#1 Trending Cybersecurity News & Magazine
Wednesday, December 6, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Income Tax Department of India

    India’s Income Tax Department Data Breach: Threat Actor Sets Price for Access

    James Yoo

    The Man Behind the Arlington Explosion: Ex-Telecom Security Chief Suspected

    SPARRSO data breach

    Cyberattack on SPARRSO Raises Concerns Over Security in Bangladesh

    GTA 6 Map Leak

    The GTA 6 Map Leaked by Rockstar Employee’s Son: What’s Disclosed?

    TrickMo Banking Trojan

    TrickMo Banking Trojan Resurfaces with New Features, Targeting Android Devices this Time Around

    Vietnam Electricity data breach

    BlackCat Ransomware Strikes Ho Chi Minh City Power Corporation

    cybersecurity

    Emerging Trends and Challenges in Cybersecurity: Insights from Abul Kalam Azad

    Spyroid Rat Android RAT

    Unmasking Spyroid Rat: An In-Depth Look at the Menacing Android RAT

    MIRLE Group cyberattack

    MIRLE Group Targeted by Notorious LockBit Ransomware Group

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI Security Guidelines

    Rethinking AI For Cybersecurity: The UK & US Reveals New Guidelines For AI Security

    Cyber Insurance

    Cyber Insurance and Real-Time Threat Dashboard to Mend the Gaps in Near Future

    Pledge to Stop Ransom Payment

    Pledge to Stop Ransom Payment Awaits Consensus from all Members of the CRI

    Executive Order on Artificial Intelligence

    Biden Administration’s AI Directive: A Blueprint for Ethical Use and Enhanced Cybersecurity

    Cyber Resilience

    Towards Cyber Resilience: A Data-Centric Approach to Security

    CybleGrowCon

    Cyble Partner Network GrowCon 2023: Uniting Cybersecurity Leaders

    GRC, What is GRC

    What is GRC (Governance, Risk & Compliance): A Beginner’s Guide

    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    InsureMO

    InsureMO Partners with Cyble to Revolutionize Cyber Insurance with Real-Time Threat Intelligence

    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Income Tax Department of India

    India’s Income Tax Department Data Breach: Threat Actor Sets Price for Access

    James Yoo

    The Man Behind the Arlington Explosion: Ex-Telecom Security Chief Suspected

    SPARRSO data breach

    Cyberattack on SPARRSO Raises Concerns Over Security in Bangladesh

    GTA 6 Map Leak

    The GTA 6 Map Leaked by Rockstar Employee’s Son: What’s Disclosed?

    TrickMo Banking Trojan

    TrickMo Banking Trojan Resurfaces with New Features, Targeting Android Devices this Time Around

    Vietnam Electricity data breach

    BlackCat Ransomware Strikes Ho Chi Minh City Power Corporation

    cybersecurity

    Emerging Trends and Challenges in Cybersecurity: Insights from Abul Kalam Azad

    Spyroid Rat Android RAT

    Unmasking Spyroid Rat: An In-Depth Look at the Menacing Android RAT

    MIRLE Group cyberattack

    MIRLE Group Targeted by Notorious LockBit Ransomware Group

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI Security Guidelines

    Rethinking AI For Cybersecurity: The UK & US Reveals New Guidelines For AI Security

    Cyber Insurance

    Cyber Insurance and Real-Time Threat Dashboard to Mend the Gaps in Near Future

    Pledge to Stop Ransom Payment

    Pledge to Stop Ransom Payment Awaits Consensus from all Members of the CRI

    Executive Order on Artificial Intelligence

    Biden Administration’s AI Directive: A Blueprint for Ethical Use and Enhanced Cybersecurity

    Cyber Resilience

    Towards Cyber Resilience: A Data-Centric Approach to Security

    CybleGrowCon

    Cyble Partner Network GrowCon 2023: Uniting Cybersecurity Leaders

    GRC, What is GRC

    What is GRC (Governance, Risk & Compliance): A Beginner’s Guide

    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    InsureMO

    InsureMO Partners with Cyble to Revolutionize Cyber Insurance with Real-Time Threat Intelligence

    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Protect Clear Text Passwords From Exposure, Install Updates Warns CISA ICS Advisory

CISA released advisories for vulnerabilities in ICS that could allow hackers to see login credentials in plain text and run arbitrary codes remotely.

Vishwa Pandagle by Vishwa Pandagle
September 6, 2023
in Firewall Daily, Vulnerabilities
0
Vulnerabilities in ICS
602
SHARES
3.3k
VIEWS
Share on LinkedInShare on Twitter

The U.S. cyber defense agency recently issued two advisories regarding vulnerabilities affecting Industrial Control Systems (ICS).

CVE-2023-38433 was identified in a Fujitsu Limited product, while CVE-2023-39227 and CVE-2023-39227 were found in Softneta. Fortunately, these ICS vulnerabilities reported by CISA in their advisories were not exploited by threat actors.

You might also like

LockBit Claims Cyberattack on Metropolitan Area Planning Council, Sets December 8 Deadline

Cyber Toufan Team Strikes Again: Israeli Organizations Allegedly Hit by Cyberattacks

ALPHV/BlackCat Claims Cyberattack on TraCS Florida, Website Outage Raises Doubts

Products Impacted by the Vulnerabilities in ICS

The advisories by CISA elaborated on the three vulnerabilities found in the following vendor products –

  1. Real-time video transmission gear of the IP series of Fujitsu Limited.
  2. MedDream PACS 2.8.810 and prior sold by Softneta.

