Friday, February 26, 2021
No Result
View All Result
  • PRESS RELEASE
  • ADVERTISE
  • CONTACT
American People News
  • Home
  • News
  • World
  • Politics
  • Defense
  • Business
  • Health
  • Sports
  • Entertainment
  • Technology
  • Lifestyle
  • Travel
  • Home
  • News
  • World
  • Politics
  • Defense
  • Business
  • Health
  • Sports
  • Entertainment
  • Technology
  • Lifestyle
  • Travel
No Result
View All Result
American People News
No Result
View All Result
Home Technology

Government Sites Said to Have Critical Vulnerabilities; NCIIPC and CERT-in Step In: Reports

by American People News
February 22, 2021
in Technology
0
Share on FacebookShare on Twitter


Security researchers said they found thousands of critical vulnerabilities in dozens of government-run Web services, more than half of which reportedly belonged to state governments. Most of the services had multiple issues that included exposed credentials, leaks of sensitive files, and existence of known bugs. If exploited, these lapses could reportedly lead to deeper access within the government network, as per the researchers. The issues had been brought under the notice of the National Critical Information Infrastructure Protection Centre (NCIIPC) earlier this month. Now, a top official from the National Cyber Security Coordinator (NCSC) said that “remedial actions” have been taken.

The details of the compromised services were not made public as a security measure. However, many government departments are still catching up on security measures, particularly at the state level. But obviously, different departments have different threat profiles.

The collective of researchers, who call themselves Sakura Samurai, reached out to the NCIIPC in early February. However, the flagged issues remained unresolved for over two weeks, as per a report by Hindustan Times.

On February 20, Sakura Samurai member John Jackson published a blog detailing the breach and how the US Department of Defense Vulnerability Disclosure Program (DC3 VDP) had to be involved to help the Indian cyber-security wing to take notice. The report suggests that the delay in action could have resulted in bad actors accessing sensitive information and conduct disruptive operations against government servers.

The critical issues found in the government Web services included exposed credentials that could allow unauthorised access for hackers. Apart from that, Jackson and his team wrote that they discovered 35 instances of credentials pairs (that can be used to authenticate to a target), three instances of sensitive files, dozens of police FIRs, and over 13,000 identifiable information instances. Potential lapses were also discovered that could compromise extremely sensitive government systems. Team Sakura Samurai tested gov.in systems as part of the Responsible Vulnerability Disclosure Program (RVDP) run by NCIIPC. RVDP allows developers, researchers, and security professionals to report issues of potential information security risk to companies and countries.

Jackson explained in the blog, “Even though the Indian Government has a RVDP in place, we didn’t feel comfortable disclosing the vulnerabilities right away. The hacking process was far from the standard situation of business-as-usual security research. In total, our report compounded to a massive 34-page report worth of vulnerabilities. We knew that our intent was good, but we wanted to ensure that the US Government had eyes on the situation.”

Sakura Samurai then co-ordinated with the DC3 VDP to assist in facilitating the initial conversations. On February 4, the US body tagged NCIIPC in a tweet, saying, “Check your email and let’s chat.”

Hey @NCIIPC! We have a researcher with some vulnerabilities to disclose that you might be interested in. Check your email and let’s chat. ☎️????

— DC3 VDP (@DC3VDP) February 4, 2021

The NCSC opened a communication channel with Jackson and his team on Sunday. National Cyber Security Coordinator (NCSC) Lt Gen Rajesh Pant told Hindustan Times that necessary actions were taken. “Remedial actions have been taken by NCIIPC (National Critical Information Infrastructure Protection Centre) and Cert-IN (Indian Computer Emergency Response Team)… NCIIPC handles only the Critical Information Infrastructure issues. In this case the balance pertained to other states and departments that were immediately informed by CERT-In. It is likely that some action may be pending by users at state levels which we are checking.”


Does WhatsApp’s new privacy policy spell the end for your privacy? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.





