Skip to content

The OT & IoT Cybersecurity Feed

News Post SCADAfence Main-1

Hey, I’m SCADAGirl.

I’m a cybersecurity superhero that ensures that OT & IoT networks are safe.

Here is my commentary on the latest headlines in OT & IoT security.

 

News Post SCADAfence Siemens

ICS Advisory (ICSA-20-224-04) Siemens SCALANCE, RUGGEDCOM 

SCADAgirlSCADAfence Research – Siemens SCALANCE and RUGGEDCOM switches, as well as security network segmentation devices are exposed to a Remote Code Execution vulnerability. A successful exploitation can significantly lower the security of the target organization’s network by allowing attackers to access OT networks that are supposed to be protected by those devices.

Additionally, Siemens Desigo CC Windows Application, which is designed for controlling and programming Building Management Systems (BMS) is vulnerable to a Remote Code Execution vulnerability. A successful exploitation may result in the attackers controlling or sabotaging the BMS system.

News Post SCADAfence 7

Bugs in HDL Automation Expose IoT Devices to Remote Hijacking

SCADAgirlSCADAfence Research  – New vulnerabilities were discovered in an automation system for smart homes and buildings that allowed taking over accounts belonging to other users and control associated devices. The vulnerabilities found in those devices might allow attackers to take control of the building’s air conditioning system, lightning and more. For more on BMS security, click here.

News Post SCADAfence6

Vulnerable Perimeter Devices: A Huge Attack Surface

SCADAgirlSCADAfence Research – JSOF, a local team of cybersecurity researchers, released the second whitepaper on their DNS client exploitation vulnerability (CVE-2020-11901) that got CVSS score of 9.1. This was the vulnerability that was demonstrated in their video. They show this vulnerability to be really severe but in my opinion it is less severe than they market it. The vulnerability is the DNS client of target devices. Because most of the affected devices don’t use DNS at all (i.e,PLCs / OT devices / Medical devices) generally use direct IP addresses to communicate – not DNS hostnames, thus it is not possible to attack them. Also, if some of them do send DNS queries, you have to be in some sort of MITM to see them and send them a response with an exploit.

The latest vulnerabilities in various gateway servers possess a threat to organizations who didn’t patch. Research shows the various gateways exposed to the internet – F5 Big-IP (1M devices), Citrix NetScalar Gateway (80K devices), Palo Alto Global Protect (60K devices), Microsoft Remote Desktop Gateway (40K devices), amongst others. For more on IoT security, click here.

News Post SCADAfence1

ICS Advisory (ICSA-20-212-02) Mitsubishi Electric Multiple Factory Automation Engineering Software Products

SCADAgirlSCADAfence Research – Numerous Mitsubishi Engineering Software Products are vulnerable to remote code execution and denial of service vulnerabilities – A total of 3 vulnerabilities were discovered. Among the software impacted are Mitsubishi’s PLC programming software GX Works2 and GX Works3. Also other network configuration software are impacted. Successful exploitation of this vulnerability may allow threat actors to take over engineering workstations. For more vulnerabilities that we found in Mitsubishi Electric products, click here.

News Post SCADAfence2

ICS Advisory (ICSA-20-210-02) Softing Industrial Automation OPC

SCADAgirlSCADAfence Research – A buffer overflow allowing Remote Code Execution influencing all Softing Industrial Automation OPC products (OPC servers for PLCs & networks) was discovered. OPC is a way of communication in OT networks, thus, successful exploitation may result in controlling the OPC servers. Attackers leveraging this can cause sabotage to industrial processes.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

Serving the socially distanced consumer: why retailers need to go to the edge

The recent global epidemic has changed the rules of the retail game – perhaps forever.

(Image credit: Image Credit: Zapp2Photo / Shutterstock)

Everyone agrees the Covid-19 pandemic has had an unprecedented impact on the retail industry. In the face of government-imposed lockdowns, non-essential stores had to close their doors and place workers on furlough. With the high street now re-open for business, retailers are having to adapt at speed to a plethora of new shopping realities. That includes flexing their estates to serve the socially distanced consumer in-store.

