* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, August 17, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    ‘The Rainmaker’ Premiere: Milo Callaghan Breaks Down Rudy Baylor’s ‘Misguided Valor’ – The Laconia Daily Sun

    Inside ‘The Rainmaker’ Premiere: Milo Callaghan Uncovers the Real Story Behind Rudy Baylor’s Misguided Valor

    Suicide Squad Member Gets New Origin in Absolute Flash – yahoo.com

    Suicide Squad Member Unveiled with Exciting New Origin in Absolute Flash

    I’ll miss the chaos of ‘And Just like That…’ (and Che Diaz too) – yahoo.com

    Why I’ll Truly Miss the Wild Ride of ‘And Just Like That…’ (and Che Diaz!)

    Webtoon Entertainment Stages Recovery With Disney’s Stamp of Approval – The Wall Street Journal

    Webtoon Entertainment Soars to New Heights with Disney’s Stamp of Approval

    Georgia Tech Launches Arts, Entertainment, and Creative Technologies Degree – Georgia Tech News Center

    Georgia Tech Unveils Exciting New Degree in Arts, Entertainment, and Creative Technologies

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Youxin Technology Ltd Faces Nasdaq Deficiency Notices Over Listing Compliance Issues

    Vermont famers say new technology is changing the state’s agriculture industry – News Channel 3-12

    Vermont Farmers Embrace New Technology Transforming the State’s Agriculture Industry

    Verb Technology Reports Revenue Growth Amidst Strategic Expansions – TipRanks

    Verb Technology Soars with Impressive Revenue Growth Driven by Strategic Expansions

    Midwest Technology Summit held in Fargo – WDAY Radio

    Midwest Technology Summit held in Fargo – WDAY Radio

    K1 Semiconductor Joins Chicago Quantum Exchange To Advance Wafer Technology. – Quantum Zeitgeist

    K1 Semiconductor Partners with Chicago Quantum Exchange to Revolutionize Wafer Technology

    Indirect tax transformation: Navigating change, embracing technology – Thomson Reuters tax and accounting

    Revolutionizing Indirect Tax: Embracing Technology to Navigate Change

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    ‘The Rainmaker’ Premiere: Milo Callaghan Breaks Down Rudy Baylor’s ‘Misguided Valor’ – The Laconia Daily Sun

    Inside ‘The Rainmaker’ Premiere: Milo Callaghan Uncovers the Real Story Behind Rudy Baylor’s Misguided Valor

    Suicide Squad Member Gets New Origin in Absolute Flash – yahoo.com

    Suicide Squad Member Unveiled with Exciting New Origin in Absolute Flash

    I’ll miss the chaos of ‘And Just like That…’ (and Che Diaz too) – yahoo.com

    Why I’ll Truly Miss the Wild Ride of ‘And Just Like That…’ (and Che Diaz!)

    Webtoon Entertainment Stages Recovery With Disney’s Stamp of Approval – The Wall Street Journal

    Webtoon Entertainment Soars to New Heights with Disney’s Stamp of Approval

    Georgia Tech Launches Arts, Entertainment, and Creative Technologies Degree – Georgia Tech News Center

    Georgia Tech Unveils Exciting New Degree in Arts, Entertainment, and Creative Technologies

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Youxin Technology Ltd Faces Nasdaq Deficiency Notices Over Listing Compliance Issues

    Vermont famers say new technology is changing the state’s agriculture industry – News Channel 3-12

    Vermont Farmers Embrace New Technology Transforming the State’s Agriculture Industry

    Verb Technology Reports Revenue Growth Amidst Strategic Expansions – TipRanks

    Verb Technology Soars with Impressive Revenue Growth Driven by Strategic Expansions

    Midwest Technology Summit held in Fargo – WDAY Radio

    Midwest Technology Summit held in Fargo – WDAY Radio

    K1 Semiconductor Joins Chicago Quantum Exchange To Advance Wafer Technology. – Quantum Zeitgeist

    K1 Semiconductor Partners with Chicago Quantum Exchange to Revolutionize Wafer Technology

    Indirect tax transformation: Navigating change, embracing technology – Thomson Reuters tax and accounting

    Revolutionizing Indirect Tax: Embracing Technology to Navigate Change

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

NCSC warns CNI operators over ‘living-off-the-land’ attacks

February 11, 2024
in Technology
NCSC warns CNI operators over ‘living-off-the-land’ attacks
Share on FacebookShare on Twitter

Malicious, state-backed actors may well be lurking in the UK’s most critical networks right now, and their operators may not even know until it is too late, warn the NCSC and its partners


Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 07 Feb 2024 20:47

The UK’s National Cyber Security Centre (NCSC), together with its Five Eyes allies from Australia, Canada, New Zealand and the United States, have issued an urgent warning to operators of critical national infrastructure (CNI), sharing new details of how state-backed threat actors are using living-off-the-land techniques to persist on their networks.

