Security News > 2022 > March > CISA warns of attacks targeting Internet-connected UPS devices

In a joint advisory with the Department of Energy, the Cybersecurity and Infrastructure Security Agency warned U.S. organizations today to secure Internet-connected UPS devices from ongoing attacks.
UPS devices are regularly used as emergency power backup solutions in mission-critical environments, including data centers, industrial facilities, server rooms, and hospitals.
They're also connected to the Internet to allow admins to perform various remote tasks such as power monitoring and routine maintenance, which also exposes them to attacks.
"Organizations can mitigate attacks against their UPS devices, which provide emergency power in a variety of applications when normal power sources are lost, by removing management interfaces from the internet."
If connecting their management interfaces to the Internet cannot be avoided, admins are advised [PDF] to put the devices behind a virtual private network, enable multifactor authentication, and strong passwords or passphrases to hinder brute-forcing attempts.
Threat actors can also use critical security vulnerabilities to enable remote takeovers of uninterruptible power supply devices and allow them to burn them out or disable power remotely.
News URL
Related news
- CISA tags SonicWall VPN flaw as actively exploited in attacks (source)
- CISA tags Broadcom Fabric OS, CommVault flaws as exploited in attacks (source)
- CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs (source)
- CISA says SaaS providers in firing line after Commvault zero-day Azure attack (source)
- CISA warns of ConnectWise ScreenConnect bug exploited in attacks (source)