Water Utility Attacks in Multiple States Show the Cost of One Old Vulnerability
The latest wave of intrusions at municipal water systems follows the same playbook as Unitronics and Oldsmar because no one is closing the door.
The latest wave of intrusions at municipal water systems follows the same playbook as Unitronics and Oldsmar because no one is closing the door.
Also this week: How not to build a security vendor booth, how we got ants in cybersecurity and why Human Risk Management and mental health matter more than ever.
The July 22 update to AA26-097A expands the scope of Iranian PLC attacks and lays out urgent mitigation steps for water, energy, and government operators.
Danielle (DJ) Jablanski argues that critical-infrastructure owners must stop waiting for perfect regulation or deterrence and instead start today to map interdependencies, engineer fault-tolerant redundancy, and reduce the severity of inevitable cyber-physical impacts.
Security engineer and architect Brad Voris recounts designing zero-trust controls for legacy dairy-plant systems to protect millions of gallons of milk from tampering or contamination.
Also this week: Introducing the CYBR.Minded podcast, why Zero Trust Framework's creator wants cybersecurity to stop talking about risk, a GPS correction tool gives Iran-linked hackers access to a major water utility, a guide to conference swag people actually want, and more!
Accenture's acquisition of a majority stake in Dragos and full ownership of runZero and NetRise reflects growing urgency across the cybersecurity industry to defend critical infrastructure against nation-state threats, particularly those attributed to China.
Iranian-linked hackers reportedly breached California Water Service by pivoting through an open-source GPS correction tool to then access billing systems. The alleged intrusion laid bare security failures that federal inspectors had already flagged across hundreds of U.S. water systems.
IRGC-affiliated actors used legitimate engineering software to compromise American water, energy, and government systems. A new report ties the hacktivist ecosystem to Iranian intelligence, enabling them to communicate directly with Iranian intelligence.
Cybersecurity has outgrown the SOC. As attacks spill into water systems, hospitals, and critical infrastructure, OT.SEC.CON will bring together the practitioners, policymakers, and operators redefining what defense looks like when cyber risk becomes physical risk.
The tens of thousands of at-risk water utilities across this country are still out there — now slightly more aware of how exposed they are, which isn’t exactly progress.
Critical infrastructure organizations reported thousands of incidents in the covered period, and year-over-year data shows a roughly 180% increase in the exploitation of vulnerabilities as an initial access path, concentrated heavily on edge devices and remote access infrastructure.
ICIT Executive Director Valerie Moon says the United States remains unprepared for critical infrastructure attacks that come with modern geopolitical conflict.
The Office of the Director of National Intelligence’s 2026 Annual Threat Assessment (ATA) highlights escalating risks to the U.S. from China, Russia, Iran, North Korea, and aggressive ransomware actors, emphasizing pre-positioning in key systems for potential disruption during crises.