Info Risk Vulnerabilities Blog

Wednesday, October 24, 2012

Iran and Aramco

CNBC has a revised atory (significantly) regarding the Iranian viral attack on Aramco, I remain unimpressed, An infected USB drive MAY have been used by a privileged user to introduce the virus, Aramco was suspiciously vulnerable, the virus included a feature (Wiper) that attacked hard drives, Wiper is nothing new and may have been taken from Flash.  I remain concerned that the Stuxnet family will be morphed into very damaging future viruses.  Regarding Aramco, I see their vulnerability as a reflection of current disregard for protection best practices and generally shoddy operations.  The fact the SOD sees US vulnerability to a virus says loads!!!  The malware threat is getting too much credit but ringing the alarm bell is not a bad thing in the current corporate environment.  Malware should be a defanged threat, of course defanged dosn't mean dead.