meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Knocking down the legs of the industrial security triad. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

News, Tech News, Daily News, Technology

4.81.1K Ratings

🗓️ 11 February 2023

⏱️ 19 minutes

🧾️ Download transcript

Summary

Pascal Ackerman, OT Security Strategist from Guidepoint Security, joins Dave to discuss his work on discovering a vulnerability in the integrity of common HMI client-server protocol. This research is a Proof of Concept (PoC) attack on the integrity of data flowing across the industrial network with the intention of intercepting, viewing, and even manipulating values sent to (and from) the HMI, ultimately trying to trick the user into making a wrong decision, ultimately affecting the proper operation of the process. In this research, they are targeting Rockwell Automation’s FactoryTalk View SE products, trying to highlight the lack of integrity and confidentiality on the production network and the effect that has on the overall security of the production environment. The research can be found here: GuidePoint Security researcher discovers vulnerability in the integrity of common HMI client-server protocol Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire Network, powered by N2K.

0:07.0

Today's episode is sponsored by SRM, your first call for cybersecurity and

0:18.1

investigations. Threats today are evolving faster than ever before and since 2005 SRM has pioneered

0:25.3

tailored security solutions for global corporations and their executives.

0:29.5

Whether it's defending against cyber attacks with their award-winning team of ethical hackers and incident response specialists,

0:36.4

or navigating the murky waters of compliance and ESG challenges,

0:40.9

SRMs, Insight and Straight straightforward advice will help you navigate complex risks

0:46.4

and emerge more resilient.

0:48.4

Their secret, a culture that nurtures the sharpest minds, giving them access to the newest technologies and the freedom

0:55.3

to solve problems in new ways, enabling them to craft simple effective solutions for your

1:01.4

unique cyber challenges.

1:03.7

Search your first call to discover how SRM can help your business. Hello everyone and welcome to the CyberWire's research Saturday.

1:27.0

I'm Dave Bitner and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities,

1:34.1

solving some of the hard problems of protecting ourselves in a rapidly evolving cyberspace.

1:39.7

Thanks for joining us. Pretty much industrial control systems are all around us, right?

1:51.0

Everything we touch is either directly controlled by one of these systems or it's

1:56.0

fabricated by one of these systems. So an industrial control system is a bunch of peripherals that

2:02.2

combined make a product or ship a good or a service to somebody.

2:07.0

That's Pascal Ackerman. He's a senior security consultant forational Technology and Threat and Attack Simulation

2:15.0

at Guidepoint Security.

2:17.0

The research is titled Guidepoint Security Researcher discovers vulnerability in the

2:21.4

integrity of common HMI client server protocol.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.