According to a blog post from IT security company Palo Alto Networks, a new variant of the IoT/Linux botnet Tsunami, which it calls Amnesia, targets an unpatched remote code execution vulnerability that was publicly disclosed over a year ago in DVR devices manufactured by TVT Digital and branded by over 70 vendors worldwide.
This vulnerability affects approximately 227,000 devices around the world with Taiwan, the US, Israel, Turkey, and India being the most exposed. IT security experts from Cylance and Positive Technologies comment below.
Jim Walter, Senior Researcher at Cylance:
Alex Mathews, Lead Security Evangelist at Positive Technologies:
“But new malware like Amnesia / Tsunami requires more security measures. First, you have to update the firmware to the safer version. Unfortunately, in many cases the manufacturers cannot provide security updates in time. Another problem is, common users just don’t know how to update different IoT devices like DVRs or wi-fi routers: these devices don’t have a simple interface like a common notebook does.
“So the best security advice here would be to limit the access to the IoT device (and from it) to certain IP addresses only (admins). Or you can place your DVRs in an isolated / firewalled network.”
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.