CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

  • A_Random_Idiot@lemmy.world
    link
    fedilink
    English
    arrow-up
    34
    ·
    22 hours ago

    why is any critical control equipment internet accessible.

    I understand some machines might need internet to send reports and make document filings and shit. But it should not be the critical control equipment that makes the system function. And there should be a massive physical gap between the internet machines and the critical machines.

    Jesus christ, even by the abysmally low bar I have for humanity, it still finds ways to dig itself a path under it.

    • Uriel238 [all pronouns]@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      6
      ·
      15 hours ago

      The entire tech sector screamed about the vulnerability of IoT devices, plenty of which are now participants in zombie botnets.

      Does anyone remember in 2015 when YESCO billboards by the thousands were hacked to show Goatse instead of an AT&T ad? Pepperidge Farm remembers. IoTs are still vulnerable, including big municipal ones and, yes, Flock Safety cameras.

      And CISA was severely broken had its staff severely reduced by DOGE.

      In unrelated news the CDC, also a victim of DOGE, is entirely unprepared for the next epidemic.