LIVE · cybersecurity feed
Live wire
Bypassing AI guardrails is so easy a script kiddie can do itCVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
security

Iran Cyberattacks Against Minnesota Water Systems

Attribution is preliminary, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself. “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the

zeroday.news · 2h ago

--- Source 2 --- Iranian-Backed Cyberattack on Water Utilities in Multiple U.S. States

Key Points: Attack Details: Iranian-backed cyberattack group, "Cyber Av3ngers," claimed responsibility for compromising Unitronics Vision Series PLCs in U.S. water facilities. Vulnerability: The attackers exploited a default password vulnerability in Unitronics Vision Series PLCs, specifically targeting devices exposed to the public internet. Impact: While the attackers claimed to have caused operational disruptions, the affected utilities reported minimal impact, primarily limited to defacement of human-machine interfaces (HMIs). Targets: The attacks targeted water utilities in multiple U.S. states, including Pennsylvania and Minnesota. Attribution: The FBI and CISA attributed the attacks to Iranian-backed actors, citing the use of "Cyber Av3ngers" branding and anti-Israel messaging. Recommendations: CISA and the FBI issued a joint advisory (AA23-335A) urging critical infrastructure organizations to secure their PLCs, change default passwords, and implement network segmentation.

Full Story:

A sophisticated cyberattack, attributed to an Iranian-backed group known as "Cyber Av3ngers," has targeted water utilities across multiple U.S. states, including Pennsylvania and Minnesota. The attackers claimed responsibility for compromising Unitronics Vision Series Programmable Logic Controllers (PLCs), exploiting a default password vulnerability in devices directly exposed to the public internet.

The "Cyber Av3ngers" group, known for its anti-Israel rhetoric, defaced the human-machine interfaces (HMIs) of the compromised PLCs with messages such as "EVERYTHING FOR ISRAEL IS UNLAWFUL." While the attackers boasted of causing significant operational disruptions, the affected utilities have largely reported minimal impact, primarily limited to the HMI defacement.

The FBI and CISA have jointly attributed these attacks to Iranian-backed actors, citing the consistent use of the "Cyber Av3ngers" moniker and the political messaging displayed on the defaced systems. This attribution aligns with broader concerns regarding nation-state sponsored cyber activities targeting critical infrastructure.

In response to these incidents, CISA and the FBI have issued a joint advisory (AA23-335A), providing urgent recommendations for critical infrastructure organizations. These recommendations include immediately changing all default passwords on PLCs and other operational technology (OT) devices, implementing robust network segmentation to isolate OT networks from IT networks, and regularly patching and updating systems. The advisory emphasizes the importance of reducing the attack surface by ensuring that OT devices are not directly accessible from the public internet.

The attacks highlight the ongoing threat posed by nation-state actors to critical infrastructure and underscore the necessity for enhanced cybersecurity measures within the utility sector.

--- Source 3 --- Iranian Hackers Target U.S. Water Systems: A Growing Threat

Key Details: Attack Group: "Cyber Av3ngers," an Iranian-backed hacking group. Targeted Systems: Unitronics Vision Series PLCs. Vulnerability Exploited: Default passwords on internet-exposed PLCs. Impact (Confirmed): Defacement of Human-Machine Interfaces (HMIs) with anti-Israel messages. Impact (Claimed by Attackers): Operational disruptions and control over water systems. Affected States: Confirmed incidents in Pennsylvania and Minnesota; claims of attacks in seven states. Official Response: FBI and CISA issued a joint advisory (AA23-335A) urging immediate action. Recommendations: Change default passwords, implement network segmentation, monitor OT networks.

Full Report:

An Iranian-backed hacking group known as "Cyber Av3ngers" has claimed responsibility for a series of cyberattacks targeting water systems across the United States. The group specifically exploited Unitronics Vision Series Programmable Logic Controllers (PLCs) that were found to be exposed to the public internet and still utilizing their default passwords.

Confirmed incidents include the defacement of Human-Machine Interfaces (HMIs) at water facilities in Pennsylvania and Minnesota. The defaced screens displayed anti-Israel messages, including "EVERYTHING FOR ISRAEL IS UNLAWFUL," aligning with the "Cyber Av3ngers" group's known political motivations. While the attackers have claimed to have achieved operational disruptions and taken control of the targeted water systems, the affected utilities have largely reported that the impact was limited to the HMI defacement. There is no official confirmation of widespread operational disruption or damage to the water supply.

The FBI and CISA have jointly issued an advisory, AA23-335A, in response to these attacks. The advisory attributes the incidents to Iranian-backed actors and provides urgent recommendations for critical infrastructure organizations, particularly those in the water and wastewater sector. These recommendations emphasize the immediate necessity of changing all default passwords on PLCs and other operational technology (OT) devices. Furthermore, the advisory stresses the importance of network segmentation to isolate OT networks from enterprise IT networks, thereby limiting potential lateral movement for attackers. Organizations are also urged to continuously monitor their OT networks for suspicious activity and to ensure that OT devices are not directly accessible from the internet.

The "Cyber Av3ngers" group has claimed to have targeted facilities in at least seven U.S. states, though specific details beyond Pennsylvania and Minnesota remain unconfirmed by official sources. This campaign underscores the persistent and evolving threat that state-sponsored cyber actors pose to critical infrastructure sectors globally. The exploitation of basic vulnerabilities like default passwords highlights a significant security gap that organizations must address to protect essential services.

ShareXLinkedInWhatsAppFacebook

More News

view all →
cloud

Apple battles it out again with the UK over encrypted iCloud access

Apple is fighting another attempt by the UK's Home Office to get a backdoor providing access to encrypted iCloud data.

nation-state

OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud

A tip from WhatsApp led OpenAI to ban multiple accounts associated with investment scams and human trafficking operations based in Cambodian scam centers.

vulnerability

SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency

Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue. Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The FOITT said the unknown

malware

New XCSSET variant targets macOS devs via compromised Xcode projects

A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]

security

77 Open VSX extensions found harvesting developer info

77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]

ai

Dem senators criticize Trump administration decisionmaking on AI security risks

The five senators said the administration has alternated between being too passive and overstepping, and China stands to benefit as a result. The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.