LIVE · cybersecurity feed
Live wire
icshigh

Ex-NSA Chief Urges Disconnecting Water Controllers from Internet

Following suspected cyberattacks on water systems across at least 12 US states, likely perpetrated by Iran, a former NSA chief has strongly advised that industrial control systems like programmable logic controllers (PLCs) should not be connected to the internet. He emphasized the need for higher cybersecurity standards to defend these critical infrastructure components, noting that Iranian actors have a history and capability for such attacks.

zeroday.news ·

Retired General Paul Nakasone, former director of the National Security Agency, has advocated for disconnecting water system controllers from the internet, citing recent suspected Iranian cyberattacks on US water facilities. Speaking at the DEF CON conference, Nakasone emphasized the need for higher cybersecurity standards, stating that programmable logic controllers (PLCs) used in water systems should not be internet-connected.

The FBI confirmed in late July that it is investigating attacks by "malicious cyber actors" targeting operational technology devices, including PLCs. These devices are crucial for monitoring sensor data, such as tank levels, and controlling pumps in water and wastewater infrastructure. While neither the FBI nor the current administration has officially attributed the attacks, some private-sector security researchers strongly suspect Iran-linked groups are responsible.

Cynthia Kaiser, SVP at Halcyon Ransomware Research Center, expressed confidence at DEF CON that Iran is behind the recent disruptions, noting that Iranian actors have a history of targeting such devices for years. Nakasone echoed this sentiment, pointing to Iran's proven capability and intent in cyber warfare, given ongoing conflicts. He believes the federal government is taking a "measured approach" to public attribution.

Nakasone highlighted the significant vulnerability of US water systems, which comprise approximately 50,000 municipalities and supply 90 percent of the nation's water. These facilities often suffer from underfunding, limited IT staff, and a lack of dedicated cybersecurity personnel, creating a vast and exposed attack surface.

To address these vulnerabilities, Nakasone stressed the importance of collaborative defense strategies. He pointed to initiatives like DEF CON Franklin, a two-year-old project where volunteer hackers assist in securing water facilities. Nakasone is also involved with Vanderbilt University’s Institute of National Security and its Wicked Problems Lab, as well as Project Chimera, an open-source cybersecurity platform designed to enhance critical infrastructure resilience. He emphasized that effective defense requires a more involved, partnership-driven approach than currently exists.

icswater systemsirancyber defenseplc
ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

breachcritical

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

breach

Unlimited Technology Systems breach impacts 3.8 million people

Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]

nation-state

Water utilities group partners with DEF CON offshoot for Water Watch Center

The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.

security

US cyber ambassador nominee Cassady confirmed in Senate

NTIA official Adam Cassady becomes the second person confirmed to be the State Department's ambassador-at-large for cyber policy.

vulnerability

More than half of AI-generated patches are broken

Research finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way. The post More than half of AI-generated patches are broken appeared first on CyberScoop.