[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fn9CjUOSpA4-nRKBA4MS4lQV-XUxlwfAGXeZp7eswRHY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"0e7a8779-c153-4217-baae-8a8420d40402","internet-exposed-water-systems-targeted-by-iranian-threat-actors-via-unsecured-plcs","9b44010a-33aa-435f-b872-f54b5e0f46a3","Internet-Exposed Water Systems Targeted by Iranian Threat Actors via Unsecured PLCs","Over 100 water and wastewater systems were targeted because their operational technology (OT) — specifically programmable logic controllers (PLCs) — was directly accessible from the internet via cellular modems, creating an easily exploitable attack surface. This reflects a fundamental configuration failure: critical industrial control systems should never be reachable from public networks without strict access controls and segmentation. The fact that Iranian state-linked actors were able to identify and target these systems at scale suggests they are being actively enumerated through tools like Shodan. While disruptions were limited this time, successful manipulation of water treatment systems could have serious public health consequences. This incident underscores the urgent need for OT\u002FICS environments to adopt network isolation principles standard in IT security.","**Immediate actions:**\n- Disconnect or firewall all internet-facing PLCs and OT devices, replacing direct exposure with VPN-gated or out-of-band access solutions.\n- Audit all cellular modem connections used in OT environments and restrict inbound access using allowlists and strong authentication.\n\n**Long-term improvements:**\n- Implement strict network segmentation between IT and OT networks using industrial DMZs and unidirectional security gateways.\n- Maintain a complete, up-to-date inventory of all internet-exposed OT\u002FICS assets and conduct regular exposure assessments using tools like Shodan or Censys.\n- Adopt the principle of least privilege for all remote access to industrial control systems, requiring multi-factor authentication at minimum.\n\n**Detection measures:**\n- Deploy OT-specific intrusion detection systems (e.g., Dragos, Claroty) to monitor for anomalous commands or unauthorized PLC interactions.\n- Establish 24\u002F7 monitoring and alerting for any unexpected remote connections to OT network segments, with escalation procedures tied to CISA advisories.",[12,13,14,15,16,17,18,19],"CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-82: Guide to ICS Security","NIST CSF PR.AC-5: Network integrity is protected","NIST CSF PR.PT-4: Communications and control networks are protected","ICS-CERT \u002F CISA Advisory AA24-207A","NERC CIP-005: Electronic Security Perimeters","ISA\u002FIEC 62443-3-3: System Security Requirements and Security Levels","published","2026-08-26T12:20:39.355143+00:00","2026-08-26T12:20:39.084+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.securityweek.com\u002Fcisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks\u002F","cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks-af99c4","CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":41,"name":42,"slug":43,"description":44,"color":45},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[47],{"id":48,"date":49,"edition":50,"title":51,"audio_url":52},"6b68be32-e9fa-45bf-b7d1-a2e9400938dd","2026-08-26","afternoon","ThreatNoir Afternoon Brief — August 26","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-26\u002Fthreatnoir-afternoon-brief-2026-08-26.mp3"]