Living-off-the-land refers to the exploitation of existing, legitimate tools on users’ IT systems in order to blend in to naturally occurring traffic that would not ordinarily raise any eyebrows. By exploiting these tools or binaries – also known as LOLbins – malicious actors can slip past security defences and teams with relative ease and operate discretely in the service of their paymasters.

The NCSC said that even organisations with the most mature cyber security techniques could easily fail to spot a living-off-the-land attack, and assessed it is “likely” that such activity poses a clear threat to CNI in the UK. As such, it is urging all CNI operators – energy suppliers, water companies, telecoms operators, and so on – to follow a series of recommended actions to help detect compromises and mitigate vulnerabilities.

In particular, it warned, both Chinese and Russian hackers have been observed living-off-the-land on compromised CNI networks – one prominent exponent of the technique is the GRU-sponsored advanced persistent threat (APT) actor known as Sandworm, which uses LOLbins extensively to attack targets in Ukraine.

“It is vital that operators of UK critical infrastructure heed this warning about cyber attackers using sophisticated techniques to hide on victims’ systems,” said NCSC operations director Paul Chichester.

“Threat actors left to carry out their operations undetected present a persistent and potentially very serious threat to the provision of essential services. Organisations should apply the protections set out in the latest guidance to help hunt down and mitigate any malicious activity found on their networks.”

“In this new dangerous and volatile world where the frontline is increasingly online, we must protect and future proof our systems,” added deputy prime minister Oliver Dowden. “Earlier this week, I announced an independent review to look at cyber security as an enabler to build trust, resilience and unleash growth across the UK economy.

“By driving up the resilience of our critical infrastructure across the UK we will defend ourselves from cyber attackers that would do us harm,” he added.

Priority actions for defenders

While it is imperative for CNI operators to adopt a defence-in-depth approach to their cyber security posture as part of standard best practice – the newly-published guidance outlines a number of priority recommendations:

Security teams should implement logging and aggregate logs in an out-of-band, centralised location;
They should establish a baseline of user, network and application activity and implement automation to continuously review and compare activity logs;
They should reduce alert noise;
They should implement application allow-listing;
They should enhance network segmentation and monitoring;
They should implement authentication controls;
They should seek to leverage user and entity behaviour analytics (UEBA).

More detail on these and other recommendations have been published by the US authorities and are available to read on the Cybersecurity and Infrastructure Security Agency (CISA) website.

LogRhythm customer solutions engineer Gabrielle Hempel said: “Critical infrastructure systems are extremely complex and interconnected, which makes them not only difficult to secure against attacks, but requiring specialised knowledge to understand and mitigate any vulnerabilities they might have.

“Often, critical infrastructure organisations also have resource constraints, which makes it difficult to implement and maintain security measures both from a personnel and financial standpoint.”

The costs arising from attacks on CNI will likely be multi-stage, including the upfront cost of incident response, system recovery and replacement, and any regulatory fines and legal costs that may follow, said Hempel. However, following this there will also be intense supply chain disrupted cascading down through various systems that may ultimately drive up costs for consumers.

“The collaborative warning highlights the alarming fact that the same cyber threats are having an impact across the globe,” added Hempel.

“There are numerous opportunities for strengthening international collaboration, including the real-time sharing of information and intelligence, joint research initiatives, and development of unified standards and frameworks for cyber security.

“However, it is also important to stress the importance of developing public-private partnerships not only nationally, but on a global scale in order to truly address vulnerabilities and attacks on critical infrastructure across the board. Because these attacks simultaneously span the globe geographically and organisations from public to private, they need to be addressed across these planes as well,” she said.

Volt Typhoon blows in

At the same time, the Five Eyes agencies also published a separate advisory sharing details of the Chinese APT known as Volt Typhoon, which first came to attention via Microsoft in May 2023.

Volt Typhoon is another active exploiter of LOLbins, which it has used extensively to compromise CNI systems in the US in particular. Just last week, the US authorities disrupted one Volt Typhoon operation that saw the operation hijack hundreds of vulnerable Cisco and Netgear routers to create a botnet that was used to obfuscate follow-on attacks on CNI operators.

