Business Wire

CA-FORESCOUT-TECHNOLOGIE

13.1.2024 15:53:28 CET | Business Wire | Pressemeddelelse

Del
Sandworm har ikke alene skylden: Forescout Research afdækker nye beviser for cyberangreb på energisektoren i Danmark

Forescout, en global leder inden for cybersikkerhed løftede i dag sløret for "Clearing the Fog of War", en rapport, der præsenterer nye beviser for to tidligere dokumenterede angreb, der ramte den danske energisektor i maj 2023.

Der er multimedier i denne pressemeddelelse. Se hele meddelelsen her: https://www.businesswire.com/news/home/20240110894177/da/

For at se dette indhold fra mms.businesswire.com, så skal du give din accept på toppen af denne side.

Clearing the Fog of War (Source: Forescout)

Forescout Research – Vedere Labs gennemførte en uafhængig analyse af disse angreb og afslørede en større kampagne, der ikke fuldt ud kunne tilskrives Advanced Persistent Threat-gruppen Sandworm, sammen med andre fund, som det danske cybersikkerhedscenter SektorCERT ikke offentliggjorde i sin rapport fra november 2023.

I sine observationer af Adversary Engagement Environment (AEE) identificerede Vedere Labs to vigtige resultater:

  • Sandworm er ikke den fælles trusselsaktør: Forescout-forskerne påviste en anden teknik til at ramme den kritiske infrastruktur i den efterfølgende bølge end den, der blev brugt i første angrebsbølge. Dette tyder på, at Sandworm ikke kan udpeges som den APT-gruppe, der er forbundet med begge angrebsbølger.
  • Masseudnyttelse blev videreført af en copycat: Den anden bølge af angreb udnyttede upatchede firewalls ved hjælp af en ny "populær" CVE-2023-27881 og yderligere IP-adresser, der ikke blev rapporteret i SektorCERT-rapporten. Meget tyder på, at den anden bølge var en del af en separat masseudnyttelseskampagne.

"At skelne mellem en statsstøttet kampagne, der har til formål at forstyrre kritisk infrastruktur, og en kriminel bølge af masseudnyttelseskampagner, samtidig med at man tager højde for potentielle overlap mellem de to, er nemmere set i bakspejlet end i øjeblikkets hede," bemærker Elisa Costante, VP of Research hos Forescout Research – Vedere Labs. "Denne rapport understreger betydningen af at kontekstualisere observerede hændelser med omfattende trussels- og sårbarhedsefterretninger med henblik på at forbedre OT-netværksovervågning og udvikle bedre hændelsesresponsplaner."

Læs bloggen: Clearing the Fog of War – En kritisk analyse af de seneste cyberangreb på energisektoren i Danmark og Ukraine

Efter den anden hændelse blev yderligere angreb i de efterfølgende måneder rettet mod udsatte enheder i kritiske infrastrukturer verden over. Forescout-forskere registrerede adskillige IP-adresser, der forsøgte at udnytte Zyxel-sårbarheden CVE-2023-28771, så sent som i oktober 2023, på tværs af forskellige enheder, herunder yderligere Zyxel-firewalls. I øjeblikket bruger seks forskellige elselskaber i europæiske lande Zyxel-firewalls, og de kan således fortsat være følsomme over for potentiel udnyttelse af ondsindede aktører.

Denne nyere dokumentation understreger nødvendigheden af, at energivirksomheder og organisationer, der fører tilsyn med kritisk infrastruktur, er opmærksomme på aktuelle trusselsefterretninger, herunder oplysninger om ondsindede IP'er og kendte udnyttede sårbarheder. Regeringer tager i stigende grad proaktive forholdsregler ved at afsætte midler til initiativer, der har til formål at styrke sikkerheden for kritisk infrastruktur inden for energisektoren. Navnlig har det amerikanske energiministerium annonceret et nyt finansieringsinitiativ og øremærket 70 millioner dollars til dette formål så sent som i sidste uge.

Forescout Research gennemførte denne analyse ved hjælp af deres AEE, som omfatter både virkelige og simulerede forbundne enheder. Dette miljø fungerer som et dybdegående værktøj til at lokalisere hændelser og skelne mellem trusselsaktørers mønstre på et højt detaljeret niveau. Målet er at forbedre reaktionerne på komplicerede angreb på kritisk infrastruktur ved hjælp af den dybere indsigt og forståelse, der opnås fra dette specialiserede testmiljø.

Flere oplysninger kan findes i den fulde rapport, "Clearing the Fog of War".

Om Forescout

Forescout Technologies, Inc. er en global leder inden for cybersikkerhed, der løbende identificerer, beskytter og hjælper med at sikre overholdelse af alle administrerede og ikke-administrerede forbundne cyberaktiver – IT, IoT, IoMT og OT. Gennem mere end 20 år har Fortune 100-organisationer og offentlige myndigheder betroet Forescout at stille leverandøruafhængig, automatiseret cybersikkerhed til rådighed i stor skala. Forescout®-platformen leverer omfattende løsninger inden for netværkssikkerhed, risiko- og eksponeringsstyring samt udvidet detektion og respons. Med gnidningsfri kontekstdeling og workflow-orkestrering via økosystempartnere giver det kunderne mulighed for mere effektivt at håndtere cyberrisici og afværge trusler.

Originalsprogsudgaven af denne bekendtgørelse er den officielle, autoriserede version. Oversættelserne er kun tænkt som en hjælp og bør sammenholdes med kildesprogsteksten, der som den eneste er juridisk bindende.

