The Protocol That’s Putting Enterprise IoT At Extreme Risk
Security Boulevard – A protocol little known by executives outside of the networking world may put the future safety of enterprise IoT at extreme risk if organizations don’t take action to secure their connections. New research out last week found that the way that many large organizations are using the Long Range Wide Area Networking (LoRaWAN) protocol is making them susceptible to hacking that could cause civic disruption and even put people at risk.
Ryuk Ransomware Takes Out Durham, North Carolina
Infosecurity Magazine – The North Carolina city of Durham has become the latest US municipality struck by ransomware after reports suggested the Ryuk variant forced key services offline. “Cities need to start investing more on cybersecurity in general, including education, threat assessment, monitoring, prevention, etc. in order to have well established plans for quick reaction and recovery from cyber-attacks,” commented Cesar Cerrudo, CTO of IOActive.
Ransomware Increasingly Targeting Small Governments
Dark Reading – To get back up and running quickly, and because it’s cheaper, city and county governments often pay the ransom, especially if insurance companies are footing the bill. The result: More ransomware. “Cybercriminals are turning their weapons and targeting local governments because they are easier and juicier targets.”
PPP Daemon flaw opens Linux distros, networking devices to takeover attacks
Helpnet Security – A vulnerability (CVE-2020-8597) in the Point-to-Point Protocol Daemon (pppd) software, which comes installed on many Linux-based and Unix-like operating systems and networking devices, can be exploited by unauthenticated attackers to achieve code execution on – and takeover of – a targeted system.
Critical PPP Daemon Flaw Opens Most Linux Systems to Remote Hackers
The Hacker News – The US-CERT today issued advisory warning users of a new dangerous 17-year-old remote code execution vulnerability affecting the PPP daemon (pppd) software that comes installed on almost all Linux based operating systems, as well as powers the firmware of many other networking devices. The affected pppd software is an implementation of Point-to-Point Protocol (PPP) that enables communication and data transfer between nodes, primarily used to establish internet links such as those over dial-up modems, DSL broadband connections, and Virtual Private Networks.