logoalt Hacker News

anonymousiamyesterday at 11:08 PM1 replyview on HN

What I heard about the Stuxnet attack was different from what you are saying:

The enrichment facility had an air-gapped network, and just like our air-gapped networks, they had security requirements that mandated continuous anti-virus definition updates. The AV updates were brought in on a USB thumb drive that had been infected, because it WASN'T air-gapped when the updates were loaded. Obviously their AV tools didn't detect Stuxnet, because it was a state-sponsored, targeted attack, and not in the AV definition database.

So they were a victim of their own security policies, which were very effectively exploited.


Replies

NicolaiStoday at 11:55 AM

Do you have any sources that the infected USB contained AV updates?

I can't find any sources saying that..