Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
32 Indlæg 29 Posters 135 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

    CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

    Per Lyngaas: the hackers "exploited automatic tank gauge systems that were sitting online and unprotected by passwords."

    A little louder for the folks in the back:

    ...."UNPROTECTED BY PASSWORDS."

    https://www.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations

    trillionb@mstdn.socialT This user is from outside of this forum
    trillionb@mstdn.socialT This user is from outside of this forum
    trillionb@mstdn.social
    wrote sidst redigeret af
    #17

    @zackwhittaker I have zero doubt there are still stations with a Win 95 box reading a bunch of PLCs and dialing a modem to report nightly status.

    And they are more secure than this bs.

    1 Reply Last reply
    0
    • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

      CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

      Per Lyngaas: the hackers "exploited automatic tank gauge systems that were sitting online and unprotected by passwords."

      A little louder for the folks in the back:

      ...."UNPROTECTED BY PASSWORDS."

      https://www.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations

      cav@infosec.exchangeC This user is from outside of this forum
      cav@infosec.exchangeC This user is from outside of this forum
      cav@infosec.exchange
      wrote sidst redigeret af
      #18

      @zackwhittaker oof.

      And I'm sure they already know about all of the internet facing devices that monitor and control crude oil levels in tanks and can be disrupted to stop the flow of oil going into pipelines. Protected only by default user/pass. I saw that far to many times when I was the industry.

      I'm sure that won't become an issue at all at some point /s

      1 Reply Last reply
      0
      • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

        CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

        Per Lyngaas: the hackers "exploited automatic tank gauge systems that were sitting online and unprotected by passwords."

        A little louder for the folks in the back:

        ...."UNPROTECTED BY PASSWORDS."

        https://www.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations

        maddad@mastodon.worldM This user is from outside of this forum
        maddad@mastodon.worldM This user is from outside of this forum
        maddad@mastodon.world
        wrote sidst redigeret af
        #19

        @zackwhittaker

        Which makes me wonder if they could then initiate false readings too. 🤔

        1 Reply Last reply
        0
        • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

          CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

          Per Lyngaas: the hackers "exploited automatic tank gauge systems that were sitting online and unprotected by passwords."

          A little louder for the folks in the back:

          ...."UNPROTECTED BY PASSWORDS."

          https://www.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations

          jason@logoff.websiteJ This user is from outside of this forum
          jason@logoff.websiteJ This user is from outside of this forum
          jason@logoff.website
          wrote sidst redigeret af
          #20

          @zackwhittaker I mean weev went to prison for accessing things unprotected on the web. “Breach” is a dumb word here though.

          1 Reply Last reply
          0
          • xauriel@mastodon.nzX xauriel@mastodon.nz

            @zackwhittaker I mean, is it even really "hacking" at that point

            gabs@mastodonapp.ukG This user is from outside of this forum
            gabs@mastodonapp.ukG This user is from outside of this forum
            gabs@mastodonapp.uk
            wrote sidst redigeret af
            #21

            @XauriEL @zackwhittaker script kiddies are back

            1 Reply Last reply
            0
            • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

              @threatresearch @zackwhittaker

              THE EXACT MANUFACTURERS AND MODELS. WE'VE KNOWN THEY'D TARGET THESE FOR AT LEAST FIVE YEARS.

              FIVE YEARS.

              https://news.sky.com/story/irans-secret-cyber-files-on-how-cargo-ships-and-petrol-stations-could-be-attacked-12364871

              johntimaeus@infosec.exchangeJ This user is from outside of this forum
              johntimaeus@infosec.exchangeJ This user is from outside of this forum
              johntimaeus@infosec.exchange
              wrote sidst redigeret af
              #22

              @neurovagrant @threatresearch @zackwhittaker

              As part of spinning up on ICS/OT, I've been ingesting all the "cyber" writeups and videos from the vendors that I can.
              Two weeks ago I watched a CTO doing a ted-ish talk on why *grid devices* don't need and can't do basic security.
              The devices in question control substation contactors up th 500kV. They ship with default creds, and open telnet.

              I'm trying to figure out how big the upcoming rant is gonna be.

              felurx@troet.cafeF 1 Reply Last reply
              0
              • johntimaeus@infosec.exchangeJ johntimaeus@infosec.exchange

                @neurovagrant @threatresearch @zackwhittaker

                As part of spinning up on ICS/OT, I've been ingesting all the "cyber" writeups and videos from the vendors that I can.
                Two weeks ago I watched a CTO doing a ted-ish talk on why *grid devices* don't need and can't do basic security.
                The devices in question control substation contactors up th 500kV. They ship with default creds, and open telnet.

                I'm trying to figure out how big the upcoming rant is gonna be.

                felurx@troet.cafeF This user is from outside of this forum
                felurx@troet.cafeF This user is from outside of this forum
                felurx@troet.cafe
                wrote sidst redigeret af
                #23

                @johntimaeus Ooh that sounds like a fascinating watch, is it public / can you share a link?

                johntimaeus@infosec.exchangeJ 1 Reply Last reply
                0
                • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                  CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

                  Per Lyngaas: the hackers "exploited automatic tank gauge systems that were sitting online and unprotected by passwords."

                  A little louder for the folks in the back:

                  ...."UNPROTECTED BY PASSWORDS."

                  https://www.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations

                  tinker@infosec.exchangeT This user is from outside of this forum
                  tinker@infosec.exchangeT This user is from outside of this forum
                  tinker@infosec.exchange
                  wrote sidst redigeret af
                  #24

                  @zackwhittaker - Everyone is worried about the next stuxnet, but OT / ICS devices often have default creds or... as you point out... no creds...

