[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhwOdLbt1XoUMlotep_Ehbwq68XWqwcXUSXLXBmcthk4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"17ef3e5d-f16f-452d-8c8a-bc4cbc401c31","critical-infrastructure-attacks-target-weak-authentication-in-fuel-systems","5986a8a9-a232-4e32-ab2b-736928a78b9c","Critical Infrastructure Attacks Target Weak Authentication in Fuel Systems","Threat actors are exploiting fundamental security weaknesses in automatic tank gauge systems, including authentication bypass vulnerabilities, hardcoded credentials, and command execution flaws. These attacks demonstrate how poor access controls on internet-facing industrial systems can allow attackers to manipulate critical infrastructure operations, potentially affecting fuel supplies and safety systems. The targeting of these systems highlights the intersection of cybersecurity and physical safety, where compromised digital controls can lead to real-world consequences including environmental hazards from disabled leak detection systems.","**Immediate actions:**\n- Remove ATG systems from direct internet exposure or place behind VPN\u002Fsecure remote access\n- Change all default and hardcoded credentials on existing systems\n- Apply available security patches for authentication and command execution vulnerabilities\n\n**Long-term improvements:**\n- Implement network segmentation to isolate operational technology from corporate networks\n- Deploy continuous vulnerability scanning for all internet-facing industrial control systems\n- Establish multi-factor authentication for all remote access to critical infrastructure systems\n\n**Detection measures:**\n- Enable logging and monitoring for all configuration changes and administrative commands\n- Set up alerts for unauthorized access attempts and unusual system behavior\n- Implement baseline monitoring to detect tampering with tank volumes and safety alerts",[12,13,14,15,16,17,18,19],"CIS Control 4","CIS Control 11","CIS Control 12","NIST AC-2","NIST AC-3","NIST RA-5","ICS-CERT Guidelines","NERC CIP-005","published","2026-06-03T22:07:37.400528+00:00","2026-06-03T22:07:37.32+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcisa-warns-of-cyberattacks-targeting-fuel-tank-monitoring-systems\u002F","cisa-warns-of-cyberattacks-targeting-fuel-tank-monitoring-systems-8bf5d5","CISA warns of cyberattacks targeting fuel tank monitoring systems",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]