Upgrade & Secure Your Future with DevOps, SRE, DevSecOps, MLOps!

We spend hours on Instagram and YouTube and waste money on coffee and fast food, but won’t spend 30 minutes a day learning skills to boost our careers.
Master in DevOps, SRE, DevSecOps & MLOps!

Learn from Guru Rajesh Kumar and double your salary in just one year.

Get Started Now!

Millions of IoT devices at hacking risk globally: Report

Source: telecom.economictimes.indiatimes.com

San Francisco: Security researchers have discovered serious vulnerabilities that could expose millions of Internet of Things (IoT) devices worldwide to hackers.

The list of affected vendors includes HP, Schneider Electric, Intel, Rockwell Automation, Caterpillar and Baxter.

According to JSOF, a boutique cybersecurity organization, the vulnerabilities dubbed ‘Ripple20’ relate to the Treck TCP/IP stack, a TCP/IP protocol suite designed for embedded systems.

The vulnerability affects hundreds of millions of IoT devices that could potentially allow nefarious actors, including nation-states, to remote take-over of these devices, the organization said in a statement late Tuesday.

JSOF said it discovered the Treck vulnerability while doing a security analysis of a single device last fall and found that its TCP-IP stack contained hackable vulnerabilities.

The firm soon realised that the code wasn’t written by the device’s manufacturer, but rather came from Treck; that meant the bugs weren’t in a single device but everywhere underscoring how widely IoT flaws can propagate

The risks inherent in this situation are high.

“Data could be stolen off of a printer, an infusion pump behaviour changed or industrial control devices could be made to malfunction.

“An attacker could hide malicious code within embedded devices for years. One of the vulnerabilities could enable entry from outside into the network boundaries; and this is only a small taste of the potential risks,” the researchers explained.

JSOF said it has contacted every vendor of affected devices, and many of the companies have released software updates.

The organisation has been working with several organizations to coordinate the disclosure of the flaws.

Related Posts

Investing in the Human Element of IIoT

Source: mbtmag.com A recent report by Vodafone Business found that COVID-19 has ignited a surge in Internet of Things (IoT) adoption, with 79 percent of U.S. businesses saying they’ve Read More

Read More

When ‘code rot’ becomes a matter of life or death, especially in the Internet of Things

Source: zdnet.com The possibilities opened up to us by the rise of the Internet of Things (IoT) is a beautiful thing. However, not enough attention is being Read More

Read More

The Good and Not So Good of the IoT Cybersecurity Improvement Act of 2020

Source: securityboulevard.com In September, the House of Representatives passed a bill requiring that all internet of things (IoT) devices purchased by the government meet minimum security requirements. Read More

Read More

Delivering the Revolution: How the Trucking Industry Utilizes the IoT and AI

Source: iotbusinessnews.com The trucking industry, and the logistics that keep it running, have become fundamental to the success of supply chains, both nationally and internationally. Without those Read More

Read More

How the Internet of Robotic Things is helping supply chains to evolve in times of uncertainty

Source: In recent years, the Internet of Things has been hailed as a game changer for businesses. The Internet of Robotic Things (IoRT) is helping businesses to Read More

Read More

Internet of Things is transforming the mobility space

Source: talkiot.co.za South Africa’s economy is easing back towards levels of activity last seen before the Covid-19 lockdown. Logistics fleets are returning to full capacity, and private Read More

Read More
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x