CISA warns about Internet-connected UPS devices attacks
By MYBRANDBOOK
The Cybersecurity and Infrastructure Security Agency (CISA) in a joint advisory with the Department of Energy, warned U.S. organizations to secure Internet-connected UPS devices from ongoing attacks.
UPS devices are connected to the Internet to allow admins to perform various remote tasks such as power monitoring and routine maintenance, exposing them to attacks. They are also regularly used as emergency power backup solutions in mission-critical environments, including data centers, industrial facilities, server rooms, and hospitals.
The federal agencies said, “Organizations can mitigate attacks against their UPS devices, which provide emergency power in a variety of applications when normal power sources are lost, by removing management interfaces from the internet.”
The agency recommended mitigation measures including finding all UPSs and other emergency power systems on orgs' networks and ensuring they're not reachable over the Internet. The recommendations also include checking that the UPSs are not using factory default credentials to attackers' attempts to use them and take over the targeted devices.
Threat actors can also use critical security vulnerabilities to enable remote takeovers of uninterruptible power supply (UPS) devices and allow them to burn them out or disable power remotely.
Admins are advised to put the devices behind a virtual private network (VPN), enable multi factor authentication (MFA), and strong passwords or passphrases to hinder brute-forcing attempts.
Legal Battle Over IT Act Intensifies Amid Musk’s India Plans
The outcome of the legal dispute between X Corp and the Indian government c...
Wipro inks 10-year deal with Phoenix Group's ReAssure UK worth
The agreement, executed through Wipro and its 100% subsidiary,...
Centre announces that DPDP Rules nearing Finalisation by April
The government seeks to refine the rules for robust data protection, ensuri...
Home Ministry cracks down on PoS agents in digital arrest scam
Digital arrest scams are a growing cybercrime where victims are coerced or ...
ICONS OF INDIA : RAJESH NAMBIAR
Rajesh leads the company’s India associates and enhances relationshi...
Icons Of India : PRATIVA MOHAPATRA
Prativa is a transformational leader with an incredible breadth of exp...
ICONS OF INDIA : VINAY SINHA
Vinay Sinha is the Managing Director of Sales for the India Mega Regio...
BEL - Bharat Electronics Limited
BEL is an Indian Government-owned aerospace and defence electronics co...
C-DOT - Center of Development of Telematics
India’s premier research and development center focused on telecommu...
LIC - Life Insurance Corporation of India
LIC is the largest state-owned life insurance company in India...
Indian Tech Talent Excelling The Tech World - REVATHI ADVAITHI, CEO- Flex
Revathi Advaithi, the CEO of Flex, is a dynamic leader driving growth ...
Indian Tech Talent Excelling The Tech World - Soni Jiandani, Co-Founder- Pensando Systems
Soni Jiandani, Co-Founder of Pensando Systems, is a tech visionary ren...
Indian Tech Talent Excelling The Tech World - Thomas Kurian, CEO- Google Cloud
Thomas Kurian, the CEO of Google Cloud, has been instrumental in expan...