* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, September 26, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    ‘Today’: Sheinelle Jones Thanks Katie Couric for Support After Husband’s Death – CBS 19 News

    Sheinelle Jones Expresses Heartfelt Thanks to Katie Couric for Support After Husband’s Passing

    Sate your hunger at DBA’s Taste of Downtown – Bakersfield.com

    Indulge Your Cravings at DBA’s Taste of Downtown!

    Caesars Entertainment (CZR): Assessing Valuation After Times Square Casino Setback and Mounting Investor Concerns – simplywall.st

    Caesars Entertainment Faces Times Square Casino Hurdles as Investor Concerns Mount

    Why Hilaria Baldwin Has Found the ‘DWTS’ Process ‘Embarrassing’ At Times – WFXG

    Hilaria Baldwin Opens Up About the Embarrassing Moments on Her ‘DWTS’ Journey

    Harvest Fest 2025 – yadkinripple.com

    Celebrate the Bounty: Harvest Fest 2025 is Coming!

    Fox News Entertainment Newsletter: Kate Middleton stuns during Trump state visit, Brett James dead at 57 – Fox News

    Kate Middleton Stuns During Trump State Visit; Remembering Brett James at 57

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Autonomous Solutions shows off cutting-edge technology for the public – Cache Valley Daily

    Autonomous Solutions Unveils Cutting-Edge Technology for the Public

    Amazon to Pay $2.5 Billion in Prime Membership Settlement – The New York Times

    Amazon to Pay $2.5 Billion in Prime Membership Settlement – The New York Times

    What are we really gaining from technology? – Fast Company

    What Are We Really Gaining from Technology?

    TOMI Environmental Solutions, Inc. Expands SteraMist iHP Technology Services in Healthcare Sector with New Provider Partnership – Quiver Quantitative

    TOMI Environmental Solutions Accelerates SteraMist iHP Technology Expansion in Healthcare with New Provider Partnership

    Indiana County Technology Center’s Joint Operating Committee looks to the future as program plans began to take shape – Indiana Gazette Online

    Indiana County Technology Center’s Joint Operating Committee Charts an Exciting Path Forward as New Program Plans Take Shape

    Meta to expand Montgomery data hub, pushing total investment to $1.5 billion – Alabama Department of Commerce

    Meta to Supercharge Montgomery Data Hub with $1.5 Billion Investment

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    ‘Today’: Sheinelle Jones Thanks Katie Couric for Support After Husband’s Death – CBS 19 News

    Sheinelle Jones Expresses Heartfelt Thanks to Katie Couric for Support After Husband’s Passing

    Sate your hunger at DBA’s Taste of Downtown – Bakersfield.com

    Indulge Your Cravings at DBA’s Taste of Downtown!

    Caesars Entertainment (CZR): Assessing Valuation After Times Square Casino Setback and Mounting Investor Concerns – simplywall.st

    Caesars Entertainment Faces Times Square Casino Hurdles as Investor Concerns Mount

    Why Hilaria Baldwin Has Found the ‘DWTS’ Process ‘Embarrassing’ At Times – WFXG

    Hilaria Baldwin Opens Up About the Embarrassing Moments on Her ‘DWTS’ Journey

    Harvest Fest 2025 – yadkinripple.com

    Celebrate the Bounty: Harvest Fest 2025 is Coming!

    Fox News Entertainment Newsletter: Kate Middleton stuns during Trump state visit, Brett James dead at 57 – Fox News

    Kate Middleton Stuns During Trump State Visit; Remembering Brett James at 57

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Autonomous Solutions shows off cutting-edge technology for the public – Cache Valley Daily

    Autonomous Solutions Unveils Cutting-Edge Technology for the Public

    Amazon to Pay $2.5 Billion in Prime Membership Settlement – The New York Times

    Amazon to Pay $2.5 Billion in Prime Membership Settlement – The New York Times

    What are we really gaining from technology? – Fast Company

    What Are We Really Gaining from Technology?

    TOMI Environmental Solutions, Inc. Expands SteraMist iHP Technology Services in Healthcare Sector with New Provider Partnership – Quiver Quantitative

    TOMI Environmental Solutions Accelerates SteraMist iHP Technology Expansion in Healthcare with New Provider Partnership

    Indiana County Technology Center’s Joint Operating Committee looks to the future as program plans began to take shape – Indiana Gazette Online

    Indiana County Technology Center’s Joint Operating Committee Charts an Exciting Path Forward as New Program Plans Take Shape

    Meta to expand Montgomery data hub, pushing total investment to $1.5 billion – Alabama Department of Commerce

    Meta to Supercharge Montgomery Data Hub with $1.5 Billion Investment

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

NCSC warns CNI operators over ‘living-off-the-land’ attacks

February 11, 2024
in Technology
NCSC warns CNI operators over ‘living-off-the-land’ attacks
Share on FacebookShare on Twitter

Malicious, state-backed actors may well be lurking in the UK’s most critical networks right now, and their operators may not even know until it is too late, warn the NCSC and its partners


Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 07 Feb 2024 20:47

The UK’s National Cyber Security Centre (NCSC), together with its Five Eyes allies from Australia, Canada, New Zealand and the United States, have issued an urgent warning to operators of critical national infrastructure (CNI), sharing new details of how state-backed threat actors are using living-off-the-land techniques to persist on their networks.

