

The lessons WGA learned from its battle with agencies

March 7, 2021
Doctor’s note lets Defence Minister Linda Reynolds skip parliament – and Senate grilling – for another month

Doctor’s note lets Defence Minister Linda Reynolds skip parliament – and Senate grilling – for another month

March 7, 2021
The lessons WGA learned from its battle with agencies

The lessons WGA learned from its battle with agencies

March 7, 2021
Roundup: No. 17 Oklahoma State defeats No. 6 West Virginia

Roundup: No. 17 Oklahoma State defeats No. 6 West Virginia

March 7, 2021
  • About
  • Privacy & Policy
  • Contact
  • Write for us

© 2019 All rights are reserved Todayheadline

No Result
View All Result
  • About Us
  • Contact Us
  • Cookie policy (EU)
  • Home
  • Privacy Policy
  • Video
  • Write for us

© 2019 All rights are reserved Todayheadline