* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, October 15, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Bluesman James Montgomery Will Perform In Falmouth – CapeNews.net

    Blues Legend James Montgomery Ready to Ignite the Stage in Falmouth

    Mexican singer Pedro Fernández to make Ave Fénix tour stop in Stockton. Tickets, schedule – Yahoo

    Mexican Singer Pedro Fernández Brings the Ave Fénix Tour to Stockton – Don’t Miss It!

    Flutter Entertainment’s SWOT Analysis: Uncovering the Growth Potential Amid Challenges

    Dylan Efron Shares Sweet ‘DWTS’ Rehearsal Photos Featuring His Little Sister Olivia – yahoo.com

    Dylan Efron’s Heartwarming ‘DWTS’ Rehearsal Moments with Little Sister Olivia

    Diane Keaton, Oscar-Winning Star of ‘Annie Hall’ and ‘The Godfather,’ Dies at 79 – Yahoo

    Diane Keaton, Oscar-Winning Star of ‘Annie Hall’ and ‘The Godfather,’ Dies at 79 – Yahoo

    THE VAMPIRE LESTAT Shares First Look Teaser Trailer (And It’s Fangtastic) – Yahoo

    THE VAMPIRE LESTAT Shares First Look Teaser Trailer (And It’s Fangtastic) – Yahoo

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Tracking DNA and RNA Together To Unlock Disease Insights – Technology Networks

    Unlocking Disease Insights by Tracking DNA and RNA Together

    The future of battery technology – Engineer Live

    Revolutionizing Energy: Exploring the Future of Battery Technology

    How Can Boosting Your Travel Experience with Less Technology Lead to a More Relaxing Vacation? All You Need to Know About This Latest Trend – Travel And Tour World

    How Can Boosting Your Travel Experience with Less Technology Lead to a More Relaxing Vacation? All You Need to Know About This Latest Trend – Travel And Tour World

    Davenport CornCon Cybersecurity Conference helps students explore technology, AI use – KWQC

    Davenport CornCon Cybersecurity Conference Ignites Student Passion for Technology and AI Innovations

    Inside Europe’s military technology resurgence – NBC News

    Europe’s Bold Comeback: Unveiling the Rise of Cutting-Edge Military Technology

    Vicor Corporation: Great Technology, Execution Trapped In Time (NASDAQ:VICR) – Seeking Alpha

    Vicor Corporation: Innovative Technology Hindered by Lackluster Execution

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Bluesman James Montgomery Will Perform In Falmouth – CapeNews.net

    Blues Legend James Montgomery Ready to Ignite the Stage in Falmouth

    Mexican singer Pedro Fernández to make Ave Fénix tour stop in Stockton. Tickets, schedule – Yahoo

    Mexican Singer Pedro Fernández Brings the Ave Fénix Tour to Stockton – Don’t Miss It!

    Flutter Entertainment’s SWOT Analysis: Uncovering the Growth Potential Amid Challenges

    Dylan Efron Shares Sweet ‘DWTS’ Rehearsal Photos Featuring His Little Sister Olivia – yahoo.com

    Dylan Efron’s Heartwarming ‘DWTS’ Rehearsal Moments with Little Sister Olivia

    Diane Keaton, Oscar-Winning Star of ‘Annie Hall’ and ‘The Godfather,’ Dies at 79 – Yahoo

    Diane Keaton, Oscar-Winning Star of ‘Annie Hall’ and ‘The Godfather,’ Dies at 79 – Yahoo

    THE VAMPIRE LESTAT Shares First Look Teaser Trailer (And It’s Fangtastic) – Yahoo

    THE VAMPIRE LESTAT Shares First Look Teaser Trailer (And It’s Fangtastic) – Yahoo

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Tracking DNA and RNA Together To Unlock Disease Insights – Technology Networks

    Unlocking Disease Insights by Tracking DNA and RNA Together

    The future of battery technology – Engineer Live

    Revolutionizing Energy: Exploring the Future of Battery Technology

    How Can Boosting Your Travel Experience with Less Technology Lead to a More Relaxing Vacation? All You Need to Know About This Latest Trend – Travel And Tour World

    How Can Boosting Your Travel Experience with Less Technology Lead to a More Relaxing Vacation? All You Need to Know About This Latest Trend – Travel And Tour World

    Davenport CornCon Cybersecurity Conference helps students explore technology, AI use – KWQC

    Davenport CornCon Cybersecurity Conference Ignites Student Passion for Technology and AI Innovations

    Inside Europe’s military technology resurgence – NBC News

    Europe’s Bold Comeback: Unveiling the Rise of Cutting-Edge Military Technology

    Vicor Corporation: Great Technology, Execution Trapped In Time (NASDAQ:VICR) – Seeking Alpha