                  And yes! The system is airgapped from the IT network! We only access it from the internet!!!! 😑

                  1 Reply Last reply
                  0
                  • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                    CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

                    Per Lyngaas: the hackers "exploited automatic tank gauge systems that were sitting online and unprotected by passwords."

                    A little louder for the folks in the back:

                    ...."UNPROTECTED BY PASSWORDS."

                    https://www.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations

                    zdl@mstdn.socialZ This user is from outside of this forum
                    zdl@mstdn.socialZ This user is from outside of this forum
                    zdl@mstdn.social
                    wrote sidst redigeret af
                    #25

                    @zackwhittaker Isn't blaming "Iranian hackers" for this kind of DARVOing it? You didn't put a lock on something you attached to the network. Do you also leave your gas tanks unlocked for any random passersby to open?

                    1 Reply Last reply
                    0
                    • zdl@mstdn.socialZ This user is from outside of this forum
                      zdl@mstdn.socialZ This user is from outside of this forum
                      zdl@mstdn.social
                      wrote sidst redigeret af
                      #26

                      @tinker @csstrowbridge @zackwhittaker Entered unsecured premises.

                      1 Reply Last reply
                      0
                      • felurx@troet.cafeF felurx@troet.cafe

                        @johntimaeus Ooh that sounds like a fascinating watch, is it public / can you share a link?

                        johntimaeus@infosec.exchangeJ This user is from outside of this forum
                        johntimaeus@infosec.exchangeJ This user is from outside of this forum
                        johntimaeus@infosec.exchange
                        wrote sidst redigeret af
                        #27

                        @felurx

                        Haven't written the rant quite yet. And I'll probably have to pull it back some because I suspect that corporate lawyers are going to advise me against the phrase "willful reckless negligence for the safety of the nation's critical infrastructure", while I mention specific companies.

                        Will share if allowed.

                        1 Reply Last reply
                        0
                        • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                          CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

                          Per Lyngaas: the hackers "exploited automatic tank gauge systems that were sitting online and unprotected by passwords."

                          A little louder for the folks in the back:

                          ...."UNPROTECTED BY PASSWORDS."

                          https://www.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations

                          leadegroot@bne.socialL This user is from outside of this forum
                          leadegroot@bne.socialL This user is from outside of this forum
                          leadegroot@bne.social
                          wrote sidst redigeret af
                          #28

                          @zackwhittaker @drwho and they figure it has to be Iranian hackers, not 11 year olds from Detroit, for Reasons 🤦‍♀️

                          drwho@masto.hackers.townD 1 Reply Last reply
                          0
                          • leadegroot@bne.socialL leadegroot@bne.social

                            @zackwhittaker @drwho and they figure it has to be Iranian hackers, not 11 year olds from Detroit, for Reasons 🤦‍♀️

                            drwho@masto.hackers.townD This user is from outside of this forum
                            drwho@masto.hackers.townD This user is from outside of this forum
                            drwho@masto.hackers.town
                            wrote sidst redigeret af
                            #29

                            @leadegroot @zackwhittaker Heh... Last year it would have been Chinese hackers.

                            1 Reply Last reply
                            0
                            • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                              CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

                              Per Lyngaas: the hackers "exploited automatic tank gauge systems that were sitting online and unprotected by passwords."

                              A little louder for the folks in the back:

                              ...."UNPROTECTED BY PASSWORDS."

                              https://www.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations

                              starkrg@myside-yourside.netS This user is from outside of this forum
                              starkrg@myside-yourside.netS This user is from outside of this forum
                              starkrg@myside-yourside.net
                              wrote sidst redigeret af
                              #30

                              @zackwhittaker So, they're not so much hackers as they are casual browsers with a penchant for finding open doors.

                              1 Reply Last reply
                              0
                              • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                                CNN's Sean Lyngaas back once again with a belter story: Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple U.S. states.

                                Per Lyngaas: the hackers "exploited automatic tank gauge systems that were sitting online and unprotected by passwords."

                                A little louder for the folks in the back:

                                ...."UNPROTECTED BY PASSWORDS."

                                https://www.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations

                                zazen@ieji.deZ This user is from outside of this forum
                                zazen@ieji.deZ This user is from outside of this forum
                                zazen@ieji.de
                                wrote sidst redigeret af
                                #31

                                @zackwhittaker Probably royally Shodaned!

                                1 Reply Last reply
                                0
                                • csstrowbridge@mastodon.socialC csstrowbridge@mastodon.social

                                  @zackwhittaker

                                  If it is unprotected, then it is not hacking.

                                  cascheranno@hachyderm.ioC This user is from outside of this forum
                                  cascheranno@hachyderm.ioC This user is from outside of this forum
                                  cascheranno@hachyderm.io
                                  wrote sidst redigeret af
                                  #32

                                  @csstrowbridge @zackwhittaker I’d say the wardialing part part counts, but have to admit they prolly just needed to ask Shodan

                                  1 Reply Last reply
                                  0
                                  • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                                  Svar
                                  • Svar som emne
                                  Login for at svare
                                  • Ældste til nyeste
                                  • Nyeste til ældste
                                  • Most Votes


                                  • Log ind

                                  • Har du ikke en konto? Tilmeld

                                  • Login or register to search.
                                  Powered by NodeBB Contributors
                                  Graciously hosted by data.coop
                                  • First post
                                    Last post
                                  0
                                  • Hjem
                                  • Seneste
                                  • Etiketter
                                  • Populære
                                  • Verden
                                  • Bruger
                                  • Grupper