Overall Alerts


Computer Network Defence Overall Alert State

 

secwiz blankback cro tp

The Computer Network Defence Overall Alert State is designed to give a general overview of the state of CyberSecurity at a brief glance.  The definitions below will give an idea of the criteria considered when setting the status.  Occasionally we may add an additional Alert State for a specific topic, should the situation warrant.

 

                                           

Current Alert State

Guarded
Overall

 


17 September, 2018 - Reduced Overall Alert to Guarded.
12 September, 2018 - Raised Overall Alert to Increased due to Patch Tuesday, patched 0-days, and other public exploits being patched.  There's just a lot going on.

2018 Overall Alert History

20 August, 2018 - Reduced Overall Alert to Guarded after appropriate patch time.
15 August, 2018 - Raised Overall Alert to Increased due to Microsoft 0-day patches in Patch Tuesday. More info.
- - - -

22 March, 2018 - Overall Alert State reduced to Guarded after a few quiet days.
19 March, 2018 - Overall Alert State set to Increased based on increasing cyber security concerns between Russia and the UK, and Russia and the US.
The UK National Cyber Security Centre (NCSC) put the National Grid on alert.  More info
US-CERT detailed report on "Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors" here.
- - - -

05 February, 2018 - Overall Alert State returned to Guarded, patches are expected for the Adobe Flash 0-day this week.
02 February, 2018 - Overall Alert State set to Increased based on AutoSploit and an Adobe Flash Player 0-Day both hitting just before the weekend.
- - - -

09 January, 2018 - Overall Alert State returned to Guarded, patches are still rolling out but everyone pretty much has a plan.
04 January, 2018 - Overall Alert State set to Increased based on Meltdown and Spectre affecting all modern processors.

2017 Overall Alert History

29 June, 2017 - Overall Alert State returned to Guarded, Petya has run it's course for the most part, and it is in post-analysis and recovery stage.
27 June, 2017 - Overall Alert State set to Increased based on Petya ransomware reported effect in Eastern Europe, and the potential for similar issues across multiple industries.
- - - -

15 May, 2017 - Overall Alert State set back to Guarded, based on little news about further spread of ransomware, and the availability of patches and procedures to stop the spread.
12 May, 2017 - Overall Alert State set to Increased based on WannaCry ransomware reported effect on Healthcare Infrastructure, and the potential for similar issues in other Infrastructure systems.
17 April, 2017 - Overall Alert State set back to Guarded.
12 April, 2017 - Overall Alert State set to Increased to bring notice to the Microsoft and Adobe Patch Days.

 

                                           

 

Current Subject Alert States

   

Increased
US:Iran

 

13 August, 2018 - Created Subject Alert for US:Iran based on expected Iranian response to US sanctions.  Given the quantity of ICS/SCADA, Building, and Infrastructure alerts we have posted lately, the attack surface is broad in several areas.  More info.

Historical Subject Alert States Details

  

VPNFilter - May-June 2018

 

High
VPNFilter

 

20 June, 2018 - Removed Subject Alert, no new news, everyone that cares already knows.
18 June, 2018
- Lowered state to Guarded, there has been no new coverage since 12 June, except that SMBs aren't heeding the warnings.
07 June, 2018
- Raised back to High, based on Talos research group's latest report that the malware hits more brands, and can infect endpoints.  More info.
06 June, 2018 - Lowered state to Increased, based on waning news coverage.
05 June, 2018 - More News Coverage.  VPNFilter continues to target the Ukraine (more info).
29 May, 2018 - FBI has taken control of C&C domain toknowall.com, and is asking everyone to reboot their routers.  More info.
24 May, 2018
- Raised a Subject Alert State for VPNFilter and set it at High.  Cisco Talos is warning of a sophisticated modular malware system known as VPNFilter.  They estimate the number of infected devices to be at least 500,000 in at least 54 countries. The known devices affected by VPNFilter are Linksys, MikroTik, NETGEAR and TP-Link networking equipment in the small and home office (SOHO) space, as well at QNAP network-attached storage (NAS) devices. Note Cisco is not in this list.  Research is not complete, but risks are high.  More info.

 

Iran:USA - May 2018

 

Increased
Iran:USA

 

24 May, 2018 - Removed Subject Alert
23 May, 2018 - Reduced Subject Alert State to Guarded.  Let's see what happens...
11 May, 2018 - Subject Alert State modified to Iran:USA based on the idea that cyber activity will increase as a result of US sanctions.
     https://www.recordedfuture.com/iran-hacker-hierarchy/
11 May, 2018 - Subject Alert State added and set to Increased for Israel:Iran.  Expect increased cyber activity.

 

US, UK, France - Apr/May 2018

Russia:UK - March/April 2018

  

Increased
Russia:UK

 

16 April, 2018 - Removed subject alert.
26 March, 2018 - Subject Alert State reduced to Guarded after a few more quiet days.
22 March, 2018 - Subject Alert State reduced to Increased after a few quiet days.
19 March, 2018:  Subject Alert state for Russia:UK raised to High.  The UK National Cyber Security Centre (NCSC) put the National Grid on alert.  More info.
UPDATE:  Russia said they had no motive for the attack on Sergei Skripal and his daughter.  PM May to "announce measures".  More info.
16 March, 2018:  US has issued sanctions in support of the UK and in response to reports that Russia is responsible for cyberactivity targeting US Infrastructure.  More info.
13 March, 2018 - Subject Alert State for Russia:UK set to Increased based on escalating tensions between Russia and the UK.  Following the Weapon of Mass Destruction attack on the UK mainland, allegedly by Russia, the UK have given Russia until midnight (GMT) on 13 March to respond.  UK media are speculating that the likely response from the UK will be a cyber attack against Russia.  More info.


