The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a public alert regarding a significant increase in malicious activity targeting water utilities, advising facilities to promptly remove publicly exposed Programmable Logic Controllers (PLCs) and other operational technology (OT) from the internet. This warning comes as state and federal investigators probe whether recent disruptions to Minnesota water systems are linked to Iran-backed hackers.
CISA's alert, published on Thursday, details that threat actors are targeting water entities of all sizes, modifying passwords to lock out operators and disconnecting PLCs by altering their IP addresses. This activity has led to boil water notices and necessitated sustained manual operations at affected facilities. The agency, in conjunction with the FBI and the Environmental Protection Agency (EPA), is involved in the ongoing response.
Earlier this week, Minnesota's state IT agency confirmed that over 30 community water systems in the state were impacted by a coordinated cyberattack beginning on July 26. While CISA's latest alert does not explicitly name Iran, multiple reports, including a memo from the WaterISAC (the water industry's cybersecurity information-sharing body), have suggested a connection to Iran-linked actors for the Minnesota incidents.
The FBI has reported that utility companies in at least seven states have informed the bureau of incidents involving PLCs. CISA had previously updated warnings earlier this month about Iranian-linked malicious activity targeting industrial OT.
The agency emphasized that even water organizations with mature cybersecurity processes should validate their external connections. This is particularly crucial because the targeting activity includes cellular modems installed by operators, vendors, or system integrators, which may not be documented or included in routine attack surface scans.
CISA underscored the risks associated with internet-exposed OT assets, which include defacement, configuration changes, operational disruptions, and, in severe cases, physical damage. PLCs are fundamental components in the control processes of various industries.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.