U.S. NIST's vulnerability database hacked
The agency says it pulled down two Web servers when malware was discovered
IDG News Service - A U.S. government computer vulnerability database and several other websites at the National Institute of Standards and Technology have been down for nearly a week after workers there found malware on two Web servers.
NIST's National Vulnerability Database (NVD) website, which includes databases of security checklists, security-related software flaws and misconfigurations, is one of the sites affected, a NIST spokeswoman said in an email.
Last Friday, a NIST firewall "detected suspicious activity and took steps to block unusual traffic from reaching the Internet," said spokeswoman Gail Porter. "NIST began investigating the cause of the unusual activity and the servers were taken offline."
The National Vulnerability Database is a comprehensive repository of information that allows computers to conduct automated searches for the latest known vulnerabilities in hardware or software computing products, Porter said.A The goal of the NVD is to help organizations and individuals better protect their computers against security threats.
Many government agencies and private businesses use the database, she said.
NIST traced the malware on two servers to a software vulnerability, she said.
The agency does not see any evidence that the NIST websites "were used to deliver malware to users of these NIST Web sites," Porter added.
NIST will restore the servers as soon as possible, she added.
Security professional Kim Halavakoski found the database was down when he went to the website to get some vulnerability information, he said in a Google+ post late Wednesday.
"Hacking the NVD and planting malware on the very place where we get our vulnerability information, that is just pure evil!" he wrote.
Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Security for Virtualization Learn more.
- When Malware Goes Mobile: Causes, Outcomes and Cures Cybercriminals are increasingly setting their sights on smartphones and other mobile devices. Learn about platform-specific policies and strategies you can employ to protect...
- Top Three Reasons Why Customers Deploy EMC VNX with EMC VPLEX What if you could build a cost effective, continuously available storage infrastructure? Learn the top reasons users are deploying EMC VNX with EMC...
- Clearing the Clouds for Midmarket Businesses The 10-point checklist included in this expert brief has been developed to help small and midsize businesses select the cloud model and cloud...
- Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud How can public cloud services help your organization reduce costs and increase security for your mission
- Williams & Fudge on Transforming IT with EMC Watch Williams & Fudge Data Center Director Phillip Reynolds discuss why this accounts receivable management firm turned to EMC. All Malware and Vulnerabilities White Papers | Webcasts