Skip to main content

DHS warns of Chinese infrastructure software vulnerabilities

China Qinshan Nuclear Plant II (under construction)
Image used with permission by copyright holder

The U.S. Computer Response Readiness Team—a part of the Department of Homeland Security—has issued a bulletin (PDF) warning of software vulnerabilities in two software applications widely used in China to help control public utilities, chemical and manufacturing plans, and even weapons systems. The vulnerabilities are classic heap-based buffer overflow errors, the same type of exploit that has been repeatedly leveraged by malware authors for Windows and other operating systems.

If exploited successfully, the flaws could enable attackers to execute arbitrary programming on the systems, or perform a remote denial of service attack. Successful attacks could be highly destructive, shutting down plants and utilities or potentially creating dangerous conditions in chemical or manufacturing facilities that could lead to much larger problems. Exploitation of the problems in weapons systems could be potentially disastrous.

Recommended Videos

The U.S.’s Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) says it has coordinated with NSS Labs researcher Dillon Beresford (who uncovered the problems), as well as Sunway and the China National Vulnerability Database, and patches are available now that address both problems. However, it could take months for industries and operations to install the patches, leaving a potential window of vulnerability where the bugs could be exploited. There are currently no known exploits in the wild.

Sunway applications are mainly used in China, but are also utilized in parts of Asia, Africa, Europe, and the Americas, according to the advisory.

In an era when cyberattacks against corporations and infrastructure are increasingly common, the vulnerabilities highlight the potential risk of Internet based attacks against infrastructure systems. The Sunway software in question is used in supervisory control and data acquisition (SCADA), SCADA systems often control critical infrastructure and manufacturing processes, but were often developed before the Internet became widely available and, in many cases, were never intended to be part of network systems. Although companies have increasingly built Internet-enabled interfaces to SCADA systems, the systems themselves often have never undergone significant security audits.

Last year, the sophisticated Stuxnet worm targeted Siemens WinCC industrial control software in an apparent attempt to hamstring Iran’s uranium enrichment efforts, demonstrating how industrial systems can be vulnerable to Internet-based attacks.

Topics
Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Get a 32-inch 1440p monitor for only $160 with this Amazon deal
The 32-inch KTC H32T13 monitor with a colorful display.

If you've been thinking about finally upgrading your outdated monitor, the good news is that you don't have to spend a lot if you want a great display. The KTC H32T13 is a perfect example of a budget-friendly option, especially now that it's on sale from Amazon with a 20% discount that lowers its price further to $160 from $200. This bargain will only be online for a limited time though, and since most monitor deals as affordable as this one sell out quickly, you should think about hurrying with your purchase if you don't want to miss out on the $40 in savings.

Why you should buy the KTC H32T13 monitor
The KTC H32T13 isn't made by one of the brands you'll see in our list of the best monitors, but it's a nice purchase, as you can see from its high rating of 4.4 out of 5 stars from more than 500 customers. It's a pretty affordable display considering it's 32 inches, which is the upper end of our computer monitor buying guide's recommended size, and with Wide QHD resolution of 2560 x 1440, you'll enjoy stunning visuals with sharp details and bright colors.

Read more
Snap up this LG 27-inch gaming monitor for $126 at Walmart
The LG 27-inch gaming monitor on a white background.

If you’ve just grabbed one of the affordable gaming PC deals going on, don't forget to grab a monitor deal too. Right now at Walmart, you can buy an LG 27-inch UltraGear full HD gaming monitor for $126. That’s a fantastic price for such a large monitor -- even this screen normally costs $159. If you’ve just bought a mid-range or budget gaming PC and you want a good looking full HD screen to pair with it, you’ll be delighted with this option. Let’s take a look at what it has to offer for this great low price.

Why you should buy the LG 27-inch UltraGear full HD gaming monitor
The best gaming monitors are a little different from the regular best monitors, focusing more on high refresh rates and low response times. The LG 27-inch UltraGear full HD gaming monitor has all of that. It has a high refresh rate of 180Hz so it can handle fast-moving action from all your favorite games, from the latest Call of Duty to some fun sessions on Fortnite. There’s no risk of motion blur here. The LG 27-inch UltraGear full HD gaming monitor also has support for AMD FreeSync, which further helps matters.

Read more
AMD says that FSR 4 might not be an RDNA 4 exclusive after all
AMD announcing FSR 4 during CES 2025.

AMD will soon launch new graphics cards, although they were pretty much absent from its CES 2025 keynote. Fortunately, a new interview with Frank Azor, AMD's chief architect of gaming solutions and gaming marketing, gives us a little bit more information. One interesting tidbit from the interview is that FSR 4, currently an RDNA 4 exclusive, might still one day make it to older AMD GPUs.

Azor spoke to Michael Quesada in an interview that was later shared by El Chapuzas Informatico and VideoCardz. They spoke about FSR 4, but also the general price point and the predicted performance of the RX 9070 XT. Throughout the interview, it's made clear that AMD is angling for a value-oriented product this time around.

Read more