[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUxC25WguwE562-n9p4BsaUZ46zC2hOwNPH1-MHOrKj8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"b74308f8-fbb7-4805-97be-ec9af6b88119","unpatched-plcs-and-weak-credentials-put-us-water-utilities-at-risk","79ef40a2-d8f4-4041-96a9-64e5bc2a70ab","Unpatched PLCs and Weak Credentials Put US Water Utilities at Risk","Attackers exploited internet-facing programmable logic controllers (PLCs) across water utilities in at least seven US states, leveraging unpatched devices and weak or default credentials — no sophisticated techniques required. The root failures were foundational: critical operational technology (OT) was left exposed to the public internet without hardening, patching, or strong authentication. These oversights resulted in real-world physical consequences, including pressure loss and flooding, demonstrating that cyber vulnerabilities in critical infrastructure translate directly into public safety risks. The fact that a joint FBI\u002FEPA alert was necessary underscores how persistently the water sector lags behind on basic cyber hygiene. This is not a novel threat — it is a recurring, preventable one.","**Immediate Actions:**\n- Audit all internet-facing OT\u002FICS devices (PLCs, HMIs, SCADA) and remove or firewall any that do not require direct internet exposure.\n- Immediately change all default and weak credentials on PLCs and related control systems to strong, unique passwords.\n- Apply all available patches and firmware updates to operational technology devices, prioritizing internet-facing assets.\n\n**Long-Term Improvements:**\n- Implement network segmentation to isolate OT\u002FICS environments from both the public internet and corporate IT networks using DMZs and industrial firewalls.\n- Establish a formal vulnerability management program specifically covering OT\u002FICS assets, including a maintained inventory of all field devices and their patch status.\n- Enforce multi-factor authentication (MFA) for all remote access to control systems and operational networks.\n\n**Detection & Response Measures:**\n- Deploy continuous monitoring and anomaly detection on OT networks to identify unauthorized access or unusual command sequences in real time.\n- Develop and regularly exercise an OT-specific incident response plan that includes coordination procedures with the FBI, EPA, and CISA.\n- Implement logging on all PLCs and network devices with centralized log aggregation to support forensic investigation after any incident.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 6: Access Control Management","NIST SP 800-82: Guide to ICS Security","NIST CSF PR.AC-3: Remote Access Management","NIST CSF PR.PT-4: Communications and Control Networks Protection","ICS-CERT Recommended Practices for Securing ICS","CISA Cross-Sector Cybersecurity Performance Goals (CPGs) — OT\u002FICS","America's Water Infrastructure Act (AWIA) Section 2013: Risk and Resilience Assessments","NERC CIP-005: Electronic Security Perimeters (analogous best practice for water sector)","published","2026-08-06T12:21:02.726081+00:00","2026-08-06T12:21:02.433+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fcyberscoop.com\u002Fwater-utility-cyberattacks-prevention-nozomi-networks-ceo-op-ed\u002F","the-water-sector-just-got-it-s-wake-up-call-again-f9bc27","The water sector just got it’s wake-up call. Again.",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"b4a0d88a-cf11-46d6-886f-96dadad94438","2026-08-06","afternoon","ThreatNoir Afternoon Brief — August 6","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-06\u002Fthreatnoir-afternoon-brief-2026-08-06.mp3"]