Water Utility Attacks in Multiple States Show the Cost of One Old Vulnerability
The latest wave of intrusions at municipal water systems follows the same playbook as Unitronics and Oldsmar because no one is closing the door.
The latest wave of intrusions at municipal water systems follows the same playbook as Unitronics and Oldsmar because no one is closing the door.
While the panel cited threat intelligence and management, autonomous pen testing and code reviews, SOC automation, and much more, when they asked how they were countering AI-generated phishing and deepfakes, they leaned heavily into the security essentials.
The Open Secure AI Alliance aims to strengthen AI security with open-source tools. Can open defense outpace AI threats?
The July 22 update to AA26-097A expands the scope of Iranian PLC attacks and lays out urgent mitigation steps for water, energy, and government operators.
OpenAI and Hugging Face exposed AI's biggest security risk: enterprises automating broken processes, weak governance, and excess access.
As vendor ecosystems expand, industrial firms are still struggling with the basics of secure remote access, oversight and credential control.
GitLost shows how prompt injection can turn AI agents into data exfiltration tools by abusing legitimate permissions and trusted workflows.
AI uncovered seven FatFs flaws affecting embedded devices. The challenge now is patching millions of systems with no easy fix.
With 48,000+ CVEs published annually, the challenge isn't volume. It's finding the vulnerabilities attackers will actually exploit.
A new White House executive order sets hard deadlines for federal agencies to migrate to post-quantum cryptography by 2030 and 2031 and extends those obligations to contractors through new procurement rules. (includes infographic)
CISA's BOD 26-04 tells federal agencies how fast to patch. It's quietly telling everyone else the same thing: through insurance underwriting, vendor contracts, and regulatory alignment.
The agency’s new directive replaces blunt severity-driven remediation with a four-factor risk model built around internet exposure, known exploitation, automatability and system control.
Iranian-linked hackers reportedly breached California Water Service by pivoting through an open-source GPS correction tool to then access billing systems. The alleged intrusion laid bare security failures that federal inspectors had already flagged across hundreds of U.S. water systems.
Security teams are caught between a rapidly expanding attack surface and accelerating adversarial use of AI. Thirty-two percent of security teams see automated, AI-fueled attacks as the single greatest driver reshaping their offensive security strategies.
A trio of fresh flaws highlights the heightened vulnerability of the entire enterprise software stack, as the combination of automated scanning, the availability of exploit code, and patching delays is cited as a factor in the rise of vulnerability exploitation as a preferred entry point.
The normalization of ransomware in industrial systems, along with an operating culture that treats downtime as unacceptable, is an uncomfortable tension that's not likely to go away soon.