LIVE · cybersecurity feed
Live wire
securitycritical

Closing the Identity Gaps in Critical Infrastructure Security

Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]

zeroday.news · 11d ago

In May 2021, the Colonial Pipeline ransomware attack demonstrated how a single compromised account could escalate into a national crisis, disrupting fuel supplies across the U.S. East Coast. Attackers reportedly gained initial access through an inactive VPN account that lacked multi-factor authentication (MFA), subsequently impacting business systems, including billing infrastructure, and forcing a shutdown. Five years later, the lessons from this incident remain highly relevant for critical infrastructure organizations.

Critical infrastructure is a prime target for threat actors due to the widespread impact that disruption can cause. Today, state-backed groups are increasingly seeking persistent access within these networks, not just for data exfiltration, but to maintain a foothold that could be exploited during future crises. Common initial attack vectors include stolen credentials, unmanaged devices, compromised laptops, remote access tools, and weak access controls.

The interconnected nature of modern systems, including operational technology (OT) environments, IT systems, cloud platforms, and SaaS applications, creates numerous exposure points. CISA recently highlighted this challenge in its guidance, "Adapting Zero Trust Principles to Operational Technology," emphasizing that implicit trust poses unacceptable risks across critical infrastructure. While OT environments require tailored security approaches due to safety, uptime, legacy systems, and physical processes, the Colonial Pipeline incident underscored that compromising business-critical IT systems can be equally damaging.

Threat actors like Volt Typhoon exemplify the sophisticated tactics used against critical infrastructure. This group specifically targets such organizations, employing techniques designed to blend into normal network activity and evade detection. U.S. agencies have warned that state-sponsored actors, including those from the PRC, have compromised and maintained access to critical infrastructure networks for extended periods, sometimes years. Their methods often involve exploiting vulnerable edge devices such as routers, firewalls, and VPN appliances, using stolen administrator credentials and legitimate accounts. They also rely on "living off the land" techniques, utilizing built-in tools instead of malware to appear routine, and routing traffic through compromised devices to hinder attribution and detection. Microsoft has reported Volt Typhoon activity against communications, manufacturing, utilities, construction, and transportation organizations in Guam and other U.S. locations, raising concerns about both espionage and the potential for disruption during geopolitical events.

Zero trust principles offer a crucial defense against these types of attacks. However, while identity is central to a zero-trust model, it cannot be the sole defense. State-backed actors are adept at stealing credentials, phishing users, hijacking sessions, and exploiting legitimate tools for lateral movement. Multi-factor authentication (MFA) is essential, but it is not a complete solution if attackers can compromise a session, enroll a rogue device, exploit a trusted remote access path, or use a legitimate account from an unmanaged endpoint. Organizations providing essential services need more robust access decisions that evaluate additional trust signals beyond just a username and password.

Given the complexities of immediately overhauling legacy OT systems or extensive third-party dependencies, strengthening workforce access to critical applications, data, and systems presents a practical starting point for many organizations. Workforce access controls integrate identity, endpoint security, and policy enforcement, allowing security teams to verify not only the user but also the device, conditions, and specific resource being accessed. Binding each identity to a device is key, ensuring that access is not granted solely based on a password, token, or approved session. Before granting access, security teams can verify if a device is known, trusted, healthy, encrypted, updated, and compliant. This approach reduces implicit trust at the point where personnel connect to vital systems, moving towards a zero-trust model.

The challenge of implementing zero trust is compounded by distributed workforces, where both onsite and remote employees require reliable access to sensitive systems, often from devices with varying security postures. For example, an engineer might use a managed, encrypted, patched laptop onsite, while a finance employee works remotely on a personal, unmanaged device. A zero-trust workforce access model should enforce these differences, requiring a specific level of device health for all access. Access policies should adapt based on device posture, user context, and resource sensitivity, thereby reducing reliance on network location as a trust signal and limiting the blast radius if an account or device is compromised.

The security of identity systems is paramount for resilient critical infrastructure. Solutions that bind identities to specific devices can enforce zero trust at every access point. This includes providing phishing-resistant authentication by ensuring users can only log in from approved, trusted devices, and continuously verifying device posture for active threats, disabled security controls, or outdated software throughout sessions. Such solutions also offer full visibility into all devices accessing the network, including managed corporate devices and unmanaged shadow IT, with controls to limit users to a specific number of authorized devices. Furthermore, a remediation toolkit can empower users to address issues without requiring service desk intervention, and grace periods can allow for device updates without disrupting productivity.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.