CISA said it had confirmed Volt Typhoon has compromised the networks of US CNI operators in the comms, energy, transport and water sectors.

The agency warned that the APT’s targeting and behaviour pattern is not consistent with traditional Chinese cyber espionage, which tends to focus on intellectual property (IP) theft.

As such, it assesses with a high degree of confidence that Volt Typhoon is pre-positioning itself to enable lateral movements to operational technology (OT) assets that they can disrupt should geopolitical tensions – notably over Taiwan – escalate into conflict.

“The PRC [People’s Republic of China] cyber threat is not theoretical: leveraging information from our government and industry partners, CISA teams have found and eradicated Volt Typhoon intrusions into critical infrastructure across multiple sectors. And what we’ve found to date is likely the tip of the iceberg,” said CISA director Jen Easterly.

“Today’s joint advisory and guide are the result of effective, persistent operational collaboration with our industry, federal, and international partners and reflect our continued commitment to providing timely, actionable guidance to all of our stakeholders. We are at a critical juncture for our national security. We strongly encourage all critical infrastructure organisations to review and implement the actions in these advisories and report any suspected Volt Typhoon or living off the land activity to CISA or FBI.”

Read more on Hackers and cybercrime prevention


CISA: Volt Typhoon had access to some U.S. targets for 5 years

ArielleWaldman

By: Arielle Waldman


Critical infrastructure hacks raise alarms on Chinese threats

AlexanderCulafi

By: Alexander Culafi


US government disrupts Chinese botnet containing hundreds of end-of-life Cisco and Netgear routers

CarolineDonnelly

By: Caroline Donnelly


Rogue state-aligned actors are most critical cyber threat to UK

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366569240/NCSC-warns-CNI-operators-over-living-off-the-land-attacks

Tags: operatorstechnologywarns
Previous Post

How Iranian cyber ops pivoted to target Israel after 7 October attacks

Next Post

The Post Office Scandal: Drawing parallels between Horizon and the UK cloud market

Little League World Series pleads for fans to not bet on games involving children – Yahoo Sports

Little League World Series Urges Fans to Avoid Betting on Youth Games

August 16, 2025
What 630,000 paintings say about the world economy – The Economist

What 630,000 Paintings Uncover About the Hidden Patterns of the Global Economy

August 16, 2025
Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

August 16, 2025
Amid growing ‘scandal’ of elder homelessness, health care groups aim to help – NPR

Amid growing ‘scandal’ of elder homelessness, health care groups aim to help – NPR

August 16, 2025
TGIF: Ian Donnis’ Rhode Island politics roundup for Aug. 15, 2025 – The Public’s Radio

Friday Focus: Ian Donnis’ Top Rhode Island Politics Highlights for August 15, 2025

August 16, 2025

Meet the Stunning Winners of the 2025 Ecology, Evolution, and Zoology Image Competition!

August 16, 2025
Topological spin textures: Scientists use micro-structured materials to control light propagation – Phys.org

Harnessing Topological Spin Textures: How Micro-Structured Materials Revolutionize Light Control

August 16, 2025
UCLA Computer Science Alumna and Taboola Executive Helps Lead Global AI Efforts to Empower Digital Media – UCLA Samueli School of Engineering

UCLA Computer Science Alumna and Taboola Executive Leading Global AI Innovation to Revolutionize Digital Media

August 16, 2025
The Future Of Cannabis: A Lifestyle Product Mirroring Wine’s Evolution – Harlem World Magazine

The Future Of Cannabis: A Lifestyle Product Mirroring Wine’s Evolution – Harlem World Magazine

August 16, 2025

Youxin Technology Ltd Faces Nasdaq Deficiency Notices Over Listing Compliance Issues

August 16, 2025

Categories

Archives

August 2025
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Jul    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (774)
  • Economy (797)
  • Entertainment (21,674)
  • General (16,505)
  • Health (9,835)
  • Lifestyle (807)
  • News (22,149)
  • People (798)
  • Politics (804)
  • Science (16,009)
  • Sports (21,294)
  • Technology (15,776)
  • World (779)

Recent News

Little League World Series pleads for fans to not bet on games involving children – Yahoo Sports

Little League World Series Urges Fans to Avoid Betting on Youth Games

August 16, 2025
What 630,000 paintings say about the world economy – The Economist

What 630,000 Paintings Uncover About the Hidden Patterns of the Global Economy

August 16, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version