One thing is for sure. The recent global epidemic has changed the rules of the retail game – perhaps forever. Social distancing, likely to be part and parcel of everyone’s lives for the foreseeable future, inhibits many of the in-person interactions that traditionally characterized the in-store experience. But that is not the only challenge that retailers face.

Rebuilding customer trust and confidence now depends on stores doing everything in their power to keep everyone safe, including employees. Initiating practical measures, such as one-way systems, safety screens and floor markings to indicate safe distancing when people are queuing at payment or collection points is just the start.

Dealing with practicalities…

The brick-and-mortar in-store experience will need to evolve fast if retailers are to cater for fast-evolving consumer expectations about how they want to shop. Following months of being restricted to shopping primarily online, they have become accustomed to the immediacy and convenience of digital channels. As a consequence, consumers are unlikely to tolerate encountering long queues outside or inside stores – or disconnected experiences that cause delays and frustration.

Despite having been forced to embrace online shopping in recent months, there appears to be plenty of pent-up demand among consumers for bricks-and-mortar shopping and the product discovery experiences that are difficult or impossible to recreate online. However, those consumers that show up to shop will expect to encounter appropriate hygiene precautions when visiting stores.

Complying with government imposed restrictions and guidance that is designed to keep people safer means that retailers are becoming more dependent than ever on in-store technologies that make it easy to deliver more seamless and engaging shopping experiences. 

For example, with fear of infection now front of mind for customers, offering touch-free shopping options across the shop floor is becoming a must-have for satisfying the needs of those consumers that want to avoid the queues, complete transactions on their mobile device, and have their purchases shipped directly to home. For others, self-checkout options, smart tags, and ‘scan-to-learn more’ shelf labels that make it easy to get answers to questions without touching physical products will be a top priority. 

Lowering risk to shoppers means that virtual reality in-store technologies that enable customers to envision how products will look on them, and enjoy that all important experiential product discovery moment, are becoming essential for securing customer confidence – and creating the richer experiences that add up to competitive advantage.

Once considered a nice-to-have, retailers are now preparing to go all-in on technologies like smart mirrors that will allow customers to virtually ‘try on’ clothes, footwear, and cosmetics. Similarly, options like digital ‘look books’ and virtual assistants that give customers new ways to choose products or get recommendations are rapidly rising up the ‘must-have’ investment list of retailer priorities.

To enable all these digital capabilities, however, retailers will need an edge computing infrastructure that makes it easy to remotely deploy the new in-store technologies and applications that will prove transformative for the in-store shopping experience.


Bringing digital to life 

The recent public health crisis has served to accelerate consumer demand for truly seamless omnichannel in-store experiences. While many retailers were already making moves in this direction, and redesigning customer journeys to accommodate this trend, consumers in just about every demographic segment now expect to shop using any device, in any store location. But blending bricks-and-mortar stores with other digital channels is just one aspect of how retailers will need to engage with shoppers in new and meaningful ways. 

To deal with the disruption created by Covid-19, retailers will need to elevate how they leverage data for business. That means stealing a leaf from online retailers to capture the shopper data insights that will enable them to hyper-personalize customer engagement. 

For example, using connected edge devices, retailers can track a customer’s journey through a store and evaluate what products caught their attention. Alongside delivering personalized offers and adverts as customers browse shelves, retailers can also analyze all this data to enhance the efficiency of their store layouts and product displays for the specific customer population profile they serve. 

Utilizing connected edge devices, retailers will also be able to monitor in real-time the number of people entering and exiting the store, instituting measures to ensure that footfall stays within safe limits. Plus, they’ll be able to personalize in-store engagement the moment a shopper walks into a store, as WiFi systems recognize a returning customer. 

Giving retailers the ability to process, analyze and take actions, based on data where it is actually generated on the shop floor, edge computing generates the purchasing trend data that retailers need to execute highly personalized marketing. This can stimulate the purchase of products already discovered in-store or alert customers to trends and upcoming products they’re interested in. 

But that’s not the only benefit that comes with initiating edge computing. Retailers can also use the data that is generated by connected IoT sensors to become more operationally nimble and efficient: whether that is automating the monitoring of fridge and freezer temperatures to optimize product storage, or initiating new digitalized supply chain processes that improve the accuracy of in-store inventory tracking and enabling automated product re-ordering.