Living-off-the-land refers to the exploitation of existing, legitimate tools on users’ IT systems in order to blend in to naturally occurring traffic that would not ordinarily raise any eyebrows. By exploiting these tools or binaries – also known as LOLbins – malicious actors can slip past security defences and teams with relative ease and operate discretely in the service of their paymasters.

The NCSC said that even organisations with the most mature cyber security techniques could easily fail to spot a living-off-the-land attack, and assessed it is “likely” that such activity poses a clear threat to CNI in the UK. As such, it is urging all CNI operators – energy suppliers, water companies, telecoms operators, and so on – to follow a series of recommended actions to help detect compromises and mitigate vulnerabilities.

In particular, it warned, both Chinese and Russian hackers have been observed living-off-the-land on compromised CNI networks – one prominent exponent of the technique is the GRU-sponsored advanced persistent threat (APT) actor known as Sandworm, which uses LOLbins extensively to attack targets in Ukraine.

“It is vital that operators of UK critical infrastructure heed this warning about cyber attackers using sophisticated techniques to hide on victims’ systems,” said NCSC operations director Paul Chichester.

“Threat actors left to carry out their operations undetected present a persistent and potentially very serious threat to the provision of essential services. Organisations should apply the protections set out in the latest guidance to help hunt down and mitigate any malicious activity found on their networks.”

“In this new dangerous and volatile world where the frontline is increasingly online, we must protect and future proof our systems,” added deputy prime minister Oliver Dowden. “Earlier this week, I announced an independent review to look at cyber security as an enabler to build trust, resilience and unleash growth across the UK economy.

“By driving up the resilience of our critical infrastructure across the UK we will defend ourselves from cyber attackers that would do us harm,” he added.

Priority actions for defenders

While it is imperative for CNI operators to adopt a defence-in-depth approach to their cyber security posture as part of standard best practice – the newly-published guidance outlines a number of priority recommendations:

Security teams should implement logging and aggregate logs in an out-of-band, centralised location;
They should establish a baseline of user, network and application activity and implement automation to continuously review and compare activity logs;
They should reduce alert noise;
They should implement application allow-listing;
They should enhance network segmentation and monitoring;
They should implement authentication controls;
They should seek to leverage user and entity behaviour analytics (UEBA).

More detail on these and other recommendations have been published by the US authorities and are available to read on the Cybersecurity and Infrastructure Security Agency (CISA) website.

LogRhythm customer solutions engineer Gabrielle Hempel said: “Critical infrastructure systems are extremely complex and interconnected, which makes them not only difficult to secure against attacks, but requiring specialised knowledge to understand and mitigate any vulnerabilities they might have.

“Often, critical infrastructure organisations also have resource constraints, which makes it difficult to implement and maintain security measures both from a personnel and financial standpoint.”

The costs arising from attacks on CNI will likely be multi-stage, including the upfront cost of incident response, system recovery and replacement, and any regulatory fines and legal costs that may follow, said Hempel. However, following this there will also be intense supply chain disrupted cascading down through various systems that may ultimately drive up costs for consumers.

“The collaborative warning highlights the alarming fact that the same cyber threats are having an impact across the globe,” added Hempel.

“There are numerous opportunities for strengthening international collaboration, including the real-time sharing of information and intelligence, joint research initiatives, and development of unified standards and frameworks for cyber security.

“However, it is also important to stress the importance of developing public-private partnerships not only nationally, but on a global scale in order to truly address vulnerabilities and attacks on critical infrastructure across the board. Because these attacks simultaneously span the globe geographically and organisations from public to private, they need to be addressed across these planes as well,” she said.

Volt Typhoon blows in

At the same time, the Five Eyes agencies also published a separate advisory sharing details of the Chinese APT known as Volt Typhoon, which first came to attention via Microsoft in May 2023.

Volt Typhoon is another active exploiter of LOLbins, which it has used extensively to compromise CNI systems in the US in particular. Just last week, the US authorities disrupted one Volt Typhoon operation that saw the operation hijack hundreds of vulnerable Cisco and Netgear routers to create a botnet that was used to obfuscate follow-on attacks on CNI operators.

