Department of Homeland Security USA Warns ERP Giants of Impeding Cyber Attack

US Department of Homeland Security (DHS) warns users against ERP Attack

Department of Homeland Security of America has warned users against impending cyber attacks on ERP (Enterprise Resource Planning) systems.
Homeland security is a US based national security that ensures that the area of the country within the national boundary is safe, secure and resilient against terror attacks.
The basis of this warning is the report published by Threat Intelligence firms that depicts that there has been a sudden surge in the interest of the hackers to target ERP systems who may use both hacking and DDoS (Distributed denial of Service) attacks to carry out disruption and compromise these high-value assets.
Attacks of this nature were first warned in May 2016 when the exploitation on 36 global organizational institutions was suspected through the abuse of the seven year old vulnerability in SAP applications.

What is ERP? Why cyber criminals target ERP systems?

ERP (Enterprise Resource Planning), is referred to as business management software that enables collection, management, storing, and interpretation of various aspects of business such as finances, customer accounts, finances, HR issues, product distribution, sales etc.
ERPs are web-based applications that use 3 different types of deployments – Cloud, On-Premise, Hybrid, Cloud ERP suite being the prominent among all for large companies and their subsidiaries.
Reason for ERP being a prominent target among the intruders is the data depth and richness of business related information ERP servers holds. Vast majority of large organizations have implemented from vendors such as Oracle or SAP. They rely on the products of these renowned ERP platforms like SAP Business Suite, SAP S/4 HANA and Oracle E-Business Suite/Financials to support business processes. As these processes hold important business information such as inventory, management, manufacturing, sales, logistics, billing, credit cards and Personally Identifiable Information (PII) from employees among other sensitive information, breaching ERP servers would be a feast for cyber criminals.

New Research Findings

ERP applications are being exploited by cyber criminal organizations, leveraging old vulnerabilities and acquiring SAP-HANA specific exploits. These include:
  • According to the researches, there has been a 100% surge in publicly available three years old exploits for SAP and Oracle RP applications.
  • From 2016 to 2017, ERP- specific vulnerabilities have seen an increase of 160%.

Expanding ERP attack Surface:


Read Full News :- Click hear

Comments

Popular posts from this blog

How to remove Speedtest-guide.com redirect from your system

The novel DNS protocol helps Mozart Malware evade detection

How to remove ZUpdater.exe Trojan from your system?