LIVE · cybersecurity feed
Live wire
breach

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology [

zeroday.news · 2h ago

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory to critical infrastructure operators, particularly those in the Water and Wastewater Systems (WWS) sector, to immediately remove internet-exposed Programmable Logic Controllers (PLCs) and other operational technology (OT) systems. This warning follows a series of cyberattacks that impacted more than 30 community water utilities across Minnesota between July 26 and 27.

Minnesota IT Services (MNIT) confirmed the coordinated cyberattack targeted OT systems, prompting the activation of the state’s cybersecurity incident response capabilities. While MNIT continues to collaborate with federal, state, local, Tribal, and private-sector partners to investigate, four cities have publicly disclosed details: Braham, Maple Plain, Plymouth, and South St. Paul. Braham, a town of approximately 1,700 residents, experienced the most significant disruption, with its water plant entirely knocked offline after attackers disabled the computerized controls for its well and treatment systems. The attacks led to boil water notices and forced some facilities to switch to manual operations, though drinking water largely remained safe due to contingency procedures.

Federal and state officials have not yet formally attributed the Minnesota attacks to a specific actor. However, Tenable researchers assess that the operational pattern is consistent with CyberAv3ngers, an Iran-linked group formally tied to the Islamic Revolutionary Guard Corps Cyber-Electronic Command. This assessment aligns with a CISA advisory updated four days prior to the Minnesota incidents, which detailed Iranian-affiliated actors targeting PLCs across U.S. critical infrastructure.

CISA is observing a significant increase in cyber threat actors targeting PLCs in the WWS sector. These attackers are not employing highly sophisticated methods; instead, they are exploiting internet-facing devices with default or weak credentials. Once remote access is gained, they modify passwords to lock out operators and change IP addresses to disconnect PLCs, leading to a loss of monitoring and control functionality. The FBI has confirmed that utility companies in at least seven states have reported similar PLC-related incidents.

A critical vulnerability, CVE-2021-22681, in Rockwell Automation PLCs (CVSS 9.8) has been actively exploited by Iranian-affiliated threat actors since March 2026. CISA has added this flaw to its Known Exploited Vulnerabilities catalog. Rockwell Automation has confirmed that no security patch is available for this vulnerability, making network isolation and other compensating controls essential.

The CISA advisory, updated in July 2026, indicates that attacks exploiting internet-exposed PLCs have expanded beyond Rockwell Automation devices to include those from Schneider Electric and Siemens. A new development noted in the advisory is the exfiltration of PLC project files. This action suggests attackers are stealing the engineering logic and programmed behavior of industrial processes to study them offline, potentially for more targeted future attacks rather than mere disruption.

CISA emphasizes that OT assets exposed to the internet face increased risks of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage. The agency stresses that even water organizations with mature cybersecurity processes must validate their external connections, as targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

Introduction

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.