Competing to win and keep customers

 

Taking the in-store shopping experience into a new era will be vital, as society continues to recover from the immediate impact of coronavirus. The rise of the socially distanced shopper has ignited greater customer demand for omnichannel fulfilment options like click-and-collect and zero-touch transaction options in-store that are frictionless – and keep shoppers safe. 

In many ways, Covid-19 has helped accelerate many of the digital transformation drivers that were already leading high street retailers to re-invent the in-store shopping experience in a bid to compete with pure-play internet retailers. Getting customers back through the door represents a golden opportunity for retailers to re-imagine the in-store shopping experience with innovative technologies and services that truly resonate with socially distancing shoppers. 

This is where a game-changing technology like edge computing can help high street retailers close the gap: delivering the scalable, cost-effective, and easy-to-manage platforms they need to securely spin up new connected retail applications and appliances, and capture customer intelligence from the shop floor.

Johan Pellicaan, Vice President & Managing Director, Scale Computing EMEA

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scale Computing 
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

About The Channel Company
The Channel Company enables breakthrough IT channel performance with our dominant media, engaging events, expert consulting and education and innovative marketing services and platforms. As the channel catalyst, we connect and empower technology suppliers, solution providers and end users. Backed by more than 30 years of unequalled channel experience, we draw from our deep knowledge to envision innovative new solutions for ever-evolving challenges in the technology marketplace. thechannelcompany.com

停止支援 TLS 1.0 / 1.1 協定通知

親愛的客戶您好,

由於各大瀏覽器業者已於 2020 年 3 月起陸續發佈停止對 TLS 1.0 與 TLS 1.1 傳輸協定支援的聲明。
為保障您的系統連線安全,SPAM SQR、Mail SQR Expert 與 Mail Archiving Expert 將停止支援 TLS (Transport Layer) 1.0/1.1 協定。
為避免無法以 HTTPS 連線至 SPAM SQR、Mail SQR Expert 與 Mail Archiving Expert,建議使用最新的瀏覽器版本,並確認啟用 TLS1.2 以上。

造成您的不便,敬請見諒

如有任何問題,請洽客服專線:02-2543-2000

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於中華數位科技 Softnext Technologies Corp.
創立於2000年8月。
秉持著【We Secure Your Content】的服務理念,以提供企業資訊應用管理服務及打造資訊內容安全防護為宗旨。專精於提供網路應用服務技術,根據市場需求推出多款資訊內容安全的解決方案及應用服務,能夠協助企業透過符合資安管理規範並遵循法規的方式進行資訊內容安全管理,以維護員工的生產力、提升企業經營績效。

關於 ASRC 垃圾訊息研究中心
ASRC 垃圾訊息研究中心 (Asia Spam-message Research Center),長期與中華數位科技合作,致力於全球垃圾郵件、惡意郵件、網路攻擊事件等相關研究事宜,並運用相關數據統計、調查、趨勢分析、學術研究、跨業交流、研討活動..等方式,促成產官學界共同致力於淨化網際網路之電子郵件使用環境。更多資訊請參考 www.asrc-global.com .

訊連科技、聯強國際與英特爾攜手合作 舉辦「防疫一把罩!AI世代的智慧防疫解決方案」線上研討會

20200908日,台北訊】 全球頂尖AI臉部辨識領導廠商訊連科技 (5203.TW)宣布,與通路大廠聯強國際及物聯網領導廠商英特爾攜手合作進軍智慧辨識領域,將於2020年9月18日共同舉辦「防疫一把罩!AI世代的智慧防疫解決方案」線上研討會,於會中分享針對Intel® OpenVINO™及Movidius™等物聯網平台打造的FaceMe® Health及FaceMe® Security等多樣智慧防疫解決方案,協助各式應用場域於後疫情時代快速導入口罩偵測、身分辨識及體溫量測等應用。

 

COVID-19於臺灣疫情趨緩,進入進入後防疫時代,口罩仍是進出各公共場所不可或缺的防疫工具。與傳統體溫量測站需專人監看相比,訊連科技的FaceMe® Health及FaceMe® Security解決方案可透過先進的AI影像辨識,偵測口罩配戴、於配戴口罩時進行身分辨識,並同時量測體溫。