For at se dette indhold fra cts.businesswire.com, så skal du give din accept på toppen af denne side.

Se kildeudgaven på businesswire.com: https://www.businesswire.com/news/home/20240110894177/da/

Information om Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Følg pressemeddelelser fra Business Wire

Skriv dig op her, og modtag pressemeddelelser på e-mail. Indtast din e-mail, klik på abonner, og følg instruktionerne i den udsendte e-mail.

Flere pressemeddelelser fra Business Wire

Caidya Announces Strategic Combination with Simbec-Orion Bridging Early Scientific Insight and Global Clinical Execution30.6.2026 17:00:00 CEST | Press release

Caidya today announced a strategic combination with Simbec-Orion designed to close the divide between early scientific insight and global clinical execution. The combination of Caidya and Simbec-Orion creates a differentiated specialty clinical CRO platform that enables programs to scale, maintaining focus, speed, and accountability. The strategic combination brings together complementary strengths to create a more complete development partner for innovative biopharma companies. With established operations across Europe, the Americas, APAC, and China, the combined organization provides meaningful expertise and execution capabilities in the regions that matter most. Simbec-Orion brings early-phase clinical pharmacology capabilities alongside deep therapeutic expertise for later stage complex oncology and rare disease trials, helping sponsors shape critical decisions early in the development lifecycle. Together, the organizations strengthen their ability to support complex, cross-border

Archer® Proves Purpose-Built AI Beats General-Purpose LLMs on Regulatory Change Management: 95% Verified Accuracy, 80x Faster, 92% Lower Cost30.6.2026 16:13:00 CEST | Press release

In a head-to-head benchmark, a leading general-purpose LLM was confidently wrong 35% of the time on regulatory dates. Archer Evolv™ shipped zero errors. For enterprises deploying AI in compliance, a wrong date is a missed deadline. The more dangerous failure is a wrong answer the model returns with high confidence, one that flows silently into a compliance calendar and is only discovered after the window has passed. Archer® today released results showing purpose-built AI beats a general-purpose large language model (LLM) on regulatory work, and it’s not close. This head-to-head test compared Archer’s purpose-built, vertical-specific AI and proprietary data sets against a leading general-purpose LLM, on a core compliance task: determining the publication, effective and comment-close dates of regulatory documents across six jurisdictions. General-purpose models are a genuine breakthrough, and this is no referendum on their quality. The question Archer set out to answer is narrower and mo

Altasciences Supports Key Development Milestone for Steel Therapeutics’ Lead Therapeutic Candidate, Fizurex™30.6.2026 16:08:00 CEST | Press release

Altasciences, a leading drug development organization, today announced a significant milestone in the development of Steel Therapeutics, Inc.’s pivotal toxicology study for its lead product candidate, Fizurex™, for the treatment of anal fissures. The successful completion of the study plays a significant role in the advancement of Fizurex™ toward first-in-human trials. The GLP-compliant study demonstrated a favorable safety profile, which has advanced Steel Therapeutics' plans to submit an Investigational New Drug (IND) application for Fizurex™ to the FDA in Q3 2026. Fizurex™, a patent-pending, single-use topical wipe, was designed to provide a standardized, accessible treatment option for a painful and often undertreated medical condition. The product builds on years of use through compounding pharmacy prescriptions and is now advancing toward clinical development and regulatory review. "We are proud to have supported Steel Therapeutics with the generation of the high-quality safety d

Interactive Brokers Expands Access to Korean Equities with Launch of Nextrade ATS30.6.2026 16:00:00 CEST | Press release

IB SmartRouting℠ Routes Orders to the Best Available Price Between KRX and Nextrade Interactive Brokers (Nasdaq: IBKR), an automated global broker, today announced the launch of select Korean equities through Nextrade, South Korea's first Alternative Trading System (ATS). The addition of Nextrade builds on Interactive Brokers' earlier launch of the Korea Exchange (KRX), through which it became the first major US-based broker to provide global investors with direct access to Korean equities. Clients trading on Nextrade benefit from significantly extended trading hours and access to additional liquidity. Interactive Brokers has enabled IB SmartRouting℠ across both the Korea Exchange (KRX) and Nextrade, automatically routing orders to the venue offering the best price. This helps clients achieve best execution while providing greater flexibility and more opportunities to participate in one of Asia's most dynamic equity markets. Korea's equity market ranks among the top global exchanges by

90% of IT Leaders See Gaps in AI Threat Readiness, Lenovo Brings Single Point of Accountability to Cyber Resiliency30.6.2026 15:00:00 CEST | Press release

New end-to-end resilience and managed security offerings help organizations reduce security complexity, cut system downtime by up to 50%, and lower remediation costs by up to 40% by bringing devices, security technologies, expert services, and ecosystem partners together under a single operational model As organizations accelerate AI adoption and digital workplace transformation, many are finding that cyber resilience is undermined not by a lack of security tools, but by growing operational complexity and threat sophistication. According to recent research, 90% of IT leaders acknowledge gaps in their ability to defend against AI-driven threats. While security investments continue to grow, many organizations face a different challenge: fragmented accountability. Security operations remain highly distributed and siloed, making it increasingly difficult to coordinate response efforts, maintain end-to-end business continuity, and recover quickly when incidents occur. To help organizations

I vores nyhedsrum kan du læse alle vores pressemeddelelser, tilgå materiale i form af billeder og dokumenter samt finde vores kontaktoplysninger.

Besøg vores nyhedsrum
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye