TOP-3 cybersecurity events of the week according to Jet CSIRT

The most significant news this week was the news of attacks on Belden and E-Land, as well as the discovery of an impressive list of IP addresses of vulnerable FortiGate SSL VPN gateways in the public domain. Read more about each event under the cut.







Cyber ​​attack targeting ICS supplier Belden



Belden reported a cyberattack in which attackers managed to steal information about its employees and partners. A press release about the incident has been posted on businesswire.com . The details of the attack were not disclosed, but the description suggests that the company fell victim to ransomware. Belden is the largest ICS equipment manufacturer in the United States, with over 9,000 employees.



E-Land trading company was attacked by ransomware



E-Land, a large South Korean retailer, was forced to suspend service of some stores due to a ransomware attack. The incident was confirmed by the company 's president, Chang-Hyun Seok. According to him, the company decided to turn off part of its IT systems to contain the spread of malware. None of the factions have yet claimed responsibility for the attack.



A list of almost 50 thousand IP vulnerable FortiGate SSL VPN gateways has been made public



Information security researcher @Bank_Security discovered on one of the sites a list of 49577 FortiGate IP VPN gateways vulnerable to CVE-2018-13379 (path traversal, which allows access to system files). In addition to addresses, the list contains credentials stolen from gateways. The vulnerability was disclosed more than a year ago, however, judging by the list, many vulnerable devices, including large financial and government organizations, are still operating on the network.



All Articles