< ciso
brief />
Tag Banner

All news with #critical infrastructure tag

432 articles

White House Memo Expands Private Cyber Operations Role

📝 This week's Threat Source newsletter by Mick Baccio examines a recent presidential memorandum directing DOJ and DHS to create a program that allows private companies to conduct government-authorized cyber surveillance and effects operations against transnational criminal organizations. The piece highlights operational questions about attribution, intelligence handling, and geopolitical risk, and notes Talos reporting on AI-driven Chinese cybercrime group UAT-10147 and critical active exploits.
read more →

AIT-GUI flaws could let unauthenticated actors command craft

🔒 Security researchers at Cycode disclosed a critical chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's AMMOS Instrument Toolkit, allowing unauthenticated attackers to issue arbitrary commands to the instrument and spacecraft command bus. Tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 (CVSS v3.1), the issues affect AIT-GUI ≤2.5.1 and were addressed in 2.5.2 on August 12, 2026. The defects include missing authentication, absent CSRF protection, and path traversal on state-changing routes, enabling POST-based command, script execution, and sequence abuse when reachable.
read more →

U.S. warns of AI-driven attacks on Siemens PLCs

🔒 U.S. cybersecurity agencies issued a joint advisory warning that threat actors are using AI-generated Python scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) within U.S. critical infrastructure. The agencies—NSA, CISA, FBI, DOE, and EPA—noted ongoing activity that targets exposed PLCs by abusing vulnerabilities, outdated software, and weak authentication to gain read/write access and disguise tools as legitimate OT monitoring software. Operators are urged to inventory devices, apply updates, block internet access, and strengthen monitoring and access controls to reduce risk.
read more →

Medusa Ransomware Hits 500+ Critical Infrastructure

🛡️ The FBI, CISA and HHS issued an updated advisory on August 18, 2026, stating Medusa ransomware has affected over 500 critical infrastructure organizations, with healthcare heavily targeted. The advisory notes the operation has accelerated exploitation of unpatched vulnerabilities—sometimes within 24 hours or before public disclosure—and expanded post-exploitation tooling. Medusa uses stealthy PowerShell techniques, legitimate RMM tools, credential theft methods like Mimikatz, and exfiltration tools such as Bandizip and Rclone to support a double-extortion model.
read more →

White House memo expands private cyber offensive role

📝A White House memorandum signed by President Donald Trump directs the National Coordination Center (NCC) to create a program enabling vetted U.S. private companies to conduct cyber surveillance and cyber effects operations against foreign Transnational Criminal Organizations (TCOs). The NCC must implement the program within 60 days and impose oversight, minimization, and reporting requirements to prevent operations from targeting U.S. persons or systems. The move broadens private sector involvement in offensive cyber actions, while raising legal and security concerns given existing prohibitions on private actors conducting cyber attacks without court authorization.
read more →

Gunra Ransomware Targets Critical Infrastructure Globally

🔒 Cybersecurity agencies in South Korea and the U.S. have warned of Gunra ransomware campaigns targeting critical infrastructure sectors globally, including healthcare, finance, and government. The actors exploit vulnerabilities in Schneider Electric PowerLogic P5 and Fortinet FortiOS/FortiProxy to gain access, then use double extortion tactics combining data theft and encryption. Victims face data leaks within days if ransoms are not paid.
read more →

CISA flags critical Progress Kemp LoadMaster flaw

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are actively exploiting a critical command injection vulnerability in Progress Kemp LoadMaster. The flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands on unpatched appliances via unsanitized API inputs. Progress released patches in June for affected GA and LTSF versions, and CISA has directed federal agencies to remediate within three days.
read more →

North Carolina ports confirm disruptive cyberattack

🔒 The North Carolina Ports Authority confirmed a cyberattack disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and the Charlotte Inland Port. The incident was detected on August 4, with recovery actions initiated August 5 and gates operating on a normal schedule by August 7. The authority has not attributed the incident to any threat actor or confirmed data theft, and some delays continue as systems are restored.
read more →

Over 4,400 Rockwell PLCs Exposed on Internet

🔍 Forescout's August 3 scan found 4,407 internet-exposed Rockwell Automation PLCs worldwide, including 2,844 in the US; 22 were in cities hit by recent water utility attacks. The firm noted attackers can alter IPs and set passwords on reachable controllers without exploiting a vulnerability, and 19 of 22 in affected cities used the same mobile carrier network. The FBI and EPA urge strong authentication, firmware updates and isolation of remote access to reduce public exposure.
read more →

Preliminary Attribution of Water System Cyberattacks

⚠️ Reports indicate a campaign of cyber intrusions affecting water systems across multiple U.S. states, with at least seven states targeted and preliminary attribution to Iran. Authorities say no significant physical damage has been observed so far. Political leaders have publicly disputed the attribution, and discussion continues in technical and public forums.
read more →

