HomeSecurityRussian Security Group Upgrades SCADA Exploit Tool

Russian Security Group Upgrades SCADA Exploit Tool

SCADA A security firm in Russia is planning to release an updated exploit pack for industrial control software that includes a number of new vulnerabilities, published by an Italian researcher . The company is called Gleg, is made up of three people and is based in Moscow. Its focus is on vulnerability research. Its research has recently focused on security issues in SCADA (supervisory control and data acquisition) systems, which are used in factories, businesses and many other industrial sectors.

Gleg is working with Miami-based Immunity, which sells the Canvas tool, which helps with penetration testing to gain insight into how vulnerabilities in software.

Gleg supplies Immunity with exploit packs, which are add-ons for Canvas. Gleg's core product is Agora, which is integrated into Canvas. Agora is regularly updated with published zero-day or other new vulnerabilities.

Russian Security Group Upgrades SCADA Exploit Tool

About two weeks ago, the Russian company released Agora SCADA+ , a new add-on for Canvas. The add-on includes 27 exploits for the SCADA software. An upgraded version will be released next week , which will contain about 35 exploits.

According to the company's CEO, Yuriy Gurkin, Gleg will incorporate the exploits, written by Luigi Ariemma. Ariemma found about 50 vulnerabilities in four products from Siemens, Iconics, 7-Technologies and Datac. All four companies used products with vulnerabilities that could be exploited remotely by an attacker.

Ariemma published details about the vulnerabilities without first notifying the affected companies, which is seen by many as a negative. However, 7-Technologies and Datac are said to have been working on a patch.

Gurkin said that Gleg also follows Luigi's practice. It does not inform companies because it considers it a waste of time.

On the other hand, Immunity vets companies interested in purchasing Canvas to make sure they are not going to use the product in a malicious way.

According to Gurkin, more and more companies using SCADA software are asking Gleg to test the products.

SCADA software wasn't originally designed to be connected to the Internet, but many companies use it that way. That, of course, means there are more risks , Gurkin said. Also, companies that use SCADA aren't as open to sharing security advice and knowledge, he said.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS