A flaw was found in popular software that’s used to manage processes in industries from manufacturing to energy.
The bad news: Researchers at Tenable, a security firm, found a serious bug in code from Schneider Electric, which has issued a fix after being given a heads-up about the problem. The flaw leaves the software vulnerable to a “buffer overflow attack.” Computer programs allocate set amounts of memory—or buffers—to hold data they’re working on. The attack pumps more data into a buffer than it’s designed to hold; the overflow corrupts memory nearby, letting hackers introduce malicious code there that can take control of servers and other systems.
The (slightly) better news: The attack worked with software running on Windows 7; more modern operating systems have built-in protections that make it much harder. That’s no reason to be complacent, though, because many industrial control systems with older OSes are still being hooked up to the internet.
Why this matters: Code governing control systems at industrial sites has already been the target of attacks, and US officials recently warned Russian hackers are probing for security holes in software controlling critical infrastructure like nuclear facilities and dams.
What’s next for the world’s fastest supercomputers
Scientists have begun running experiments on Frontier, the world’s first official exascale machine, while facilities worldwide build other machines to join the ranks.
The future of open source is still very much in flux
Free and open software have transformed the tech industry. But we still have a lot to work out to make them healthy, equitable enterprises.
The beautiful complexity of the US radio spectrum
The United States Frequency Allocation Chart shows how the nation’s precious radio frequencies are carefully shared.
How ubiquitous keyboard software puts hundreds of millions of Chinese users at risk
Third-party keyboard apps make typing in Chinese more efficient, but they can also be a privacy nightmare.
Get the latest updates from
MIT Technology Review
Discover special offers, top stories, upcoming events, and more.