Another day, another attack

July 2017 News & Events

One of the sad things about South Africa is that we have all become hardened to crime, especially violent crime. For whatever reason, the media does not report most of the crime that happens, unless it happens to a famous person or if it has some titillation value – or unless it is so horrendous it’s guaranteed to attract readers.

It seems the same is happening globally when it comes to cybercrime. Only weeks ago we had the WannaCry attack that affected companies globally, locking people and companies out of their computers, including the British NHS (National Health Service). The Microsoft patch that would have prevented the attack had already been released, but many companies had not updated their systems.

As I write this column, the Petya attack has just happened – and it is not as easy to stop as WannaCry. Again, unpatched systems are in the firing line. Petya not only encrypts files on your hard drive, but forces a Windows reboot and in the process infects the Master Boot Record (MBR) to prevent the system from loading normally, and then encrypts the Master File Table (MFT). (A more in-depth description can be found at https://securelist.com/petya-the-two-in-one-trojan/74609/.)

To use a technical term, once infected, unless you get the decryption key you’re screwed. In this case GNLcyber.com reports that those who paid the ransom were not given the ability to unlock their systems. So is it a financial attack or some form of cyber terrorism? Another report says that the email addresses linked to the Bitcoin account users are directed to send the ransom to, is disconnected, so the criminals won’t be able to assist you even if you do pay and even if they had planned to.

I understand that Microsoft’s endless bug fixes are a pain, but they are necessary. Last month’s patch (from May) would protect from this malware (they say also blocking the Microsoft PsExec tool helps). But right now, we have governments and supermarkets, the giant Maersk shipping company, and many more big organisations around the world sitting helpless. In certain countries a government shutdown would have a positive impact on society, but in most of the world this would be a catastrophe.

The vulnerability that allows for this attack was part of the alleged dump by Shadow Brokers of the software stolen from the NSA, which was keeping it secret for its own shady activities.

Of course, in the midst of all this we still have governments who are actively trying to break secure computing by insisting they be allowed to have back doors into everything. Because they won’t tell anyone how to use it, just like the NSA didn’t tell anyone how to use the SMB vulnerability (that WannaCry and Petya use).

We know politicians have no idea what they are doing, apart from getting rich, but their booty is also at stake when there is no way to secure your bank or your financial transactions – even the offshore ones. So how about listening to the people out there who have an inkling of what is happening? There may be a cyber security skills shortage, but there are many people who would be happy to assist in national cyber protection projects – even right here in SA.

So ask yourself, who in your company is opening unknown Zip files that have appeared in their inbox?

Andrew Seldon

Editor



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
From the editor's desk: Interesting times
Technews Publishing News & Events
We certainly live in interesting times. From delaying the budget speech because the ANC doesn’t see any reason why VAT shouldn’t be increased by 2%, to crime fighters being set up and prosecuted in ...

Read more...
World-first safe K9 training for drug detection
Technews Publishing SMART Security Solutions Editor's Choice News & Events Security Services & Risk Management Government and Parastatal (Industry)
The Braveheart Bio-Dog Academy recently announced the results of its scientific research into training dogs to accurately detect drugs and explosives without harming either the dogs or their handlers.

Read more...
Bosch sells product business to Triton
Bosch Building Technologies News & Events Products & Solutions Facilities & Building Management
Bosch is selling its Building Technologies division’s product business for security and communications technology to the European investment firm Triton. The division is set to focus on systems integration business in the future.

Read more...
Nice launches DC Blue Astute garage door motor
Nice Group South Africa Technews Publishing News & Events Access Control & Identity Management Perimeter Security, Alarms & Intruder Detection
Nice Systems SA has launched the Nice DC Blue Astute, a garage door motor for the South African market featuring a pre-installed lithium-ion battery instead of traditional lead-acid batteries.

Read more...
The human element remains the cornerstone of success
News & Events
Gallagher Security, has unveiled its Security Industry Trends Report 2025, offering insights into the rapid evolution of security systems and the broader role they play in business operations worldwide.

Read more...
New firearms training modules from ITA
News & Events Security Services & Risk Management
The International Firearm Training Academy has launched two new firearms training modules to support career development in the firearms industry: the Maintenance Fitter and the Firearms Custodian modules.

Read more...
The IoT trends shaping a smarter, more connected future
IoT & Automation News & Events
The Internet of Things (IoT) is revolutionising sectors across Africa. In 2025, IoT is expected to continue driving digital innovation, enhancing operational efficiencies, and enabling the creation of smarter, more sustainable ecosystems.

Read more...
New AI advisor for robot selection
News & Events Industrial (Industry) AI & Data Analytics
Igus’ new AI chatbot has been added to its online platform to enable companies with little previous experience and technological expertise to quickly and reliably put together Low-Cost Automation (LCA) solutions to become more competitive.

Read more...
On the ball or unaware
Technews Publishing Information Security Security Services & Risk Management
Whether an organisation is operating at a high level of information security maturity or has dangerous vulnerabilities that could put an entire business at risk, advanced, strategic penetration testing can uncover its true state of IT security.

Read more...