< ciso
brief />
Tag Banner

All news with #critical infrastructure tag

470 articles · page 2 of 24

N‑able issues hotfix for critical N-central RCE

🔒 N-able has released a hotfix addressing a critical pre-authentication remote code execution vulnerability, CVE-2026-86218, in its N-central monitoring and management platform. The flaw, given a maximum CVSS score of 10, impacts N-central versions before 2026.3.1.14 and could allow unauthenticated code execution on the server. N-able patched the issue in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) and reports no evidence of in-the-wild exploitation. This follows several recent high-severity vulnerabilities and prior hotfixes.
read more →

Fortinet Joins Project Watershed to Secure Water Systems

💧Fortinet joined federal, state, and industry partners on August 31 to launch Project Watershed 250, a six-month pilot in Texas aimed at strengthening water and wastewater cybersecurity. The program offers participating utilities red-team testing, system assessments, hardening support, threat intelligence, and AI-enabled defenses. It emphasizes proactive, scalable public-private collaboration to protect OT environments and develop a model for broader national adoption.
read more →

Small coin-sized implant can subvert Boeing 737

🔎 Security researchers demonstrated a compact, coin-sized device that can be inserted into an externally accessible hatch on a Boeing 737 to interface with the ARINC 429 bus. The implant, assembled from off-the-shelf parts for under US$100, can inject false signals that alter takeoff/landing calculations, autopilot routes, and displayed data, while potentially hiding changes from pilots. Researchers disclosed the issue to Boeing in 2020 and recommended physical sealing, electrical protection, and cryptographic authentication as mitigations.
read more →

OpenAI Pledges $1bn to Subsidize Daybreak Access

🔒 OpenAI will spend $1bn to subsidize access to its Daybreak cyber models for essential services worldwide, beginning in the US. The Daybreak for Frontline Defenders initiative will help sectors such as water, electricity, local governments, non-profits and banking integrate Daybreak into existing cybersecurity tools and workflows. A pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC) will provide guided training and hands-on support for public-sector and water system defenders.
read more →

OpenAI launches $1B Daybreak initiative for utilities

🛡️ OpenAI announced Daybreak for Frontline Defenders, a $1 billion global initiative to expand subsidized access to its Daybreak cyber models, training, and technical support for critical infrastructure defenders. The program combines frontier defensive models with the Codex harness and Codex Security to identify and remediate vulnerabilities, and will integrate with enterprise tools via the Daybreak Defense Network. A U.S.-focused pilot with MS-ISAC will train public-sector and water-system defenders, while OpenAI convenes utilities and offers targeted support to affected states and operators.
read more →

When the patch tsunami meets maintenance windows

🔧 AI-driven vulnerability discovery has collapsed discovery timelines from months to hours, but operational technology (OT) remediation still moves at plant speed. OT systems face physical, economic and contractual constraints that make rapid patching impractical, so defenders must prioritize containment, compensating controls and documented retirement plans. Preparation, vendor engagement and exercised surge plans are essential.
read more →

How China Industrialized State Hacking Infrastructure

🛡️ Last week the US Justice Department and FBI seized domains tied to QScan and QTRouter, platforms used by PRC-linked group QTFY to target US agencies and critical infrastructure. QTFY, operated by Nanjing Xinjiuwei, provided scanning, exploitation, and obfuscation services—turning IoT devices into routing infrastructure for state clients. The takedown highlights how marketized contractors and shared services scale Chinese offensive operations while creating choke points for law enforcement. Experts urge CISOs to shift from IP-based defenses to behavioral visibility, rapid patching, and stronger edge controls.
read more →

Defending Water and OT Systems from Internet Risk

🔒 Recent cyberattacks against U.S. water and wastewater systems show that OT impact extends beyond data loss to public health, environment, and community functions. Distributed architectures, legacy controllers, remote cellular sites, and accumulated third-party access increase the attack surface. Government advisories document exploitation of internet-facing PLCs and HMIs, while new legislation seeks to expand EPA cybersecurity authority. Fortinet recommends unified OT architectures, secure cellular connectivity, ZTNA, and IEC 62443-4-2–certified solutions for consistent protection.
read more →

Securing Water Sector Infrastructure in the AI Era

🔒 This Cloud CISO Perspectives issue outlines the rising cyber risks to water utilities and presents practical, prioritized steps for OT and IT leaders. It emphasizes basic cybersecurity hygiene—asset inventory, replacing default credentials, backups, segmentation, and vendor access controls—while urging incident planning integration with existing all-hazards systems. The piece also highlights the role of AI as a force multiplier for defenders and the need for unified governance between IT and OT.
read more →

Monthly security roundup: August 2026 highlights

🔍 ESET Chief Security Evangelist Tony Anscombe reviews the major cybersecurity stories from August 2026, summarizing incidents that should concern businesses and critical infrastructure operators. He covers an OpenAI agent breach affecting Hugging Face, Iran-linked attacks on water and power systems, a Delta Airlines in‑flight Wi‑Fi spoofing report, and a Ukrainian takedown of fraudulent call centres. The video outlines lessons and mitigation steps for organizations.
read more →

