{"id":3414,"date":"2024-05-03T16:07:51","date_gmt":"2024-05-03T21:07:51","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps"},"modified":"2024-05-03T16:07:51","modified_gmt":"2024-05-03T21:07:51","slug":"paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/03\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps\/","title":{"rendered":"Paris Olympics Cybersecurity at Risk via Attack Surface Gaps"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte77d98cbadf7bbab\/6635318936036759aa6d0ac9\/olympics_Svet_fotos_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Web applications and other Internet-facing assets related to the 2024 Summer Olympics in Paris appear to be better protected against cyberattacks than previous major sporting events, such as the 2022 FIFA World Cup in Qatar.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But a few gaps persist that could prove troublesome, given the enormous interest in the event among hacktivists, cybercriminals, nation-state groups, and other attackers. During the 2021 Olympics in Japan, for instance, such bad actors launched a startling 450 million attacks on online infrastructure related to the Games.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Troubling Olympics Security Gaps\">Troubling Olympics Security Gaps<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers at Outpost24 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.businesswire.com\/news\/home\/20240502415930\/en\/Urgent-Cybersecurity-Risks-Identified-in-Paris-2024-Olympic-Games-Online-Infrastructure-by-Outpost24\" rel=\"noopener\">recently mapped the entire Internet-facing footprint<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> associated with the 2024 Olympic Games. This included looking at all domains, subdomains, hosts, Web applications, and third-party cloud resources. Their evaluation concluded that the Olympics&#8217; external attack surface is more secure against compromise compared to what they discovered when performing a similar assessment before the 2018 FIFA World Cup soccer games in Russia.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The gaps they found in the Olympics&#8217; infrastructure included a handful of open ports, SSL misconfigurations, security header issues, domain squatting, and some privacy issues like cookie consent violations. The issues give threat actors an opportunity to break through what otherwise appears to be a relatively well-protected attack surface, says Stijn Vande Casteele, CSO of Outpost24\u2019s external attack surface management group.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When attackers find a website with an expired certificate or returning a 404 error indicating a broken URL, for instance, they are likely to enumerate them for other flaws.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Not having basic IT and cyber hygiene under control draws the attention [of attackers] and could indicate potentially more severe opportunities for threat actors&#8221; to explore, Vande Casteele says. Similarly, the domain squatting issues that Outpost24 discovered could portend an uptick in Olympics-themed phishing campaigns for credential theft and other malicious reasons.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The Olympic Games are a high-profile event and the biggest sport competition in the world,&#8221; says Vande Casteele. It presents an enormous target for attackers. &#8220;As an organization, you want to discourage them by running a tight, super-secure digital footprint.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Vande Casteele says the Paris 2024 Olympics organization operates more than 700 domains and 800 external Web applications residing on more than 16 different cloud providers. Systems connected to the Games currently are located across nine different countries in the EU, Asia, and North America.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;[Given] the volatility and dynamic character of an attack surface with this complexity, keeping all of this on the radar is a real challenge for the organization&#8217;s risk and security stakeholders,&#8221; he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cyber a Top Concern\">Cyber a Top Concern<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybersecurity is a top-of-mind concern among Olympics officials in France, just as it has been for organizers of other major sporting events, such as the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/super-bowl-lviii-vast-attack-surface-threat-actors\" rel=\"noopener\">Super Bowl<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a recent article, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.politico.eu\/article\/france-paris-olympics-emmanuel-macron-terror-security\/\" rel=\"noopener\">Politico<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> described France&#8217;s primary cybersecurity agency \u2014 ANSSI \u2014 as starting preparations for the event two years ago and, among other things, conducting extensive penetration tests and awareness-raising campaigns. The director of ANSSI told Politico the goal is not to block 100% of the attacks that are sure to happen when the Games begin, but to block most of them. Officials do not want a repeat of what happened at the 2018 Winter Olympics in Pyeongchang, South Korea, when suspected Russian attackers used a malware tool dubbed &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/olympic-destroyer-s-false-flag-changes-the-game\" rel=\"noopener\">Olympic Destroyer<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8221; to massively disrupt Wi-Fi and other communication services during the opening ceremony.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Also of concern is the threat of a coordinated terror and cyberattack to take out crucial security and surveillance systems around the Games. During the 2021 Olympics in Tokyo, threat actors launched a staggering 450 million attacks at various Games-related targets. In comments to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nytimes.com\/2024\/04\/16\/world\/europe\/paris-olympics-cyberattacks.html\" rel=\"noopener\">The New York Times<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> earlier this month, Franz Regul, the individual responsible for cybersecurity at the Olympics, said his team expects to face between eight and 12 times that number of attempts at this year&#8217;s Games.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As part of their preparations for the attacks, Regul&#8217;s team has conducted numerous war games in collaboration with technology partners and analysts at the International Olympic Committee. They also have put in a place bug bounty program that rewards researchers who find exploitable vulnerabilities in the technology infrastructure supporting the Games, the Times reported.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Diverse, Sophisticated, and Persistent\">Diverse, Sophisticated, and Persistent<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s anybody&#8217;s guess how effective these measures will be once the Games start. Steven Baer, vice president, field sales and services at NetWitness, fully expects the cybersecurity team at the Paris Olympics will have implemented a course of action and an attack kill chain to stop and contain known threats as they happen. Their threat intelligence efforts would likely be focused on new and emerging trade craft, and incident response teams will be standing by and ready to swing into action when needed, says Baer, whose company played a role in helping secure the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/how-the-2022-qatar-world-cup-soccer-was-nearly-hacked\" rel=\"noopener\">2022 FIFA World Cup soccer games<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in Qatar.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I would anticipate that the cybersecurity threats targeting the 2024 Olympics&nbsp;in Paris&nbsp;will be diverse, sophisticated, and persistent,&#8221; Baer adds. &#8220;I would expect to see cyberattacks aimed at stealing sensitive data, disrupting critical infrastructure, sabotaging operations, extorting money, or spreading propaganda and misinformation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The Games are a prime opportunity for cybercriminals, nation-state actors, hacktivists, and terrorists to exploit the vulnerabilities of a high-profile event&nbsp;with a global audience.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Geopolitics is another factor, says Vande Casteele. The Israel-Palestine conflict and the war between Russia and Ukraine both will likely influence the nature of threats that state-sponsored cyber actors present to the Games. &#8220;It is worth highlighting, for instance, that Russia has been banned from this edition of the Games, which inherently poses a significant threat to the host and the Olympics&#8217; [infrastructure],&#8221; Vande Casteele says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Phishing campaigns targeting the general public, DDoS attacks on organizations, and espionage against high-profile individuals\/institutions are other common occurrences during high-profile events like the Olympics, he says. &#8220;One thing is certain: These events enlarge the attack surface and provide the perfect timing for attacks, be they politically or financially motivated.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Vande Casteele likens the challenges associated with securing the constantly changing digital footprint of the Olympic Games to building and keeping a gigantic house secure in a relative short period of time.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Every day new floors are added, windows and doors are created,&#8221; he says. &#8220;Many different people are involved, so after a while they lack the oversight, and they forget how many windows and doors there are.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Web applications and other Internet-facing assets related to the 2024<\/p>\n","protected":false},"author":12,"featured_media":3415,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3414","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?fit=1000%2C750&ssl=1",1000,750,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?fit=300%2C225&ssl=1",300,225,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?fit=640%2C480&ssl=1",640,480,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?fit=640%2C480&ssl=1",640,480,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?fit=1000%2C750&ssl=1",1000,750,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?fit=1000%2C750&ssl=1",1000,750,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?fit=1000%2C750&ssl=1",1000,750,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps.jpg?fit=1000%2C750&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3414"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3414\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3415"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}