CISA said it had confirmed Volt Typhoon has compromised the networks of US CNI operators in the comms, energy, transport and water sectors.

The agency warned that the APT’s targeting and behaviour pattern is not consistent with traditional Chinese cyber espionage, which tends to focus on intellectual property (IP) theft.

As such, it assesses with a high degree of confidence that Volt Typhoon is pre-positioning itself to enable lateral movements to operational technology (OT) assets that they can disrupt should geopolitical tensions – notably over Taiwan – escalate into conflict.

“The PRC [People’s Republic of China] cyber threat is not theoretical: leveraging information from our government and industry partners, CISA teams have found and eradicated Volt Typhoon intrusions into critical infrastructure across multiple sectors. And what we’ve found to date is likely the tip of the iceberg,” said CISA director Jen Easterly.

“Today’s joint advisory and guide are the result of effective, persistent operational collaboration with our industry, federal, and international partners and reflect our continued commitment to providing timely, actionable guidance to all of our stakeholders. We are at a critical juncture for our national security. We strongly encourage all critical infrastructure organisations to review and implement the actions in these advisories and report any suspected Volt Typhoon or living off the land activity to CISA or FBI.”

Read more on Hackers and cybercrime prevention


CISA: Volt Typhoon had access to some U.S. targets for 5 years

ArielleWaldman

By: Arielle Waldman


Critical infrastructure hacks raise alarms on Chinese threats

AlexanderCulafi

By: Alexander Culafi


US government disrupts Chinese botnet containing hundreds of end-of-life Cisco and Netgear routers

CarolineDonnelly

By: Caroline Donnelly


Rogue state-aligned actors are most critical cyber threat to UK

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366569240/NCSC-warns-CNI-operators-over-living-off-the-land-attacks

Tags: operatorstechnologywarns
Previous Post

How Iranian cyber ops pivoted to target Israel after 7 October attacks

Next Post

The Post Office Scandal: Drawing parallels between Horizon and the UK cloud market

Ecological burns slated for Corvallis area this weekend – NPR for Oregonians

Ecological Burns Set for This Weekend to Revitalize Corvallis Habitats

September 26, 2025
Beijing International Week for Science Literacy Wraps Up with Focus on AI-Driven Communication – The Korea Herald

Beijing International Week for Science Literacy Wraps Up Highlighting AI-Powered Communication Innovations

September 26, 2025
Science & Society: September 2025 – Yale School of Public Health

Science & Society: September 2025 – Yale School of Public Health

September 26, 2025
New Mexico Prickly Pear Festival expands to two-day event – Albuquerque Journal

New Mexico Prickly Pear Festival Grows into Exciting Two-Day Celebration

September 26, 2025
Autonomous Solutions shows off cutting-edge technology for the public – Cache Valley Daily

Autonomous Solutions Unveils Cutting-Edge Technology for the Public

September 26, 2025
Iowa Sports Betting: Best IA Sportsbooks, Apps, and Promos – FOX Sports

Iowa Sports Betting: Best IA Sportsbooks, Apps, and Promos – FOX Sports

September 26, 2025
Botswana Minister outlines ‘Diamonds, Democracy, and Development’ vision at World Leaders Forum – Columbia Daily Spectator

Botswana Minister Unveils Inspiring Vision of Diamonds, Democracy, and Development at World Leaders Forum

September 26, 2025
US economy grows at fastest pace in nearly two years as spending roars back – New York Post

US Economy Surges at Fastest Rate in Nearly Two Years as Consumer Spending Booms

September 26, 2025
Best 9: Top events for the week ahead in Santa Cruz County arts & entertainment, Sept. 25-Oct. 2 – Lookout Santa Cruz

Discover the Top 9 Can’t-Miss Arts & Entertainment Events in Santa Cruz County This Week (Sept. 25-Oct. 2)

September 26, 2025
Their son was ‘too unstable to function outside of hospital.’ Insurance denied his mental health treatment anyway. – NBC News

Denied Mental Health Care: When a Son Too Unstable to Leave the Hospital Was Left Without Support

September 26, 2025

Categories

Archives

September 2025
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« Aug    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (838)
  • Economy (858)
  • Entertainment (21,733)
  • General (17,254)
  • Health (9,901)
  • Lifestyle (871)
  • News (22,149)
  • People (860)
  • Politics (868)
  • Science (16,068)
  • Sports (21,358)
  • Technology (15,841)
  • World (841)

Recent News

Ecological burns slated for Corvallis area this weekend – NPR for Oregonians

Ecological Burns Set for This Weekend to Revitalize Corvallis Habitats

September 26, 2025
Beijing International Week for Science Literacy Wraps Up with Focus on AI-Driven Communication – The Korea Herald

Beijing International Week for Science Literacy Wraps Up Highlighting AI-Powered Communication Innovations

September 26, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version