 

聯強國際是英特爾的長期合作夥伴,身為英特爾物聯網解決方案聚合商(Intel® IoT Solution Aggregator),聯強國際可提供最多元化的英特爾物聯網解決方案,協助各系統整合商和終端用戶於各式應用場景導入標準化、端對端的物聯網應用,具備快速部署、一站式服務之優勢。透過與訊連科技的合作,聯強國際可協助終端用戶於醫院、零售店、中央廚房、工廠等各式物聯網場景,快速打造自動化、一站式的AI健康量測站,及整合口罩辨識、身分辨識的智慧安控解決方案。

 

「防疫一把罩!AI世代的智慧防疫解決方案」線上研討會

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於CyberLink
訊連科技創立於1996年,擁有頂尖視訊與音訊技術的影音軟體公司,專精於數位影音軟體及多媒體串流應用解決方案產品研發,並以「抓準技術板塊,擴大全球行銷布局」的策略,深根台灣、佈局全球,展現亮麗的成績。訊連科技以先進的技術提供完美的高解析影音播放效果、以尖端的科技提供完整的高解析度擷取、編輯、製片及燒錄功能且完整支援各種高解析度影片及音訊格式。產品包括:「威力導演」、「PowerDVD」、「威力製片」、「威力酷燒」等。

關於聯強國際元件事業
聯強元件事業成立於1975年,是台灣第一家引進英特爾微處理器的公司,四十多年來扮演原廠與電子產品製造廠的橋樑,持續引進與代理先進的電子元組件產品,為OEM、ODM與品牌製造商提供整合性應用服務,滿足原廠與客戶在兩岸三地的市場需求。

聯強元件事業總共代理80多家國際一流品牌廠商電子元組件產品,橫跨計算機、周邊、通訊、消費性電子、工業儀表以及汽車領域等的多個垂直市場,結合聯強國際集團高效與優質運籌系統,提供客戶領先市場的一站式採購整合服務。

近年來,元件事業更積極拓展AI與物聯網市場,除了既有之軟硬體技術支援功能,更增強了主流和新興平台的工程能力,為供應商與客戶提供穩定信賴的支援系統。

更多詳細資訊請上聯強國際官網:http://www.synnex-grp.com/component/index.html

The Gorilla Guide to Delivering Turnkey IT Systems

Gorilla Guides are a popular series of free enterprise technology books, written to help readers avoid common IT strategy pitfalls and translate knowledge into actionable outcomes. Produced by ActualTech Media in cooperation with Scale Computing, the brand new “Gorilla Guide to Delivering Turnkey IT Systems” offers the perfect blend of easy reading and technical detail to ensure deep learning in a short amount of time.

A top priority for many IT departments is eliminating operational complexity. That’s not just true for large enterprises, either. Even small-to-midsize businesses can have a lot of IT infrastructure in their data center. This includes everything from hardware and software to databases and applications to switches and routers, and more. In other words, it’s a whole lot of “stuff”, and the more of it there is, the more complicated and time-consuming it becomes to manage it, to secure it, and to deploy new technologies.

In traditional or legacy computing environments, that leads to those things (management, security, deployment, etc.) all being handled separately — or as we say in IT, they become “siloed.” Silos are notoriously inefficient, slow things down, and make your admins less productive. This is exactly what gave rise to hyperconverged infrastructure (HCI)

HCI takes a giant leap forward in making things easier by eliminating those silos and reducing the administrative burden of providing and managing IT infrastructure. The Gorilla Guide clarifies core HCI concepts and explains how it can break down the silos that come with traditional or legacy computing and streamline every aspect of your IT operations to save time and money while decreasing TCO. Basically, everything becomes “turnkey.”

In setting out the dramatic advantages offered by HCI, from scalability and simplicity to manageability and cost, it’s hard if not impossible for legacy-style IT infrastructure to compete. But not all HCI vendors are the same, and this guide offers an ideal starting point for those looking to introduce HCI and eliminate complexity.

To download The Gorilla Guide to: Delivering Turnkey IT Systems, click here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scale Computing 
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×