[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvFtlzy7IUbqyidOsdEE-OCipS5afYkU-LWY448hpmZU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"4c97bb2f-09e0-4aaf-b1f4-6428f499c05e","internet-exposed-plcs-in-water-utilities-under-active-attack","fe814887-fe89-4c85-81e9-a581253e8132","Internet-Exposed PLCs in Water Utilities Under Active Attack","Attackers are exploiting programmable logic controllers (PLCs) in water and wastewater systems that are directly accessible from the public internet — a fundamental security misconfiguration that should never exist in critical infrastructure. By gaining access to these exposed devices, threat actors were able to change passwords, alter IP addresses, and disrupt operations across more than 30 Minnesota community water systems. This incident highlights that operational technology (OT) environments require strict isolation from the internet, as these systems were designed for reliability, not cyber resilience. The consequences of compromised water infrastructure extend beyond IT disruption to direct public health and safety risks, making this a critical national security concern.","**Immediate actions:**\n- Audit all OT\u002FICS assets and immediately remove any PLCs or SCADA components with direct internet-facing exposure.\n- Change all default credentials on PLCs and enforce strong, unique passwords for every operational technology device.\n- Apply available firmware and software patches to all internet-connected industrial control systems.\n\n**Long-term improvements:**\n- Implement strict network segmentation using firewalls and DMZs to isolate OT networks from IT networks and the public internet.\n- Deploy a jump server or secure remote access solution (e.g., VPN with MFA) as the only permitted pathway for remote OT administration.\n- Maintain a continuously updated asset inventory of all OT\u002FICS devices, including firmware versions and network exposure status.\n\n**Detection measures:**\n- Enable logging and real-time alerting on all PLC configuration changes, login attempts, and network anomalies.\n- Deploy an OT-aware intrusion detection system (IDS) capable of monitoring industrial protocols (e.g., Modbus, DNP3).\n- Conduct regular vulnerability scans and penetration tests specifically targeting OT\u002FICS assets.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 12 – Network Infrastructure Management","CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 6 – Access Control Management","NIST SP 800-82 – Guide to ICS Security","NIST AC-3 – Access Enforcement","NIST SC-7 – Boundary Protection","NIST IR-6 – Incident Reporting","ICS-CERT Recommended Practices for Securing ICS","CISA Cross-Sector Cybersecurity Performance Goals (CPGs) – CPG 1.A, 2.B","America's Water Infrastructure Act (AWIA) Section 2013 – Cybersecurity Risk Assessment Requirements","published","2026-07-31T18:20:39.870537+00:00","2026-07-31T18:20:39.762+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcisa-warns-of-cyberattacks-disrupting-us-water-utilities\u002F","cisa-warns-of-cyberattacks-disrupting-u-s-water-utilities-0bef39","CISA warns of cyberattacks disrupting U.S. water utilities",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[49,55],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"c33feede-3ad8-496c-b300-02a00a11584d","2026-08-02","afternoon","ThreatNoir Weekend Brief — August 2","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-02\u002Fthreatnoir-afternoon-brief-2026-08-02.mp3",{"id":56,"date":57,"edition":58,"title":59,"audio_url":60},"ebd17d28-8bff-4323-a27c-df527b94d0ab","2026-08-01","morning","ThreatNoir Weekend Brief — August 1","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-01\u002Fthreatnoir-morning-brief-2026-08-01.mp3"]