LIVE · cybersecurity feed
Live wire
ai

DEF CON hackers add new muscle to water utility protection

Franklin project adds new security providers, employs digital twins and AI

zeroday.news ·

At the annual DEF CON hacker conference, the DEF CON Franklin project and the National Rural Water Association (NRWA) announced a new initiative called the Water Watch Center. This program aims to enhance the cybersecurity of small rural water utilities across the United States, particularly those serving fewer than 10,000 people. The initiative expands on previous volunteer efforts by integrating managed detection and response (MDR) providers, digital twins, and artificial intelligence (AI) agents.

The Water Watch Center will initially fund five security providers: Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies. These providers will assist small water utilities in detecting and mitigating cyber breaches. A key component of the program involves these security providers exchanging threat intelligence and sharing it with the NRWA, which offers technical assistance and operational support to water and wastewater utilities nationwide.

Jake Braun, co-founder of the DEF CON Franklin project, highlighted the need for a scalable cybersecurity delivery mechanism for the approximately 150,000 small water utilities, 98 percent of which operate as small businesses. He noted that while volunteers have been working in the field for two years, the sheer number of utilities necessitates a more structured approach, similar to how managed security service providers (MSSPs) serve small businesses.

Braun described the Water Watch Center as a tiered system. The NRWA sits at the top, overseeing the program. Below that, the MDR providers will deploy sensors to monitor utility networks for vulnerabilities. Franklin project volunteers will then assist in fixing identified issues or responding to alerts. The program plans to expand from an initial five MSSPs to ten, aligning with the ten CISA regions, and will leverage volunteers to connect utilities with MSSPs and deliver cybersecurity solutions based on alerts from CISA and ISACs.

The initiative also addresses the growing threat of AI-powered cyberattacks. The Water Watch Center has partnered with Vanderbilt University to apply research from the DARPA Cyber Agents for Security Testing and Learning Environment (CASTLE) program. This collaboration will involve creating digital twins of selected water and wastewater systems. Researchers will then deploy both red-team (attack) and blue-team (defense) AI agents within these digital replicas.

The red-team agents will attempt to breach the simulated water systems, testing the automated detection and response capabilities of the blue-team defenders. The ultimate goal is to train AI-based defense agents that can eventually be deployed to water and wastewater facilities across the U.S. Braun emphasized that with a significant shortage of cybersecurity professionals, AI-driven defenses are crucial for combating future AI attacks.

Recent weeks have seen suspected Iranian hackers target numerous water systems, predominantly small community systems, by exploiting programmable logic controllers (PLCs) exposed directly to the internet with default or weak passwords. While there is no current indication that these attackers used AI, experts anticipate this will become a factor in future cyber disruptions. The Water Watch Center's AI initiatives are designed to proactively address this evolving threat landscape.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.