News: 1710929708

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Five Eyes tell critical infra orgs: take these actions now to protect against China's Volt Typhoon

(2024/03/20)


The Feds and friends yesterday issued yet another warning about China's Volt Typhoon gang, this time urging critical infrastructure owners and operators to protect their facilities against destructive cyber attacks that may be brewing.

The Tuesday alert – issued by the US Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), FBI and eight other [1]US and international partners – comes a little more than a month after the same groups from the same Five Eyes nations sounded the alarm on Volt Typhoon compromising "multiple" critical infrastructure orgs' IT networks in America.

The previous advisory, published on February 7, also warned that the Beijing-backed crew was readying "disruptive or destructive cyber attacks" against these same targets.

[2]

Today's advisory is more of a condensed version of the February one. While it doesn't include any new details about specific Chinese threats or compromised networks, it's more "focused on providing guidance to non-technical senior business leaders," a CISA spokesperson told The Register .

[3]

[4]

"As a first step, organizations should use intelligence-informed prioritization tools, such as the [5]Cybersecurity Performance Goals (CPGs) or derived guidance from an SRMA," [6]the alert [PDF] advises.

For those not fluent in CISA acronyms, an SRMA is a [7]Sector Risk Management Agency and each of the 16 US critical infrastructure sectors has its own.

[8]China's Volt Typhoon spies broke into emergency network of 'large' US city

[9]US says China's Volt Typhoon is readying destructive cyberattacks

[10]Volt Typhoon not the only Chinese crew lurking in US energy, critical networks

[11]Forget TikTok – Chinese spies want to steal IP by backdooring digital locks

The alert also encourages cyber security best practices – such as turning on logging for all applications and systems, and storing these logs in a central system. This can help security teams detect "living off the land" techniques, which involve using legitimate admin tools and software, rather than installing custom malware, to blend in and avoid being detected by security tools.

Pretty much [12]every Volt Typhoon warning we've seen, from both government agencies and private-sector threat hunters, has observed that this China state-backed cybercrime gang is especially adept at living off the land.

[13]

Organizations should also develop an incident response plan and conduct regular tabletop exercises so that everyone knows their role and what to do in case of an attack.

Today's alert also recommends securing the supply chain and ensuring vendor risk management processes are in place.

This includes "ensuring that suppliers and partners adhere to strict security standards and any foreign ownership, control, or influence (FOCI) are clearly identified and managed, including consideration of, for example, the US Department of Commerce Entities List and Unverified List." ®

Get our [14]Tech Resources



[1] https://www.theregister.com/2024/02/07/us_chinas_volt_typhoon_attacks/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfrBxFv6RYB9IAK2HkZaTQAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfrBxFv6RYB9IAK2HkZaTQAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfrBxFv6RYB9IAK2HkZaTQAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.cisa.gov/cross-sector-cybersecurity-performance-goals

[6] https://www.cisa.gov/sites/default/files/2024-03/Fact-Sheet-PRC-State-Sponsored-Cyber-Activity-Actions-for-Critical-Infrastructure-Leaders-508c.pdf

[7] https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/sector-risk-management-agencies

[8] https://www.theregister.com/2024/02/14/volt_typhoon_emergency_network/

[9] https://www.theregister.com/2024/02/07/us_chinas_volt_typhoon_attacks/

[10] https://www.theregister.com/2024/02/07/its_not_just_volt_typhoon/

[11] https://www.theregister.com/2024/03/14/chinese_espionage_safe_locks/

[12] https://www.theregister.com/2024/02/14/volt_typhoon_emergency_network/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfrBxFv6RYB9IAK2HkZaTQAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Dear Mister Language Person: I am curious about the expression, "Part of
this complete breakfast". The way it comes up is, my 5-year-old will be
watching TV cartoon shows in the morning, and they'll show a commercial for
a children's compressed breakfast compound such as "Froot Loops" or "Lucky
Charms", and they always show it sitting on a table next to some actual food
such as eggs, and the announcer always says: "Part of this complete
breakfast". Don't that really mean, "Adjacent to this complete breakfast",
or "On the same table as this complete breakfast"? And couldn't they make
essentially the same claim if, instead of Froot Loops, they put a can of
shaving cream there, or a dead bat?

Answer: Yes.
-- Dave Barry, "Tips for Writer's"