    Vicor Corporation: Innovative Technology Hindered by Lackluster Execution

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

NCSC warns CNI operators over ‘living-off-the-land’ attacks

February 11, 2024
in Technology
NCSC warns CNI operators over ‘living-off-the-land’ attacks
Share on FacebookShare on Twitter

Malicious, state-backed actors may well be lurking in the UK’s most critical networks right now, and their operators may not even know until it is too late, warn the NCSC and its partners


Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 07 Feb 2024 20:47

The UK’s National Cyber Security Centre (NCSC), together with its Five Eyes allies from Australia, Canada, New Zealand and the United States, have issued an urgent warning to operators of critical national infrastructure (CNI), sharing new details of how state-backed threat actors are using living-off-the-land techniques to persist on their networks.

Living-off-the-land refers to the exploitation of existing, legitimate tools on users’ IT systems in order to blend in to naturally occurring traffic that would not ordinarily raise any eyebrows. By exploiting these tools or binaries – also known as LOLbins – malicious actors can slip past security defences and teams with relative ease and operate discretely in the service of their paymasters.

The NCSC said that even organisations with the most mature cyber security techniques could easily fail to spot a living-off-the-land attack, and assessed it is “likely” that such activity poses a clear threat to CNI in the UK. As such, it is urging all CNI operators – energy suppliers, water companies, telecoms operators, and so on – to follow a series of recommended actions to help detect compromises and mitigate vulnerabilities.

In particular, it warned, both Chinese and Russian hackers have been observed living-off-the-land on compromised CNI networks – one prominent exponent of the technique is the GRU-sponsored advanced persistent threat (APT) actor known as Sandworm, which uses LOLbins extensively to attack targets in Ukraine.

“It is vital that operators of UK critical infrastructure heed this warning about cyber attackers using sophisticated techniques to hide on victims’ systems,” said NCSC operations director Paul Chichester.

“Threat actors left to carry out their operations undetected present a persistent and potentially very serious threat to the provision of essential services. Organisations should apply the protections set out in the latest guidance to help hunt down and mitigate any malicious activity found on their networks.”

“In this new dangerous and volatile world where the frontline is increasingly online, we must protect and future proof our systems,” added deputy prime minister Oliver Dowden. “Earlier this week, I announced an independent review to look at cyber security as an enabler to build trust, resilience and unleash growth across the UK economy.

“By driving up the resilience of our critical infrastructure across the UK we will defend ourselves from cyber attackers that would do us harm,” he added.

Priority actions for defenders

While it is imperative for CNI operators to adopt a defence-in-depth approach to their cyber security posture as part of standard best practice – the newly-published guidance outlines a number of priority recommendations:

Security teams should implement logging and aggregate logs in an out-of-band, centralised location;
They should establish a baseline of user, network and application activity and implement automation to continuously review and compare activity logs;
They should reduce alert noise;
They should implement application allow-listing;
They should enhance network segmentation and monitoring;
They should implement authentication controls;
They should seek to leverage user and entity behaviour analytics (UEBA).

More detail on these and other recommendations have been published by the US authorities and are available to read on the Cybersecurity and Infrastructure Security Agency (CISA) website.

LogRhythm customer solutions engineer Gabrielle Hempel said: “Critical infrastructure systems are extremely complex and interconnected, which makes them not only difficult to secure against attacks, but requiring specialised knowledge to understand and mitigate any vulnerabilities they might have.

“Often, critical infrastructure organisations also have resource constraints, which makes it difficult to implement and maintain security measures both from a personnel and financial standpoint.”

The costs arising from attacks on CNI will likely be multi-stage, including the upfront cost of incident response, system recovery and replacement, and any regulatory fines and legal costs that may follow, said Hempel. However, following this there will also be intense supply chain disrupted cascading down through various systems that may ultimately drive up costs for consumers.

“The collaborative warning highlights the alarming fact that the same cyber threats are having an impact across the globe,” added Hempel.

“There are numerous opportunities for strengthening international collaboration, including the real-time sharing of information and intelligence, joint research initiatives, and development of unified standards and frameworks for cyber security.

“However, it is also important to stress the importance of developing public-private partnerships not only nationally, but on a global scale in order to truly address vulnerabilities and attacks on critical infrastructure across the board. Because these attacks simultaneously span the globe geographically and organisations from public to private, they need to be addressed across these planes as well,” she said.

Volt Typhoon blows in

At the same time, the Five Eyes agencies also published a separate advisory sharing details of the Chinese APT known as Volt Typhoon, which first came to attention via Microsoft in May 2023.

Volt Typhoon is another active exploiter of LOLbins, which it has used extensively to compromise CNI systems in the US in particular. Just last week, the US authorities disrupted one Volt Typhoon operation that saw the operation hijack hundreds of vulnerable Cisco and Netgear routers to create a botnet that was used to obfuscate follow-on attacks on CNI operators.

