Most Popular Stories
Events
- Customer Engagement Technology World
March 28-29, 2012 — San Francisco - DrupalCon Denver: Drupal Means Business
March 20 - 23, 2012 — Denver, CO - MDSL Telecom Expense Management Roadshow
Feb 21–23, 2012 — New York, Houston, Chicago - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> Tech world's top flops and fiascos of 2011 | Windows 8 slideshow | Cybersecurity | Caron's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
FierceCIO provides CIOs with IT best practices, business intelligence, and forward-looking IT strategies. Join 32,000+ industry insiders who get FierceCIO twice a week via email and save time.
About | View Sample | Privacy
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Whitepaper: 10 Reasons You Absolutely Need AD Reporting
- 5 Must Haves in your Information Management Strategy
- Because Hope Is Not A Strategy: Business Continuity/Disaster Recovery Planning
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
- Storage Consolidation: Best of Both Worlds
Researchers expose security holes in SCADA systems
Manufacturing plants and critical infrastructure facilities may have received a rude awakening last week when researchers released exploit modules after finding major security flaws in industrial control systems, reports Kim Zetter at Wired. Armed with the modules, hackers may have been able to attack the systems before organizations had a chance to patch them or shut them down.
The flaws were discovered in programmable logic controllers (PLCs) built by five manufacturers, including General Electric, Rockwell Automation, Schneider Modicon, Koyo Electronics and Schweitzer Engineering. The devices control functions on assembly lines and in utilities like water, power and nuclear plants. The security holes include backdoors, no encryption and authentication and poor password storage.
The researchers, led by SCADA security firm Digital Bond, said they publicized the exploit modules, which they released with help from Rapid7, to demonstrate the vulnerability of the systems.
"We felt it was important to provide tools that showed critical infrastructure owners how easy it is for an attacker to take control of their system with potentially catastrophic results," said Dale Peterson, founder of Digital Bond.
Peterson said he hoped the news of the security flaws and the release of the exploits would spur the PLC vendors into making security a higher priority. "We kind of view this as just a first step maybe to help prod the industry to move forward to do something about it," he said, asserting that "a large percentage" of the flaws were known to the PLC makers who had "chosen to live with" them.
For more:
- see Kim Zetter's article at Wired
Related Articles:
Consultant: Companies running critical infrastructure take months to patch holes
Report: Majority of software programs lack acceptable security
Thinking about security from the beginning
Related Stories
- Businesses hold third-party software to lower standards
- Consultant: Companies running critical infrastructure take months to patch holes
- Report: Majority of software programs lack acceptable security
- GAO: Cyber data sharing falls short
- Corporate America's dumbest security bungles
- NSA's Perfect Citizen to peek into private networks
- Thinking about security from the beginning
- Experts ponder software security conundrum
- Data centers head underground
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceCRO | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2012 FierceMarkets. All rights reserved. |
![]() |




