Tag Archive for: August

Technion Hackers Expose Dangerous Vulnerabilities in Siemens PLC Firmware | The Jewish Press – JewishPress.com | Hana Levi Julian | 14 Av 5782 – August 10, 2022


Photo Credit: Macedo Media / Pixabay

illustrative

A hacker group from the Technion in Haifa has successfully broken into Siemens’ Simatic S7 series open controller. Siemens is believed to have the highest security standards in the industry.

Researchers in the Henry and Marilyn Taub Faculty of Computer Science at the Technion – Israel Institute of Technology were set to present their decryption of Siemen’s programmable logic controller (PLC) firmware on Wednesday at the prestigious Black Hat Hacker Convention in Las Vegas.

The findings of the study were forwarded to the company.

The group succeeded in hacking the ET200 SP Open Controller, CPU 1515sp, of Siemens’ Simatic S7 series, which represents a new concept in controller planning among numerous vendors.

The concept is based on the integration of a standard operating system. In this case specifically, the Windows 10 operating system was integrated into the CPU 1515sp.

These controllers are used in a variety of civil and military applications, including transportation system, factories, power stations, smart buildings, traffic lights, and others. Their purpose is to provide an automated process control that delivers an optimal, fast response to changing environmental conditions.

Attacks against PLCs have posed a challenge for Siemens, which is considered a vendor that meets the highest of security standards in the industry.

The S7 PLC series is perceived as innovative and highly secure, largely thanks to the integration of built-in cryptographic mechanisms, and consequently, attacks against it pose a great challenge.

The Technion researchers attacked the CPU 1515sp and, for the first time, decrypted the firmware which is common to all PLCs in the series.

The successful attack enabled the researchers to study the software characteristics. They say the attack exposed possible vulnerabilities in this PLC, as well as in other controllers in the series, and intensifies the need for improved security of these devices. The researchers warned that because the PLC and other controllers in the series are deployed in critical systems such as power plants, water facilities, transportation system, etc.,…

Source…

Oppo to launch ColorOS 13 on August 18: Here’s what we know so far


With speculations suggesting Android 13 will be officially launched sometime in September this year, some manufacturers are already announcing their Android 13-based custom skins. We saw OnePlus announce OxygenOS 13 earlier this month, and now Oppo has announced that it will make ColorOS 13 official later this month.

The Chinese smartphone-maker announced they will launch Android 13-powered ColorOS 13 on 18 August this year. Oppo will be live streaming the ColorOS 13 launch event on YouTube and Twitter on 18 August.

However, Oppo hasn’t revealed which phones will be getting the Android 13 update. But a recent leak by 91Mobiles suggests it will be first available on the Oppo Reno 8 series.

While the company still hasn’t confirmed which features will make their way to ColorOS 13, it said a brand new design will help deliver a ‘concise, comfortable, and smooth Android experience’ and that it ‘integrates Android 13’s underlying safety and privacy features and provides customisations similar to Google’s Material You’.

Opoo also said the features developed will help deliver the best experience on devices with large screens, provide interconnectivity between multiple devices and help increase productivity.

Oppo ColorOS 13 beta program

In case you want to try your hands on the ColorOS 13 before everyone else, you can sign up for the beta program. However, keep in mind that the beta program is limited to 1,000 users at a time and only those living in Thailand, Vietnam, UAE, France, Malaysia, Indonesia and Australia are eligible.

Source…

Samsung Galaxy Z Flip 5G gets August 2022 Android security patch


Samsung once again became the first smartphone brand to roll out a new Android security patch as it released the August 2022 security patch for the Galaxy S20, S21, and S22 series recently. Now, it is the Samsung Galaxy Z Flip 5G that’s getting updated with the August 2022 patch.

Samsung Galaxy Z Flip 5G gets August 2022 Android security patch

The new firmware is rolling out with version F707BXXU6GVG5 for the Galaxy Z Flip 5G having model code SM-F707B. It’s currently seeding in Switzerland, but the rollout should expand to other markets soon.

If you live in Switzerland and haven’t received the update yet, you can check for it manually by heading to your Samsung Galaxy Z Flip 5G’s Settings > Software update menu.

Via

Source…

Hackers targeted US drinking water and wastewater facilities as recently as August, Homeland Security says


WASHINGTON – The nation’s top civilian cybersecurity agency issued a warning Thursday about ongoing cyber threats to the U.S. drinking water supply, saying malicious hackers are targeting government water and wastewater treatment systems.

Authorities said they wanted to highlight ongoing malicious cyber activity “by both known and unknown actors” targeting the technology and information systems that provide clean, drinkable water and treat the billions of gallons of wastewater created in the U.S. every year.

The alert, which disclosed three previously unreported ransomware attacks on water treatment facilities, was issued by the Department of Homeland Security’s Cybersecurity and Infrastructure Agency (CISA). It was the result of analytic efforts by DHS, the FBI, the Environmental Protection Agency and the National Security Agency.

One DHS cybersecurity official described it as the routine sharing of technical information between federal agencies and their industry partners “to help collectively reduce the risk to critical infrastructure in the United States.” Added a second Homeland Security official: “It’s not any indication of a new threat. We don’t want anyone to think that their drinking water supply is under attack.”

Both officials spoke on the condition of anonymity in order to elaborate on the agency’s public statements.

Despite their assurances, the advisory disclosed that in March 2019, a former employee at a Kansas-based water and waste water treatment facility unsuccessfully tried to threaten drinking water safety by logging in with his user credentials – which had not been revoked at the time of his resignation – to remotely access a facility computer.

In that case, a federal grand jury in Topeka, Kansas accused Wyatt Travnichek, 22, of tampering with the water treatment facilities for the sprawling, eight-county Post Rock Rural Water District.

The indictment, announced March 31, alleges that Travnichek’s job for the utility was to monitor the water plant remotely by logging into its computer system. Two months after he left his job with the water district in January 2019, it said, Travnichek logged in remotely with the intent of shutting shut down…

Source…