Boston Scientific Hit by Global IT Disruption

🔒 Boston Scientific disclosed a cyber incident identified on August 25 that caused network outages and disrupted access to certain operating systems and business applications. The company activated incident response protocols with third-party cybersecurity experts and reported impacts to order processing and shipping, while a full restoration timeline remains unknown. The SEC filing described the disruption as "global," and security experts warned of potential downstream effects on patient care and the importance of robust containment and segmentation.
read more →

US Navy urges personnel to tighten social media privacy

🔒 The US Navy has instructed its 340,000 active-duty members, 58,000 reservists, and 210,000 civilian employees to clean up social media profiles following a bulletin titled "Epic Vigilance: Immediate Actions for Force Protection and Personal Security." The advisory warns of a "coordinated, multi-domain campaign" by adversaries collecting intelligence and exploiting online posts and geolocation data. Personnel and families are urged to enable privacy settings, remove Navy links, report suspicious activity, and avoid sharing patterns of life that could be exploited.
read more →

Small generators expose critical infrastructure risk

🔒 A recent cyber incident that took a small UK electricity generator offline for days — without causing national outages — highlights a weakness across Western critical infrastructure: thousands of small, internet-exposed industrial control devices lack the security protections of larger utilities. Governments and security firms are investigating attribution and impacts while urging operators to remove PLCs from direct internet access, secure cellular modems, and test manual-operation procedures. The episodes mirror attacks on US water systems and underscore how modest targets can create disproportionate disruption.
read more →

FBI Disrupts China-Linked QTFY Botnet Operations

🔒 The U.S. Department of Justice and FBI announced the disruption of two hacking platforms, QScan and QTRouter, used by the China-linked group QTFY to target U.S. critical infrastructure and sensitive networks. Lumen Black Lotus Labs, which tracked the group since 2018, collaborated with the FBI after observing extensive targeting of research and public sector organizations. QScan infected IoT devices to build a proxy mesh while QTRouter and associated services obfuscated attack origins using compromised routers, commercial proxy services, and leased VPSs. The court-authorized seizure of hard-coded domains caused the platforms to cease operations.
read more →

CISA red team reveals starkly different SOC outcomes

🛡️ CISA released dual red team reports showing two critical infrastructure organizations were fully domain-compromised using similar tradecraft. Organization A suffered extensive undetected access due to default machine account quotas, misconfigured AD CS templates, cleartext credentials, static cloud keys, and fragmented SOC visibility. Organization B detected and isolated initial footholds quickly, limiting spread despite similar underlying weaknesses, illustrating the decisive role of people and processes.
read more →

US Treasury Targets Iran-Linked Cyber Actors

🛡️ The U.S. Department of the Treasury announced Operation Economic Outcast, imposing sanctions on nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks. The measures target an MOIS-affiliated cyber group accused of widespread compromises of U.S. critical infrastructure and financially motivated theft, and designate five individuals tied to the Tehran-based Mabna Institute. Treasury and partner agencies emphasized cutting Iran's financial lifelines, while the State Department’s Rewards for Justice offers up to $10 million for information on malicious cyber actors.
read more →

Massive DDoS Disrupts Norway’s Government Services

🔒 A large DDoS attack began at 03:38 CEST, disrupting the Norwegian Digitalization Agency (Digdir) and its provider Vivicta, affecting public-service logins, electronic IDs and signatures, secure digital mail, and inter-agency data exchange. Several services were briefly unavailable and some, including ID-porten and eSignering, remain partially inaccessible, causing login errors and slow responses. Digdir reports stabilization of many systems, no evidence of a security breach or personal data compromise, and has notified NSM and Datatilsynet. This is the third recent DDoS against Digdir; there is no official attribution but media have speculated about Russian involvement.
read more →

Weekly Recap: AI-Enabled PLC Exploits Rise

🔍 U.S. agencies warn that threat actors are using AI to craft exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs), posing risks to water, energy, manufacturing, and other critical infrastructure. Attackers leverage public scanning services to locate vulnerable PLCs and deploy AI-generated tools that masquerade as legitimate monitoring software to probe and prepare for disruptive write operations. The advisory stresses this is an active, not theoretical, threat and highlights the need for improved segmentation, monitoring, and remediation.
read more →

White House Memo Expands Private Cyber Operations Role

📝 This week's Threat Source newsletter by Mick Baccio examines a recent presidential memorandum directing DOJ and DHS to create a program that allows private companies to conduct government-authorized cyber surveillance and effects operations against transnational criminal organizations. The piece highlights operational questions about attribution, intelligence handling, and geopolitical risk, and notes Talos reporting on AI-driven Chinese cybercrime group UAT-10147 and critical active exploits.
read more →

AIT-GUI flaws could let unauthenticated actors command craft

🔒 Security researchers at Cycode disclosed a critical chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's AMMOS Instrument Toolkit, allowing unauthenticated attackers to issue arbitrary commands to the instrument and spacecraft command bus. Tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 (CVSS v3.1), the issues affect AIT-GUI ≤2.5.1 and were addressed in 2.5.2 on August 12, 2026. The defects include missing authentication, absent CSRF protection, and path traversal on state-changing routes, enabling POST-based command, script execution, and sequence abuse when reachable.
read more →