Russia:US CNI - March 2018

Increased
Russia:US CNI

 

23 March, 2018 - Subject Alert State removed.
22 March, 2018 - Subject Alert State reduced to Guarded after a few quiet days.
19 March, 2018:  Subject Alert created for Russia:US CNI and set to Increased.  US-CERT detailed report on "Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors" here.

  

APT on Critical Infrastructure - Oct 2017

Increased
APT for Critical Infrastructure

 

23 Oct, 2017 - Subject Alert State for APT for Critical Infrastucture set to Increased based on CERT report of advanced persistent threat (APT) actions targeting government entities and organizations in the energy, nuclear, water, aviation, and critical manufacturing sectors.  More info.

BlackHat/Broadcom Wi-Fi - July 2017

 

Increased
BlackHat

 

30 July, 2017 - Subject Alert State for BlackHat removed, since BlackHat and DefCon are over.
24 July, 2017 - Subject Alert State for BlackHat set to Increased based on Broadcom Wi-Fi chipset vulnerabilities and the upcoming BlackHat presentation.  Both Apple and Google have addressed this in recent updates for iOS, Boot Camp, and Android.  Apple's bulletins for iOS and Boot Camp, Google's bulletin for Android.

Petya Ransomware - June 2017

 

Increased
Ransomware

 

30 June, 2017 - Removed the Subject Alert, we all know about it and the myriad of ideas around it.
29 June, 2017 - Subject Alert State set to Increased, Petya has run it's course for the most part, and it is in post-analysis and recovery stage.  Some wariness is still required, and patch, patch patch!
27 June, 2017 - Created a Subject Alert state for Ransomware set to High, based on fast spreading infections of a ransomware called "Petya".  Starting in Eastern Europe, and hitting financial and infrastructure hard.  The ransomware uses the Microsoft SMB vulnerability as WannaCry.

Windows - April 2017

 

Guarded
Windows

 


17 April, 2017 - Subject Alert for Windows removed.
13 April, 2017 - Set to Increased, since updates should be rolling...
12 April, 2017 - A Subject Alert for Windows was added and set at High, to highlight the patch for the Office and WordPad 0-day announced a few days ago.  Exploitation of this issue has increased, indicating a need to patch quickly.  Also, Vista is now officially EOL, with no new security updates.

 

WannaCry Ransomware - May 2017

 

Increased
Ransomware

 

16 May, 2017 - Removed, nothing left but the patching...
15 May, 2017 - Lowered to Guarded with little new reporting
13 May, 2017 - Lowered to Increased based on the registration of the domain that acted as a kill switch, and Microsoft publication of patches for unsupported versions of the software.
12 May, 2017 - Raised to High based on the pace of infections...
12 May, 2017
- Created a Subject Alert state for Ransomware set to Increased, based on fast spreading infections of a ransomware called "WannaCry".  ISPs, Hospitals, and Energy Infrastructure companies are among the victims.  The ransomware uses a Microsoft SMB vulnerability patched in March, 2017.  More info here and here.

 

                                                                                                                                        

Overall Alert Definitions

Guarded
Overall

GUARDED This is the lowest envisaged Alert State for the foreseeable future.
Remain vigilant and be prepared for attack. There are no discernible issues impacting end networks or the infrastructure of the Internet.

UK Military Terminology – Stand Down
Civilian Terminology – Chillax

Increased
Overall

INCREASED There is unrest in cyber space requiring increased vigilance for possible cyber disruption, such as:

  • Several severe vulnerabilities across multiple platforms (eg Patch Tuesday)
  • Increased political unrest or International hostilities between Nation States which may result in indiscriminate cyber attacks and watering hole acquisition to build botnets.
  • There is a new attack vector which is taking hold and may require mitigation but not yet raising too much cause for concern.

UK Military Terminology – Stand To
Civilian Terminology – Keep Calm and Carry On

High
Overall

HIGH There is a marked escalation in cyber attacks and actual effect, security staff should align their security posture to mitigate the threat and exercise possible use cases relating to the threat, the threats might include:

  • Significant degradation of the Internet infrastructure, such as loss of backbones, DDoS, DNS etc.
  • Several significant vulnerabilities which are being actively exploited and/or proving difficult to mitigate.
  • Malware which is spreading quickly and causing significant issues.
  • Outbreak of Cyber hostilities between Nation States, those nations involved go to Critical Alert State

UK Military Terminology – Watch and Shoot
Civilian Terminology – Wake Up and Smell the Coffee

Critical
Ukraine&Russia

CRITICAL There is a direct cyber threat which will impact the majority of systems and significantly hamper IT operations, this Alert State will be used sparingly.

Where the Critical Alert State can be localised, by Product Type, Attack Vector, Threat Actor or Nations, these will be reflected in the sub heading as per the example shown.

Military Terminology – Incoming, Take Cover
Civilian Terminology – OMG!

Return to the top of the Overall Alerts Page

 

Go to the Radar Page                                                 cndlogo 150x150

 

http://www.ubuntu.com/usn/usn-1215-1/