More

    Industrial computing systems at risk from “time bombs ” in malicious NuGet packages



    • Socket found nine NuGet packages with delayed sabotage targeting industrial control systems
    • Sharp7Extend can corrupt Siemens S7 PLCs and randomly crash host processes
    • Malicious code activates in 2027–2028; users urged to audit and remove affected packages

    Thousands of critical infrastructure organizations, as well as those working in other, equally important verticals, were targeted by a perfidious attack that sought to sabotage their industrial control devices (ICD) two years down the line, experts have discovered.

    Cybersecurity researchers Socket recently found nine packages on NuGet that contained sabotage payloads set to activate in 2027 and 2028, if certain conditions were met.


    https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-2560-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img