Tag: Marty Edwards

Comment from Tenable on the Cyberattack on Colonial Pipeline

“Cyberattacks are a real and present danger to critical infrastructure around the world and, by extension, every single consumer. If reports are accurate, the Colonial Pipeline incident has all of the markings of a possible ransomware attack that began in the IT environment and, out of precaution, forced the operator to shut down operations.

“Ransomware has been a favoured attack vector of cybercriminals because of its effectiveness and return-on-investment. That’s precisely why bad actors have recently set their sights on critical infrastructure. Shutting down operational technology (OT) environments can cost hundreds of millions of dollars which forces providers to outweigh the costs.

“We should not underestimate these groups. Many of them now have help desks, technical support, payroll processing and subcontractors. They are essentially full-fledged criminal corporations operating in the digital world. While it’s unknown how this attack played out, it’s yet another reminder of the increasing threats to critical infrastructure we all rely on.” — Marty Edwards, VP of OT Security at Tenable and longest-serving director of ICS-CERT.

Comment from Tenable on BadAlloc flaws

Microsoft disclosed more than 25 critical memory allocation vulnerabilities in OT and IoT devices that could enable an attacker to bypass security controls and execute malicious code or cause a system to crash in industrial, medical, and enterprise networks.

“Vulnerabilities such as the BadAlloc flaws underscore the need for critical infrastructure and manufacturing organisations to have continuous visibility into the devices used in their production environments. It is no longer sufficient to evaluate your risk ‘with a clipboard’ on a periodic basis. When the CISO comes to ask if your organisation is exposed to these latest vulnerabilities, you should have the answer immediately. Not being able to answer that question gives attackers the upper hand.

Since these vulnerabilities are in the Real Time Operating Systems that are the foundation of many OT and IoT devices, the end user may not actually know that they rely on these products. Hopefully, the OT OEM vendor community will evaluate these vulnerabilities and determine if they are a risk in their products. We always advise owners of OT to work with their vendors on how to appropriately mitigate vulnerabilities in critical devices. This case is no different.” — Marty Edwards, VP of OT security, Tenable