"Attackers can easily identify and access internet-connected systems that use shared default passwords. It is imperative to change default manufacturer passwords and restrict network access to critical and important systems," the cybersecurity agency said.
CISA urges tech manufacturers to stop using default passwords
- December 15, 2023
- 02:01 PM
- 0

Once discovered, threat actors can use such default credentials a backdoor to breach vulnerable devices exposed online.
- Default passwords are commonly used to streamline the manufacturing process or help system administrators deploy large numbers of devices within an enterprise environment more easily.
- "This SbD Alert urges technology manufacturers to proactively eliminate the risk of default password exploitation," CISA said, by taking "ownership of customer security outcomes" and building "organizational structure and leadership to achieve these goals."
goog_1901901143"This SbD Alert urges technology manufacturers to proactively eliminate the risk of default password exploitation," CISA said, by taking- "By implementing these two principles in their design, development, and delivery processes, software manufactures will prevent exploitation of static default passwords in their customers' systems."
- "By implementing these two principles in their design, development, and delivery processes, software manufactures will prevent exploitation of static default passwords in their customers' systems."
- "Years of evidence have demonstrated that relying upon thousands of customers to change their passwords is insufficient, and only concerted action by technology manufacturers will appropriately address severe risks facing critical infrastructure organizations," CISA added.
Alternatives to default passwords
- Moreover, they can implement time-limited setup passwords designed to deactivate once the setup phase concludes and prompt admins to activate more secure authentication methods, such as phishing-resistant Multi-Factor Authentication (MFA).
- Another possibility involves mandating physical access for the initial setup and specifying distinct credentials for each instance.
- "Attackers can easily identify and access internet-connected systems that use shared default passwords. It is imperative to change default manufacturer passwords and restrict network access to critical and important systems," the cybersecurity agency said.
"Default passwords are intended for initial testing, installation, and configuration operations, and many vendors recommend changing the default password before deploying the system in a production environment."
Iranian hackers recently employed this approach, using a '1111' default password for Unitronics programmable logic controllers (PLCs) exposed online to breach U.S,. critical infrastructure systems, including a U.S. water facility.
LATEST ARTICLES
-
3CX warns customers to disable SQL database integrations
VoIP communications company 3CX warned customers today to disable SQL Database integrations because of risks posed by what it describes as a potential vulnerability.
- DECEMBER 15, 2023
- 12:30 PM
0
-
Ransomware gang behind threats to Fred Hutch cancer patients
The Hunters International ransomware gang claimed to be behind a cyberattack on the Fred Hutchinson Cancer Center (Fred Hutch) that resulted in patients receiving personalized extortion threats.
- DECEMBER 15, 2023
- 11:50 AM
0
-
Box cloud storage down amid 'critical' outage
Cloud storage provider Box.com is suffering an outtage preventing customers from accessing their files.
- DECEMBER 15, 2023
- 10:36 AM
0
-
Delta Dental of California data breach exposed info of 7 million people
Delta Dental of California and its affiliates are warning almost seven million patients that they suffered a data breach after personal data was exposed in a MOVEit Transfer software breach.
- DECEMBER 15, 2023
- 09:53 AM
0
-
This cyber security workshop is on sale for $499.99 (reg. $1000)
Get these Cyber Security Specialist Workshop Live Sessions on sale for just $499.99 (reg. $1000) for a limited time only.
- DECEMBER 15, 2023
- 07:17 AM
0
-
Kraft Heinz investigates hack claims, says systems ‘operating normally’
Kraft Heinz has confirmed that their systems are operating normally and that there is no evidence they were breached after an extortion group listed them on a data leak site.
- DECEMBER 14, 2023
- 06:30 PM
1
-
New NKAbuse malware abuses NKN blockchain for stealthy comms
A new Go-based multi-platform malware identified as 'NKAbuse' is the first malware abusing NKN (New Kind of Network) technology for data exchange, making it a stealthy threat.
- DECEMBER 14, 2023
- 05:15 PM
0
-
Ubiquiti users report having access to others’ UniFi routers, cameras
Since yesterday, customers of Ubiquiti networking devices, ranging from routers to security cameras, have reported seeing other people's devices and notifications through the company's cloud services.
- DECEMBER 14, 2023
- 03:38 PM
1
-
US detains suspects behind $80 million 'pig butchering' scheme
The U.S. Department of Justice charged four suspects (two of them already detained) for their alleged involvement in a pig butchering fraud scheme that resulted in more than $80 million in victim losses.
- DECEMBER 14, 2023
- 02:47 PM
1
-
Ten new Android banking trojans targeted 985 bank apps in 2023
This year has seen the emergence of ten new Android banking malware families, which collectively target 985 bank and fintech/trading apps from financial institutes across 61 countries.
- DECEMBER 14, 2023
- 02:40 PM
0
-
This refurbished Microsoft Surface Pro is just $393.99 (reg. $849)
Get this Microsoft Surface Pro 6, 12.3" i5 1.7Ghz 8GB RAM 128GB SSD with Type Cover (Refurbished) on sale for only $393.99 (reg. $849).
- DECEMBER 14, 2023
- 02:06 PM
0
-
Discord adds Security Key support for all users to enhance security
Discord has made security key multi-factor authentication (MFA) available for all accounts on the platform, bringing significant security and anti-phishing benefits to its 500+ million registered users.
- DECEMBER 14, 2023
- 01:21 PM
0
-
U.S. nuclear research lab data breach impacts 45,000 people
The Idaho National Laboratory (INL) confirmed that attackers stole the personal information of more than 45,000 individuals after breaching its cloud-based Oracle HCM HR management platform last month.
- DECEMBER 14, 2023
- 12:59 PM
0
-
Ledger dApp supply chain attack steals $600K from crypto wallets
Ledger is warnings users not to use web3 dApps after a supply chain attack on the 'Ledger dApp Connect Kit' library was found pushing a JavaScript wallet drainer that stole $600,000 in crypto and NFTs.
- DECEMBER 14, 2023
- 11:22 AM
0
No comments:
Post a Comment