Six hard truths from CI Fortify guidance

🔒 The Five Eyes’ CI Fortify guidance urges critical infrastructure operators to be able to isolate operational technology deliberately and sustain services during a crisis. The advisory rates VLANs and MPLS as insufficient long-term segregation and cautions against trusting carrier services or native OT encryption. It warns that software-defined controls are convenient but not equivalent to physical separation, and that isolation introduces its own operational risks requiring planning and testing.
read more →

CISA warns of attacks on US water and wastewater systems

🚨 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert after hackers disrupted over 30 Minnesota community water systems by targeting internet-exposed programmable logic controllers (PLCs). The attacks included password changes that locked operators out, IP alterations that severed internet connectivity, and other actions that impaired operations. CISA urges owners and operators to remove publicly exposed PLCs and OT from the internet, use VPNs or gateway devices for access, change default passwords, and implement IP allow-lists. Security vendor research from Censys found thousands of internet-reachable PLC hosts and highlighted undocumented cellular modems as a common blind spot.
read more →

Coordinated cyberattack disrupts Minnesota water systems

🔒 A coordinated cyberattack targeted more than 30 Minnesota community water systems over July 26–27, prompting temporary operational shutdowns and local emergency responses while officials reported drinking water remained safe. Security researchers link the campaign to a months-long surge in attacks on water infrastructure and note potential ties to exposed PLCs, including Rockwell Automation MicroLogix 1400 controllers. Federal agencies urged utilities to remove internet-exposed operational technology and follow mitigation guidance as investigations continue.
read more →

Critical Ruflo MCP bridge flaw risks full AI agent takeover

🔒 A critical vulnerability in the open-source AI agent platform Ruflo (CVE-2026-59726, "RufRoot") allows unauthenticated attackers to exploit an exposed Model Context Protocol (MCP) bridge and gain full control of enterprise AI environments. Researchers at Noma Security showed a single HTTP request to the bridge’s /mcp endpoint can execute code, steal LLM API keys, access conversations, hijack agents, and poison persistent AI memory. Ruflo issued a rapid patch that binds the MCP bridge to loopback and enforces failure-closed behavior, while researchers urged immediate firewall and credential remediation.
read more →

FCC Blocks New Foreign-Produced Robots and Inverters

🔒 The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, generally blocking new models from receiving US equipment authorization for import, marketing, or sale. Previously authorized units and existing owners are unaffected, and federal purchases remain permitted. A waiver allows security and compatibility software updates through at least January 1, 2029, while manufacturers may seek Conditional Approval by January 1, 2028.
read more →

CISA's Six-Step Blueprint for Infrastructure Isolation

🔒 The US CISA and Five Eyes partners published CI Fortify, a six-step guide to isolate and protect critical infrastructure during cyber incidents. The guide outlines identifying vital systems and customers, classifying trust levels, mapping interconnections, and building separation points. It emphasizes physical isolation and phased isolation plans while acknowledging operational constraints and the need for encryption and robust risk management.
read more →

Coordinated cyberattack hits 30+ Minnesota water systems

🔒 A coordinated cyberattack impacted operational technology at more than 30 Minnesota community water systems on July 26–27, prompting a statewide cybersecurity response. Several municipalities, including Braham, Plymouth, South St. Paul and Maple Plain, reported outages, communications failures or affected automated controls, with Maple Plain declaring a local emergency. Minnesota IT Services (MNIT) and federal partners are investigating, sharing intelligence and working to contain and recover systems while attribution and technical details remain under investigation.
read more →

Critical Check Point Management Authentication Bypass

🔒 Rapid7 and other researchers disclosed technical details for CVE-2026-16232, a critical authentication bypass in Check Point Security Management Server and MDS. The flaw lets an unauthenticated attacker obtain an application login token and authenticate with full administrator privileges via SmartConsole. Exploitation requires network access to the Management Server and permissive Trusted Clients configuration. Check Point released Jumbo Hotfixes on July 22, 2026, and Rapid7 published a PoC for testing.
read more →

NCSC issues guidance for disruptive cyber incidents

🛡️ The UK's National Cyber Security Centre (NCSC) has published What To Do When Cyber-Attacks Disrupt Your Organisation, outlining three chronological stages for response: immediate hours and days, recovery to minimum viable operations, and longer-term restoration to business as usual. The guidance emphasizes preparing in advance, practicing realistic simulations, and engaging NCSC-vetted incident response firms to build resilience against escalating threats such as AI-accelerated attacks.
read more →

Guidance for isolating critical infrastructure OT

🔒 New joint guidance from U.S. and Australian cybersecurity agencies, including CISA and the ACSC, advises critical infrastructure operators to prepare to isolate vital operational technology systems during cyber incidents. The document defines concepts like vital systems, isolation points, and graduated versus physical isolation, and stresses planning, documentation, and regular testing. It highlights trade-offs, operational impacts, and the need to maintain manual operations and secure offline plans.
read more →