7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
美国7个州的供水系统遭网络攻击,疑与伊朗有关
This week, WIRED obtained a memo that tied dozens of cyberattacks against Minnesota water and wastewater utilities to Iran, the first official documentation of Iran’s likely responsibility for the most impactful campaign of cyberattacks to hit the US in the midst of the war that began nearly six months ago. 本周,《连线》(WIRED)获得的一份备忘录显示,针对明尼苏达州供水和废水处理设施的数十起网络攻击与伊朗有关。这是官方首次记录到伊朗极有可能对这场自六个月前战争爆发以来,对美国造成最严重影响的网络攻击行动负责。
In other news, more details have emerged about OpenAI’s “rogue” AI agent breach of Hugging Face’s platform. OpenAI disclosed that the AI agent hacked multiple third-party accounts and services as it sought to breach Hugging Face’s production database, which contained solutions for the cybersecurity tests OpenAI was evaluating the agent with. 在其他新闻方面,关于 OpenAI 的“流氓”AI 智能体入侵 Hugging Face 平台的更多细节浮出水面。OpenAI 披露称,该 AI 智能体在试图入侵 Hugging Face 的生产数据库时,黑进了多个第三方账户和服务。该数据库中包含了 OpenAI 用于评估该智能体的网络安全测试方案。
Anthropic, too, disclosed that its AI models gained unauthorized access to three organizations’ systems during its own cybersecurity testing. Experts say the incidents underscore the importance of implementing well-known security best practices on the part of AI labs. Anthropic 也披露,其 AI 模型在自身的网络安全测试过程中,未经授权访问了三个组织的系统。专家表示,这些事件凸显了 AI 实验室落实公认安全最佳实践的重要性。
AI is changing cybersecurity in other ways. Google’s Chrome Browser now receives twice-a-week security updates as more bugs are identified and fixed thanks to the security team’s use of AI tools. And a new research study found that AI chatbots are effective at reeling victims into pig-butchering scams. 人工智能正在以其他方式改变网络安全。得益于安全团队对 AI 工具的使用,谷歌 Chrome 浏览器现在每周会收到两次安全更新,以识别并修复更多漏洞。此外,一项新的研究发现,AI 聊天机器人能有效地诱导受害者陷入“杀猪盘”诈骗。
The US Immigration and Customs Enforcement is attempting to prevent state oversight of four detention facilities, and a Department of Homeland Security official resigned, citing the agency’s “war on immigrants.” 美国移民及海关执法局(ICE)正试图阻止州政府对四个拘留设施的监管,一名国土安全部官员辞职,并称该机构在发动“针对移民的战争”。
Plus, a GPS jamming exercise in New Mexico contributed to the crash of a civilian plane, as drone warfare reshapes how safe the skies are both in the US and abroad. People were surprised to see shared Claude chats popping up as search results on major search engines. An innocent gamer was imprisoned for 18 months after law enforcement made a typo in a subpoena. Researchers found that the top image-editing models on Hugging Face can easily create explicit deepfakes. And attendee badges for this year’s Defcon hacker conference feature a custom hardware security token that can be used as a security token after the conference is over. 此外,新墨西哥州的一次 GPS 干扰演习导致了一架民用飞机的坠毁,无人机战争正在重塑美国及全球领空的安全性。人们惊讶地发现,共享的 Claude 对话出现在了主流搜索引擎的搜索结果中。一名无辜的游戏玩家因执法部门在传票中出现拼写错误而被监禁了 18 个月。研究人员发现,Hugging Face 上顶级的图像编辑模型可以轻易制作出露骨的深度伪造(deepfake)内容。今年的 Defcon 黑客大会参会证件内置了一个定制的硬件安全令牌,会议结束后仍可作为安全令牌使用。
And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there. 还有更多内容。每周,我们都会汇总那些我们未深入报道的安全与隐私新闻。点击标题即可阅读全文。祝大家保持安全。
7 States’ Water Utilities Now Hit With Cyberattacks—Likely by Iranian Hackers
美国7个州的供水设施遭网络攻击——疑为伊朗黑客所为
The news that more than 30 water utilities across Minnesota were hit with cyberattacks in the last week already represented perhaps the broadest, most disruptive hacking campaign to ever target American industrial control systems—the technology that connects digital software with physical equipment, often in critical infrastructure settings. Now the FBI has warned that the attacks have hit utilities in no fewer than seven states, well beyond Minnesota alone. 上周,明尼苏达州 30 多家供水设施遭到网络攻击的消息,可能已成为针对美国工业控制系统(连接数字软件与物理设备的底层技术,常用于关键基础设施)规模最大、破坏性最强的黑客行动。现在,联邦调查局(FBI)警告称,攻击已波及至少 7 个州的公用事业设施,远不止明尼苏达州一地。