CISA said it had confirmed Volt Typhoon has compromised the networks of US CNI operators in the comms, energy, transport and water sectors.

The agency warned that the APT’s targeting and behaviour pattern is not consistent with traditional Chinese cyber espionage, which tends to focus on intellectual property (IP) theft.

As such, it assesses with a high degree of confidence that Volt Typhoon is pre-positioning itself to enable lateral movements to operational technology (OT) assets that they can disrupt should geopolitical tensions – notably over Taiwan – escalate into conflict.

“The PRC [People’s Republic of China] cyber threat is not theoretical: leveraging information from our government and industry partners, CISA teams have found and eradicated Volt Typhoon intrusions into critical infrastructure across multiple sectors. And what we’ve found to date is likely the tip of the iceberg,” said CISA director Jen Easterly.

“Today’s joint advisory and guide are the result of effective, persistent operational collaboration with our industry, federal, and international partners and reflect our continued commitment to providing timely, actionable guidance to all of our stakeholders. We are at a critical juncture for our national security. We strongly encourage all critical infrastructure organisations to review and implement the actions in these advisories and report any suspected Volt Typhoon or living off the land activity to CISA or FBI.”

Read more on Hackers and cybercrime prevention


CISA: Volt Typhoon had access to some U.S. targets for 5 years

ArielleWaldman

By: Arielle Waldman


Critical infrastructure hacks raise alarms on Chinese threats

AlexanderCulafi

By: Alexander Culafi


US government disrupts Chinese botnet containing hundreds of end-of-life Cisco and Netgear routers

CarolineDonnelly

By: Caroline Donnelly


Rogue state-aligned actors are most critical cyber threat to UK

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366569240/NCSC-warns-CNI-operators-over-living-off-the-land-attacks

Tags: operatorstechnologywarns
Previous Post

How Iranian cyber ops pivoted to target Israel after 7 October attacks

Next Post

The Post Office Scandal: Drawing parallels between Horizon and the UK cloud market

Preview: could Premier League fitness make the difference in recurve men? – World Archery

Could Premier League Fitness Be the Game-Changer for Recurve Men?

October 15, 2025
The $2.5 trillion ocean economy is at a crossroads. Capital must act now – Fortune

The $2.5 Trillion Ocean Economy at a Crossroads: Why Urgent Capital Investment Is Essential

October 15, 2025
Bluesman James Montgomery Will Perform In Falmouth – CapeNews.net

Blues Legend James Montgomery Ready to Ignite the Stage in Falmouth

October 15, 2025
30-year decline in Kansas health can be reversed with leadership, report finds – Kansas Reflector

30-year decline in Kansas health can be reversed with leadership, report finds – Kansas Reflector

October 15, 2025
Scorecard ranks Northwest politician as the most Trump-aligned Democrat in Congress – OregonLive.com

Northwest Politician Touted as the Most Trump-Aligned Democrat in Congress

October 14, 2025
CVYS reiterates ban on activities threatening ecology and public order – Nagaland Tribune

CVYS Takes a Strong Stand to Protect Ecology and Public Safety

October 14, 2025
Inaugural Implementation Science Symposium Highlights Excitement for Burgeoning Discipline – Geisel School of Medicine at Dartmouth

Inaugural Implementation Science Symposium Ignites Excitement for Emerging Field

October 14, 2025
Scientists find the brain’s hidden pulse that may predict Alzheimer’s – ScienceDaily

Scientists find the brain’s hidden pulse that may predict Alzheimer’s – ScienceDaily

October 14, 2025
You know you’re smarter than someone if these 10 thought patterns are obvious to you but not them – VegOut

10 Thought Patterns That Show You’re Smarter Than Most People

October 14, 2025
New Strider Report Reveals Scope and Scale of U.S. Academic Research Done in Collaboration with PLA-Affiliated Entities on STEM Technologies – PR Newswire

New Strider Report Reveals Widespread U.S. Academic Collaborations with PLA-Linked Entities in STEM Technologies

October 14, 2025

Categories

Archives

October 2025
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Sep    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (867)
  • Economy (889)
  • Entertainment (21,761)
  • General (17,598)
  • Health (9,931)
  • Lifestyle (901)
  • News (22,149)
  • People (889)
  • Politics (899)
  • Science (16,099)
  • Sports (21,388)
  • Technology (15,868)
  • World (872)

Recent News

Preview: could Premier League fitness make the difference in recurve men? – World Archery

Could Premier League Fitness Be the Game-Changer for Recurve Men?

October 15, 2025
The $2.5 trillion ocean economy is at a crossroads. Capital must act now – Fortune

The $2.5 Trillion Ocean Economy at a Crossroads: Why Urgent Capital Investment Is Essential

October 15, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version