Source link

Tags: CERTinCriticalGovernmentNCIIPCReportsSitesstepVulnerabilities
ShareTweetShare

Related Posts

Technology

Sony winds down Japan Studio to focus on Astro’s Playroom team

February 26, 2021
Technology

Bessemer Venture Partners closes on $3.3 billion across two funds – TechCrunch

February 26, 2021
Technology

DirecTV to become standalone company after AT&T, TPG Capital ink deal

February 25, 2021
Technology

Microsoft is finally hiding the 3D Objects Folder in Windows 10

February 25, 2021
Technology

Your new Mac’s speedy SSD might not last as long as it should

February 25, 2021
Technology

Cloud, data amongst APAC digital skills most needed

February 25, 2021
Load More
  • Trending
  • Comments
  • Latest

Attorney Lin Wood Releases Statement Before Supreme Court Ruling on Election Fraud Today — UPDATED WITH NEW COMMENT

February 19, 2021

2021 Senior Bowl Rosters, Weigh-Ins, and Measurements

January 23, 2021

Myanmar military says it takes charge of country for ONE YEAR, declaring state of emergency over alleged ‘election fraud’ — RT World News

February 1, 2021

Off the California coast, the US Navy tests hunting subs with an aerial drone

January 18, 2021

Democrats Don’t Want Biden To Have Full Control Of Nuclear Weapons

February 24, 2021

Antifa-BLM Organizer Who Stormed US Capitol Is Released from Jail Without Bail

January 16, 2021

Dr. Fauci Backtracks on Wearing Multiple Face Masks After Pushing It Just One Week Ago

January 31, 2021

Democrats Are Drafting Legislation to Criminalize Trump Rallies — Classify Them as “Domestic Terrorism”

January 11, 2021

Global Bond Selloff Eases; Asian Stocks Slump: Markets Wrap

0

Vigilante win Epic Games, Unreal Grant for Model Library Creation

0

DSET 2021 Announces Tech Sponsor

0

Demand for Cyber Threat Intelligence experts forces companies to widen search and increase salaries 

0

CREST International and CMMC Center of Excellence Announce Memorandum of Understanding

0

HUBER+SUHNER UK division receives Supply Chains for the 21st Century Bronze Award for operational excellence

0

Just Less Than 2 weeks to Go Until SMi Group’s 22nd Annual Global MilSatCom Virtual Conference & Exhibition

0

UKCloud awarded MOD Silver Award extending its commitment to building digital skills in the UK

0

Global Bond Selloff Eases; Asian Stocks Slump: Markets Wrap

February 26, 2021
[VIDEO] A Clearly Unnerved McConnell Just “Bowed” to President Trump on Live TV

[VIDEO] A Clearly Unnerved McConnell Just “Bowed” to President Trump on Live TV

February 26, 2021

Russian diplomats leave by hand-pushed trolley

February 26, 2021

India GDP: India looks set to beat recession even as new virus cases loom

February 26, 2021

Rockets, Cavaliers, Thunder Considered NBA’s Only True Sellers Entering Deadline Period

February 26, 2021

SVU’ Crossover Unites Elliot, Olivia: Promo

February 26, 2021

L.A. County COVID-19 hospitalizations hit three-month low while MIS-C cases climb

February 26, 2021

Biden launches airstrikes against Iran-backed militias in Syria to “send a message”

February 26, 2021
American People News

Get the latest news and follow the coverage of breaking news, local news, national, politics, and more from the world's top trusted sources.

Browse by Category

  • American Football
  • Baseball
  • Basketball
  • Business
  • Defense
  • Entertainment
  • Health
  • Ice Hockey
  • Lifestyle
  • Politics
  • Soccer
  • Sports
  • Technology
  • Top News
  • Travel
  • World

Recent News

Global Bond Selloff Eases; Asian Stocks Slump: Markets Wrap

February 26, 2021
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact

Copyright © 2020 American People News.

No Result
View All Result
  • Home
  • News
  • World
  • Politics
  • Defense
  • Business
  • Health
  • Sports
  • Entertainment
  • Technology
  • Lifestyle
  • Travel

Copyright © 2020 American People News.