Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
China Security Technology

Chinese Hackers Breach US Internet Firms via Startup, Lumen Says (msn.com) 16

The state-sponsored Chinese hacking campaign known as Volt Typhoon is exploiting a bug in a California-based startup to hack American and Indian internet companies, according to security researchers. From a report: Volt Typhoon has breached four US firms, including internet service providers, and another in India through a vulnerability in a Versa Networks server product, according to Lumen's unit Black Lotus Labs. Their assessment, much of which was published in a blog post on Tuesday, found with "moderate confidence" that Volt Typhoon was behind the breaches of unpatched Versa systems and said exploitation was likely ongoing.

Versa, which makes software that manages network configurations and has attracted investment from Blackrock and Sequoia Capital, announced the bug last week and offered a patch and other mitigations. The revelation will add to concerns over the susceptibility of US critical infrastructure to cyberattacks. The US this year accused Volt Typhoon of infiltrating networks that operate critical US services, including some of the country's water facilities, power grid and communications sectors, in order to cause disruptions during a future crisis, such as an invasion of Taiwan.

This discussion has been archived. No new comments can be posted.

Chinese Hackers Breach US Internet Firms via Startup, Lumen Says

Comments Filter:
  • But everyone here knows that MS-Windows is the only vulnerable operating system ever written. Wait, I know, is Versa a Microsoft business partner? No? How can this be? Everyone knows Cisco, Apple and the GNU/Linux communities collectively produce perfect software that's absolutely immune to exploit or abuse (well, everyone here at /., at any rate?). Even other companies make a far more stable and secure product than Microsoft, right?

    There. Got that out of my system. Now, from TFA:

    Microsoft Corp. na

    • But everyone here knows that MS-Windows is the only^H^H^H^Hmost vulnerable operating system ever written. (OK, maybe not.)

      It's not surprising that we see bugs at every layer of software. Operating system bugs tend to be critical because they affect a wide range of use cases. Applications tend to have exploits more frequently because there are a lot of different applications of widely varying quality, most of it very poor quality.

      If we lived in a system where you could sue for damaged due to hackers. Then I

      • by mmell ( 832646 )

        Yeah, there sure is. And I'll give you this - I can look at practically any Linux software, certainly anything FOSS, and see the design choices and even implementation specifics. Microsoft's proprietary black-box approach magnifies the effect of all design and implementation failures while simultaneously making it more difficult to identify and fix said deficiencies. A known sin of the proprietary model which makes Microsoft a beloved pariah in the IT industry.

  • Weird world (Score:3, Insightful)

    by Baron_Yam ( 643147 ) on Tuesday August 27, 2024 @01:25PM (#64740242)

    More or less open borders, agents could blow up critical infrastructure hubs and cripple the country for weeks if not months and nobody really worries about it.

    But someone hacks the control systems and we both lose our shit AND don't consider it an act of war.

    • Re: (Score:3, Informative)

      by OrangeTide ( 124937 )

      Borders or not, terrorist cells are able to operate within a country. Either by bringing people in legally, such as tourist visa or asylum seeker. We saw this with the ISIS stabbings in Germany. But also a terrorist organization can enlist radicalized citizens of a country in order to do their dirty work.
      Shutting down borders. Ceasing trade. Ending globalization. And so on is going to cause more economic harm than good, and in the end it won't really keep you safe.

      State sponsored cyberwarfare is happening t

  • Sure is looking like you have a better chance to control your own security.

    Copy-pasta third party security isn't. But at least you can pass the blame.
  • Chinese hacking [US] according to US state spying agency the NSA.

"How many teamsters does it take to screw in a light bulb?" "FIFTEEN!! YOU GOT A PROBLEM WITH THAT?"

Working...