Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek.

Water facilities in New Jersey and Alabama have reportedly joined a growing list of states targeted in cyberattacks against industrial control systems (ICS). The incidents are part of a broader campaign attributed to Iranian-linked hackers, which has reportedly impacted water infrastructure in at least a dozen U.S. states.
The attacks specifically focused on industrial control systems, which are critical components for managing and automating operational technology (OT) in sectors like water utilities. These systems are responsible for controlling physical processes, such as water flow, chemical treatment, and pressure regulation. Compromise of such systems could potentially disrupt operations, affect water quality, or even cause physical damage to infrastructure.
While the specific mechanisms of compromise were not detailed, attacks against ICS often exploit vulnerabilities in network segmentation, outdated software, or weak authentication protocols. Threat actors might leverage remote access points, phishing campaigns targeting OT personnel, or supply chain compromises to gain initial access to these specialized networks. Once inside, they could attempt to manipulate controllers, disable safety systems, or exfiltrate sensitive operational data.
Water utilities, like other critical infrastructure sectors, typically employ a layered defense strategy. This often includes robust network segmentation to isolate OT networks from IT networks, regular patching and vulnerability management for all connected systems, and strong access controls. Additionally, continuous monitoring of ICS networks for anomalous activity and comprehensive incident response plans are crucial for detecting and mitigating such threats.
The reported targeting of water facilities highlights the increasing focus of state-sponsored actors on critical infrastructure. This trend underscores the strategic value of disrupting essential services and the potential for such attacks to cause widespread societal impact. The distributed nature of these incidents across multiple states suggests a coordinated effort rather than isolated opportunistic attacks.
This series of incidents underscores the persistent and evolving threat landscape facing critical infrastructure operators in the United States. The involvement of state-linked actors in targeting essential services like water utilities elevates the severity of these threats, necessitating continuous vigilance, enhanced cybersecurity investments, and collaborative information sharing across government and industry to defend against such sophisticated campaigns.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed