CISA warns about Internet-connected UPS devices attacks
By MYBRANDBOOK
The Cybersecurity and Infrastructure Security Agency (CISA) in a joint advisory with the Department of Energy, warned U.S. organizations to secure Internet-connected UPS devices from ongoing attacks.
UPS devices are connected to the Internet to allow admins to perform various remote tasks such as power monitoring and routine maintenance, exposing them to attacks. They are also regularly used as emergency power backup solutions in mission-critical environments, including data centers, industrial facilities, server rooms, and hospitals.
The federal agencies said, “Organizations can mitigate attacks against their UPS devices, which provide emergency power in a variety of applications when normal power sources are lost, by removing management interfaces from the internet.”
The agency recommended mitigation measures including finding all UPSs and other emergency power systems on orgs' networks and ensuring they're not reachable over the Internet. The recommendations also include checking that the UPSs are not using factory default credentials to attackers' attempts to use them and take over the targeted devices.
Threat actors can also use critical security vulnerabilities to enable remote takeovers of uninterruptible power supply (UPS) devices and allow them to burn them out or disable power remotely.
Admins are advised to put the devices behind a virtual private network (VPN), enable multi factor authentication (MFA), and strong passwords or passphrases to hinder brute-forcing attempts.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
SECUREYE SERVICES PVT. LTD.
DIGISOL SYSTEMS LTD.
DATA SAFEGUARD INDIA PRIVATE LIMITED
RELIANCE JIO INFOCOMM LTD.
ICONS OF INDIA : VIJAY SHEKHAR SHARMA
Vijay Shekhar Sharma is an Indian technology entrepreneur and multimil...
Icons Of India : MADHABI PURI BUCH
Madhabi Puri Buch is the first-female chairperson of India’s markets...
Icons Of India : Dilip Asbe
At present, Dilip Asbe is heading National Payments Corporation of Ind...
ITI - ITI Limited
ITI Limited is a leading provider of telecommunications equipment, sol...
IOCL - Indian Oil Corporation Ltd.
IOCL is India’s largest oil refining and marketing company ...
HPCL - Hindustan Petroleum Corporation Ltd.
HPCL is an integrated oil and gas company involved in refining, market...
Indian Tech Talent Excelling The Tech World - ARVIND KRISHNA, CEO – IBM
Arvind Krishna, an Indian-American business executive, serves as the C...
Indian Tech Talent Excelling The Tech World - Soni Jiandani, Co-Founder- Pensando Systems
Soni Jiandani, Co-Founder of Pensando Systems, is a tech visionary ren...
Indian Tech Talent Excelling The Tech World - George Kurian, CEO, Netapp
George Kurian, the CEO of global data storage and management services ...