Claroty

State of CPS Security Report

We have been conditioned as an industry to equate healthcare cybersecurity with data privacy. The Health Insurance Portability and Accountability Act (HIPAA) has been the impetus for this approach for 27 years by zeroing in on the protection of personal patient information and enacting privacy and security rules aimed at keeping such data confidential. For […]

State of CPS Security Report Read More »

State of XIoT Security: 2H 2022

For more than three years, and now six of these reports, Claroty Team82 has provided biannual analyses of publicly disclosed vulnerabilities affecting operational technology (OT), internet of things (IoT) devices, and most recently, the internet of medical things (IoMT). We have not only found and privately disclosed more than 400 vulnerabilities since our inception, but

State of XIoT Security: 2H 2022 Read More »

State of XIoT Security

Team82’s analysis of vulnerabilities impacting cyber-physical systems across the Extended Internet of Things—1H 2022 After more than 20 years of connecting things to the internet, we’ve reached a critical mass where the food we eat, water we drink, elevators we ride, and the oil and gas that warms our homes rely on computer code. Today’s

State of XIoT Security Read More »

Evil PLC Attack: Weaponizing PLCs

Programmable logic controllers (PLCs) are indispensable industrial devices that control manufacturing processes in every critical infrastructure sector. Because of their position within automation, threat actors covet access to PLCs; several industrial control system malware strains, from Stuxnet to Incontroller/Pipedream, have targeted PLCs. But what if the PLC wasn’t the prey, and instead was the predator?

Evil PLC Attack: Weaponizing PLCs Read More »

Global State of Industrial Cybersecurity 2021: Resilience Amid Disruption

This independent, global survey of 1,100 information technology (IT) and operational technology (OT) security professionals who work full time for enterprises that own, operate, or otherwise support components of critical infrastructure, explores how they have dealt with the significant challenges in 2021, their levels of resiliency, and priorities moving forward. Key findings include: Ransomware is

Global State of Industrial Cybersecurity 2021: Resilience Amid Disruption Read More »

Claroty biannual ICS risk & vulnerability report: 1H 2021

The first half of 2021 was the biggest test of industrial cybersecurity in history. Many companies are enjoying the fruits of connecting devices to the internet and converging operational technology (OT) under IT systems management. Yet that momentum has also beaconed out to threat actors, particularly those whose trade is extortion and profit. Assets are

Claroty biannual ICS risk & vulnerability report: 1H 2021 Read More »

Claroty Biannual ICS Risk & Vulnerability Report: 2H 2020

EXECUTIVE SUMMARY Few of us will fondly remember 2020, a transformative year that forced businesses worldwide to rethink and reprioritize remote workforces, their impact on productivity and business continuity, and the expanded attack surfaces consequential to those changes. Opportunistic attackers went especially low throughout 2020, elevating extortion and ransomware attacks within their arsenals and targeting

Claroty Biannual ICS Risk & Vulnerability Report: 2H 2020 Read More »

License to Kill: Leveraging License Management to Attack ICS Networks

Claroty researchers have found six vulnerabilities in Wibu-Systems AG’s CodeMeter product, a solution widely used in the ICS domain as a license-management and antipiracy tool. The vulnerabilities collectively earned the highest criticality CVSS score of 10.0, and can be exploited in denial-of-service attacks, or to achieve remote code execution. Wibu-Systems’ CodeMeter is used in critical

License to Kill: Leveraging License Management to Attack ICS Networks Read More »