Scary datapoints re network visibility in Dragos annual report on OT cyberattacks
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内。首先,我需要仔细阅读文章,抓住主要观点。 文章主要讲的是OT网络攻击的威胁。里面提到只有5-10%的基础设施有预事件的可见性,这说明大部分企业缺乏足够的防御能力。然后,重点是勒索软件团伙已经找到了攻击OT/ICS系统的方法,而且他们不需要特别的技术,只需要身份滥用就能进入系统。这可能意味着攻击门槛降低,威胁增加。 接着,文章指出这些勒索软件攻击者通常是为了快速获利,并且他们的技能水平中等。他们通过加密管理OT设备的虚拟或桌面机器来影响受害者。最后,作者提到未来的威胁可能来自“Com”在OT网络中的存在。 总结一下,我需要把这些要点浓缩到100字以内。要确保涵盖关键点:OT网络攻击、勒索软件、无需特殊技能、影响企业运营、未来威胁。 现在组织语言:文章讨论了针对OT网络的未知威胁和勒索软件攻击的风险。勒索软件团伙无需特殊技能即可通过身份滥用直接访问OT系统,影响企业运营。未来,“Com”在OT中的存在可能带来更多威胁。 检查字数是否合适,大约在100字左右。确保没有使用“文章内容总结”之类的开头,直接描述内容。 </think> 文章讨论了针对工业控制系统的未知网络威胁和勒索软件攻击的风险。尽管大多数关键基础设施缺乏足够的安全可见性以应对此类攻击,但勒索软件团伙已找到直接访问和破坏OT/ICS系统的方法,并且无需特殊技能即可实现。这些攻击不仅影响企业运营,还可能导致更广泛的物理破坏风险。 2026-2-23 03:40:54 Author: www.reddit.com(查看原文) 阅读量:15 收藏

OT cyber attacks are an unknown unknown. We don't know what we don't know because (per the annual Dragos report) only 5-10 percent of even regulated critical infrastructure has the pre-incident visibility into OT network traffic to do root cause analysis or post incident forensics and identify cyber attacks.
But the lead for my OT Today story, and the really scary thing is that ransomware gangs have finally figured out how to get to and disable OT/ICS systems.
Headline: They don't need any special skills. Bog standard identity abuse will get them access. They don't even need to pivot through a (hopefully segmented) enterprise IT network, because there are servers and desktops that provide direct access to OT systems. If they were foreign cyber warriors intent on developing the capability to destroy the system physically, they would begin exfiltrating system configuration files.
But by and large the ransomware IABs attacking industrial organizations are greedy, sadistic and mid-skilled at best (see Scattered Lapsus ShinyHunters). They are after a quick profit and ignorant as they might be, they do know that deploying common or garden ransomware on virtual or desktop machines remotely managing OT/ICS equipment will affect their victims' bottom line much more readily than an email server.
The future is The Com in every OT network.


文章来源: https://www.reddit.com/r/netsec/comments/1rc6t3w/scary_datapoints_re_network_visibility_in_dragos/
如有侵权请联系:admin#unsafe.sh