News: 1665120493

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Top of the Pops: US authorities list the 20 hottest vulns that China's hackers love to hit

(2022/10/07)


Three US national security agencies - CISA, the FBI and the NSA - on Thursday issued a joint advisory naming the 20 infosec exploited by state-sponsored Chinese threat actors since 2020.

The list reads like a hit parade of recent security SNAFUs, with remote code executions like [1]Log4j and [2]Atlassian topping the charts, as well as a [3]handful of Microsoft bugs.

The Cybersecurity and Infrastructure Security Agency, National Security Agency (NSA) and Federal Bureau of Investigation (FBI) [4]stated they collectively consider the People’s Republic of China (PRC) state-sponsored cyber activities as “being one of the largest and most dynamic threats to U.S. government and civilian networks.”

[5]

“NSA, CISA, and FBI assess PRC state-sponsored cyber actors have actively targeted U.S. and allied networks as well as software and hardware companies to steal intellectual property and develop access into sensitive networks,” added the agencies.

[6]

[7]

The threat actors use VPNs to obfuscate their locations and activities and make their way in via web-facing applications. Many of the vulnerabilities allow for unauthorized access to sensitive networks, and once in, they can move into connected networks.

CISA's recommended mitigations seem obvious, but are worth repeating: update and patch systems, use phishing-resistant multi-factor authentication and unique passwords, block unused protocols, upgrade or replace kit on schedule, trust no one, and monitor logs.

[8]USA adds two more Chinese carriers to 'probably a national security threat' list

[9]Uncle Sam orders federal agencies to step up scans for govt IT security holes

[10]As Cybersecurity Week begins, Beijing claims US attacked Uni doing military research

[11]Microsoft fixes four zero-day flaws in Exchange Server exploited by China's 'Hafnium' spies to steal victims' data

While CISA, the FBI and NSA were creating their top 20 vulns list, the Department of Defense (DoD) was making another list.

The DoD list is of Chinese companies operating either directly or indirectly within the US during 2021, and which may appear to be civilian operations but are tied to the Chinese military.

[12]

“The Department is determined to highlight and counter the PRC Military-Civil Fusion strategy, which supports the modernization goals of the People’s Liberation Army (PLA) by ensuring its access to advanced technologies and expertise are acquired and developed by PRC companies, universities, and research programs that appear to be civilian entities,” [13]said the DoD on Wednesday.

The list already included many names that are also deemed separately as national security threats like [14]China Unicom , [15]China Mobile and China Telecom. Huawei, Hikvision, SMIC also unsurprisingly had spots on the initial version of the list released on June 3, 2021.

The 13 additions for FY 2021 include drone-maker [16]DJI; CCTV manufacturer [17]Dahua (already listed as national security threat, and; Cloudwalk Technology - a software company accused of developing facial recognition software that can be weaponized against ethnic minorities.

[18]

Cloudwalk and DJI are already on another list that bans any US financial support on grounds they are active participants in the repression and surveillance of China’s Uyghur population. ®

Get our [19]Tech Resources



[1] https://www.theregister.com/2022/07/14/dhs_warns_expect_log4j_risks/

[2] https://www.theregister.com/2022/10/04/atlassian_microsoft_cisa_flaws/

[3] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/

[4] https://www.cisa.gov/uscert/ncas/alerts/aa22-279a

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yz-4urjc1A5jEAun9LyiAwAAAMM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yz-4urjc1A5jEAun9LyiAwAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yz-4urjc1A5jEAun9LyiAwAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/09/21/fcc_puts_pacific_network_and/

[9] https://www.theregister.com/2022/10/04/cisa_software_vulnerability_directive/

[10] https://www.theregister.com/2022/09/07/china_accuses_usa_nsa_cyberattack/

[11] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yz-4urjc1A5jEAun9LyiAwAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.defense.gov/News/Releases/Release/Article/3180636/dod-releases-list-of-peoples-republic-of-china-prc-military-companies-in-accord/utm_source/substack/utm_medium/dod-releases-list-of-peoples-republic-of-china-prc-military-companies-in-accord/

[14] https://www.theregister.com/2022/09/21/fcc_puts_pacific_network_and/

[15] https://www.theregister.com/2022/03/28/fcc_kaspersky_china_telecom_china_mobile_national_security/

[16] https://www.theregister.com/2022/08/17/russia_weaponizes_chinese_drones_robots/

[17] https://www.theregister.com/2022/07/05/uk_ban_hikvision_dahua/

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yz-4urjc1A5jEAun9LyiAwAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[19] https://whitepapers.theregister.com/



On one side, cybercrooks, on the other one, bean counters. And IT in between.

Potemkine!

CISA's recommended mitigations seem obvious, but are worth repeating: update and patch systems, use phishing-resistant multi-factor authentication and unique passwords, block unused protocols, upgrade or replace kit on schedule, trust no one, and monitor logs

It may be obvious, but how many companies allocate the adequate resources to IT teams to do these jobs? It takes a lot of time, a lot of means to do this.

== Bring us Dabbsy back! ==

Prevalent beliefs that knowledge can be tapped from previous incarnations or
from a "universal mind" (the repository of all past wisdom and creativity)
not only are implausible but also unfairly demean the stunning achievements
of individual human brains.
-- Barry L. Beyerstein, "The Brain and Consciousness: Implications for
Psi Phenomena", The Skeptical Inquirer, Vol. XII No. 2, ppg. 163-171