In its alert, the FBI didn’t name the targeted states or include details about the extent of the disruption or damage the hacking campaign caused. But the bureau said that it and the Environmental Protection Agency were working with affected utilities. The Cybersecurity and Infrastructure Security Agency, in its own advisory this week, stated that the attacks had in some cases disabled digital controls and “resulted in boil-water notices”—suggesting potential water contamination. Echoing that CISA advisory, the FBI also warned that utilities should immediately take measures to remove from the internet digital devices that connect to physical equipment, known as programmable logic controllers, protect them with strong passwords, and set up allow-lists to only allow authorized devices to connect to them. 在警报中,FBI 未点名受影响的州,也未提供此次黑客行动造成的破坏程度或损失细节。但该局表示,正与环境保护署(EPA)共同协助受影响的公用事业机构。网络安全与基础设施安全局(CISA)在本周的咨询报告中指出,攻击在某些情况下禁用了数字控制系统,并“导致了煮沸用水通知”——这暗示了潜在的水污染风险。FBI 呼应了 CISA 的建议,警告称公用事业机构应立即采取措施,将连接物理设备的数字设备(即可编程逻辑控制器,PLC)从互联网上移除,使用强密码进行保护,并设置白名单,仅允许授权设备连接。
The leading suspect behind the wave of attacks remains Iranian-affiliated hackers, as first laid out in a CISA advisory in April, which a leaked memo obtained by WIRED confirmed was connected to the more recent Minnesota utility attacks, too. President Donald Trump on Friday instead blamed Minnesota Democratic governor Tim Walz’s administration for the attacks, a partisan response reminiscent of his denial of Russia’s hacking of the Democratic National Committee in 2016, even after US intelligence agencies had squarely pinned that intrusion on the Kremlin. 此次攻击浪潮的主要嫌疑人仍是与伊朗有关的黑客,这与 CISA 4 月份的咨询报告一致。WIRED 获得的一份泄露备忘录证实,这与近期明尼苏达州的公用事业攻击事件也有关联。周五,唐纳德·特朗普总统将攻击归咎于明尼苏达州民主党州长蒂姆·沃尔兹(Tim Walz)的政府。这种党派色彩浓厚的反应,让人想起他在 2016 年否认俄罗斯黑客攻击民主党全国委员会的行为,尽管当时美国情报机构已明确将该入侵事件归咎于克里姆林宫。
FBI Shops for Pre-Crime AI
FBI 寻求“犯罪预判”AI
An FBI request for information, posted in March by the bureau’s procurement arm, lists predictive modeling as one of six requirements for the Threat Screening Center. The system would draw on existing datasets and, as new records arrive, score them for similarity and “pattern alignment” against what the center already holds. The second Trump administration has reoriented the center toward domestic targets, guided by a memorandum directing the national security apparatus to target people defined broadly as anti-capitalist, anti-Christian, and hostile toward traditional views on family and religion. FBI 采购部门于 3 月发布的一份信息征询书,将预测建模列为威胁筛查中心的六项要求之一。该系统将利用现有数据集,并在新记录录入时,根据中心已有的数据对其进行相似度和“模式匹配”评分。特朗普第二届政府已将该中心的重心转向国内目标,并根据一份备忘录指示国家安全机构,将目标锁定为被广泛定义为反资本主义、反基督教以及敌视传统家庭和宗教观念的人群。
FBI director Kash Patel told Congress in March that the center had posted double-digit growth in biometric capability and intelligence production. The watch list is reportedly approaching 2 million names. Watch-listing functions without a criminal charge and audits have repeatedly turned up errors in the underlying data. The US Supreme Court has already ruled against the bureau twice over its use of the list as leverage to recruit informants. FBI 局长卡什·帕特尔(Kash Patel)3 月份告诉国会,该中心的生物识别能力和情报产出实现了两位数的增长。据报道,观察名单上的名字已接近 200 万个。观察名单的运作无需刑事指控,且审计多次发现底层数据存在错误。美国最高法院已两次就 FBI 利用该名单作为招募线人筹码的行为作出不利于该局的裁决。
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorism
俄罗斯指控 Telegram 创始人帕维尔·杜罗夫协助恐怖主义
As Russia continues to increase its control over internet access, including banning apps and running local internet shutdowns, the country has also charged the founder of Telegram, Pavel Durov, with facilitating terrorism. This week, the Russian Federal Security Service issued an international arrest warrant for Durov, saying that Telegram had been used to coordinate sabotage and attacks inside Russia. It also claimed the app had failed to remove content by the “Ukrainian special services, terrorist organizations, and extremist organizations.” 随着俄罗斯继续加强对互联网接入的控制(包括封禁应用程序和实施局部互联网中断),该国还指控 Telegram 创始人帕维尔·杜罗夫(Pavel Durov)协助恐怖主义。本周,俄罗斯联邦安全局对杜罗夫发出了国际逮捕令,称 Telegram 被用于协调俄罗斯境内的破坏和袭击活动。该局还声称,该应用未能删除“乌克兰特种部队、恐怖组织和极端组织”发布的内容。
“Under Russian law, I’m banned from ‘publishing information on the internet,’” Durov posted online following the charge. “根据俄罗斯法律,我被禁止‘在互联网上发布信息’,”杜罗夫在被指控后在网上发文称。