The vulnerability in Fujitsu Limited products impacted Real-time Video Transmission Gear “IP series” of IP-HE950E: firmware versions V01L001 to V01L053, IP-HE950D of firmware versions V01L001 to V01L053, IP-HE900E of firmware versions V01L001 to V01L010, and IP-HE900D of firmware versions V01L001 to V01L004 among others.

Vulnerabilities in ICS – Fujitsu Limited

CVE-2023-38433 in Fujitsu Limited equipment was assigned a base score of 7.5 by NIST, which maintains the National Vulnerability Database. The vulnerability could allow hackers the Use of Hard-Coded Credentials, noted the ICS advisory by CISA.

“Successful exploitation of this vulnerability could result in an attacker logging into the web interface using the obtained credentials,” CISA mentioned in the advisory.

Such vulnerabilities in ICS can be remotely exploited to reboot the products and terminate the video transmission.

Since these products that are manufactured in Japan, are used by customers worldwide in government and commercial facilities, the reason to update to the latest version is higher.

Fujitsu posted the links to mitigate the risks in the IP Series here –  https://www.fujitsu.com/global/products/computing/peripheral/video/download/.

Vulnerabilities in ICS – Softneta MedDream PACS

The vulnerability CVE-2023-40150 in Softneta MedDream PACS is remotely exploitable.

It was assigned a CVSS v3 base score of 9.8 according to the ICS vulnerability advisory by CISA. The Softneta product MedDream PACS is used in the healthcare and public health sector, worldwide.

To avoid falling prey to a cyber attack, Softneta provided updates to v7.2.9.820 were made available for users. They can patch their systems using – Fix-v230712.

The bug in Softneta products could allow hackers to skip authentication process to perform malicious tasks impacting the industrial control systems in the healthcare sector.

Another vulnerability in Softneta – CVE-2023-39227 could give access to login credentials. Addressing this safety hazard, the CISA advisory on ICS vulnerabilities wrote, “​The affected product stores usernames and passwords in plaintext.”

“The plaintext storage could be abused by attackers to leak legitimate user’s credentials,” the CISA cybersecurity advisory concluded.

Gaining access to one’s login credentials especially from the healthcare organizations and their clients can lead to catastrophic circumstances.

Hackers can leak patient data, and other critical information, make duplicate health records to get free treatments, insurance claims, create fraudulent ID cards etc.

Mitigation Techniques to Fortify the ICS Cybersecurity Infrastructure

Cyber attacks on Industrial Control Systems can pose a severe threat to data security and the life of personnel handling machinery that must not be remotely manipulated by threat actors.

CISA placed useful steps to be followed to prevent risk by any user or client of the aforementioned products.

  1. Control the exposure of the network so the control systems are not exposed to all Internet users and are accessed by credible and specific employees only.
  2. Install firewalls for control systems and keep them detached from business networks.
  3. While remotely accessing the industrial control systems, choose Virtual Private Networks (VPNs) that are updated.

Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: CISA Cybersecurity AdvisoryCISA ICS advisoryICS BugsICS securityIndustrial Control SystemsThe Cyber ExpressThe Cyber Express NewsVulnerabilities in ICS
Previous Post

Cactus Ransomware Group Hits 5 Global Corporations, Marfrig, Seymours Among Victims

Next Post

China-Based Threat Actor Targets South Korean Android Users with Spyware Campaign

Vishwa Pandagle

Vishwa Pandagle

Related Posts

MAPC Cyberattack
Firewall Daily

LockBit Claims Cyberattack on Metropolitan Area Planning Council, Sets December 8 Deadline

by Samiksha Jain
December 6, 2023
cyberattacks on Israeli organizations
Firewall Daily

Cyber Toufan Team Strikes Again: Israeli Organizations Allegedly Hit by Cyberattacks

by Ashish Khaitan
December 6, 2023
TraCS Florida cyberattack
Firewall Daily

ALPHV/BlackCat Claims Cyberattack on TraCS Florida, Website Outage Raises Doubts

by Samiksha Jain
December 6, 2023
Income Tax Department of India
Data Breach News

India’s Income Tax Department Data Breach: Threat Actor Sets Price for Access

by Samiksha Jain
December 5, 2023
James Yoo
Cybersecurity News

The Man Behind the Arlington Explosion: Ex-Telecom Security Chief Suspected

by Samiksha Jain
December 5, 2023
Next Post
Android Users

China-Based Threat Actor Targets South Korean Android Users with Spyware Campaign

Latest Issue is Out. Subscribe Now

Cybersecurity Magazine



Follow Us On Google News

Latest Cyber News

Income Tax Department of India
Data Breach News

India’s Income Tax Department Data Breach: Threat Actor Sets Price for Access

December 5, 2023
James Yoo
Cybersecurity News

The Man Behind the Arlington Explosion: Ex-Telecom Security Chief Suspected

December 5, 2023
SPARRSO data breach
Firewall Daily

Cyberattack on SPARRSO Raises Concerns Over Security in Bangladesh

December 5, 2023
GTA 6 Map Leak
Firewall Daily

The GTA 6 Map Leaked by Rockstar Employee’s Son: What’s Disclosed?

December 5, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance