CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.
The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.
Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.
I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency



I am repeating what I said elsewhere on a different comm:
I call FULL bullshit on this being Iran.
I personally worked on the cybersecurity incident that happened to St Paul municipal and water systems last year as the Incident Response Technical lead.
The threat actors were not Iranian then. They were Russian.
I personally rebuilt most of their networks, VMware hosts, storage, and servers. The majority of the VMware environments did not have config backups and were running 5 and 6 branches of VMware, only two had 7+.
Their network was insecure. They had IPSEC VPNs between the various location, but there was no further security in that respect. Their firewalls were not being kept up. AAAAND… I warned them that we thought they were still compromised.
In fact, the forensics team called them out as being clean on a group call one week into the incident, but while we were on the call with leadership, they got RE-infected.
I had my team compile a massive set of recommendations for them and I wrote the report. Water Systems specifically. They did not listen to us, apparently. The forensics team also did this.
They had FBI, national guard (fucking incompetent), and law enforcement (useless) in all meetings.
If they got into Water, they’ll get back into city and municipal again. I guarantee it.
This is not Iran. It’s the fucking incompetence of city government and Russian threat actors.
Minor nit: Russia and Iran are already working together on shaheds and targeting
No surprise at all if they also coordinate cyber
Whatever. I worked the fucking case. The infiltrators were Russian. After that, it’s a political or financial negotiation.
No doubt so trump can make up some bullshit excuse to try to suspend the midterms.
We already know he’s going to try, I hate how obvious this shit is from a thousand miles away, but still nothing is done about it.
If budget weren’t an issue, how many clones of your teams would it take to do that for all the water systems in the US in five years?
What are the odds that the average muncipality understands the security implications of just existing on the internet these days?
10 people per site, per incident, at 50-70 hours/week.
It’s thankless work and the people in control don’t typically take on contractors. They underpay the actual IR staff. That’s why I left the industry. It’s a big buddy-system network. Really fucked.
So to sweep all of the water systems in the country in advance isn’t doable in any time frame?
IR isn’t an acronym I’m familiar with.
Incident response, basically getting pulled in to clean up someone else’s fuck up that got them owned.