CISA warns about Internet-connected UPS devices attacks
By MYBRANDBOOK
The Cybersecurity and Infrastructure Security Agency (CISA) in a joint advisory with the Department of Energy, warned U.S. organizations to secure Internet-connected UPS devices from ongoing attacks.
UPS devices are connected to the Internet to allow admins to perform various remote tasks such as power monitoring and routine maintenance, exposing them to attacks. They are also regularly used as emergency power backup solutions in mission-critical environments, including data centers, industrial facilities, server rooms, and hospitals.
The federal agencies said, “Organizations can mitigate attacks against their UPS devices, which provide emergency power in a variety of applications when normal power sources are lost, by removing management interfaces from the internet.”
The agency recommended mitigation measures including finding all UPSs and other emergency power systems on orgs' networks and ensuring they're not reachable over the Internet. The recommendations also include checking that the UPSs are not using factory default credentials to attackers' attempts to use them and take over the targeted devices.
Threat actors can also use critical security vulnerabilities to enable remote takeovers of uninterruptible power supply (UPS) devices and allow them to burn them out or disable power remotely.
Admins are advised to put the devices behind a virtual private network (VPN), enable multi factor authentication (MFA), and strong passwords or passphrases to hinder brute-forcing attempts.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
GLOBUS INFOCOM LTD.
HIMACHAL FUTURISTIC COMMUNICATIONS LTD.
SAMRIDDHI AUTOMATIONS PVT. LTD.
HAVELLS INDIA LTD.
Icons Of India : Dilip Asbe
At present, Dilip Asbe is heading National Payments Corporation of Ind...
Icons Of India : PRATIVA MOHAPATRA
Prativa is a transformational leader with an incredible breadth of exp...
ICONS OF INDIA : RAJIV MEMANI
As Chair of the EY Global Emerging Markets Committee, Rajiv connects e...
PFC - Power Finance Corporation Ltd
PFC is a leading financial institution in India specializing in power ...
RailTel Corporation of India Limited
RailTel is a leading telecommunications infrastructure provider in Ind...
IOCL - Indian Oil Corporation Ltd.
IOCL is India’s largest oil refining and marketing company ...
Indian Tech Talent Excelling The Tech World - Anirudh Devgan , President, Cadence Design
Anirudh Devgan, the Global President and CEO of Cadence Design Systems...
Indian Tech Talent Excelling The Tech World - NIKESH ARORA, Chairman CEO - Palo Alto Networks
Nikesh Arora, the Chairman and CEO of Palo Alto Networks, is steering ...
Indian Tech Talent Excelling The Tech World - JAYASHREE ULLAL, President and CEO - Arista Network
Jayshree V. Ullal is a British-American billionaire businesswoman, ser...