LIVE · cybersecurity feed
Live wire
OpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
security

Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity

Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.

zeroday.news ·

Two Democratic senators have introduced legislation aimed at bolstering the cybersecurity of the nation's water and wastewater systems, proposing an annual allocation of $300 million for improvements. Senators Adam Schiff (D-Calif.) and Amy Klobuchar (D-Minn.) unveiled the Water Cyber Shield Act, which seeks to grant the Environmental Protection Agency (EPA) enhanced authority to regulate cybersecurity within this critical infrastructure sector.

The proposed legislation follows a series of recent cyberattacks targeting at least 30 water and wastewater systems across approximately 12 states. These incidents are widely believed to be linked to groups associated with Iran’s military. The bill would authorize $300 million annually from the Drinking Water and Clean Water State Revolving Funds specifically for cybersecurity enhancements.

Under the Water Cyber Shield Act, the Safe Drinking Water Act and the Clean Water Act would be amended to empower the EPA to conduct cybersecurity assessments and mandate corrective actions for identified vulnerabilities. Water and wastewater systems would be required to integrate cybersecurity risk assessments into their resilience planning and comply with incident reporting requirements outlined in the forthcoming Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA).

The act outlines differentiated rules for water systems based on their size, allowing states to determine whether they will manage cybersecurity regulations independently or seek EPA assistance. The EPA would also collaborate with the Cybersecurity and Infrastructure Security Agency (CISA) to share threat intelligence and develop cybersecurity standards, with a technical advisory committee tasked with creating these standards.

To encourage participation and protect sensitive information, cybersecurity data submitted by utilities would be exempt from public disclosure. Smaller water systems would receive greater flexibility and be prioritized for federal financial aid. The EPA would also be mandated to develop cybersecurity metrics to track progress within the water sector and publish regular reports on the issue.

Senator Klobuchar highlighted the urgency, stating that recent cyberattacks in Minnesota underscore the need to secure water systems and critical infrastructure. The legislation aims to direct the EPA to assess water infrastructure cybersecurity, identify vulnerabilities, and assist municipal water systems in defending against cyber threats.

Currently, the EPA is responsible for managing the water sector but lacks the direct authority to institute cybersecurity regulations. A previous attempt by the Biden administration to incorporate cybersecurity checks into annual water system assessments was met with legal challenges from water industry groups and several states, who argued that such improvements would lead to increased costs for consumers. This effort was ultimately abandoned, leading to continued attacks by state-backed groups and ransomware gangs, which have forced some systems to shut down tools or operate manually.

A spokesperson for Senator Schiff indicated that his office consulted with various stakeholders, including water industry groups, state regulators, cybersecurity experts, and federal agencies, to address potential concerns. Feedback was also gathered from the EPA and other federal agencies. Senator Schiff emphasized that all Americans rely on safe, reliable drinking water and that recent events have exposed the vulnerability of these systems to cyberattacks from foreign adversaries and criminal entities. He stated that these threats are not hypothetical and are occurring now, and the legislation would provide the EPA with necessary tools to protect critical infrastructure while offering resources to local water and wastewater systems without burdening ratepayers with additional costs.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Poland uncovers second heat plant cyberattack that went hidden for months

The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.

vulnerability

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data

security

UK man tied to The Com sentenced for abusing 117 victims

Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.

security

Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

Cisco is proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

breach

Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. “Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to custome

breach

Metabase zero-day exploited to access Framework customer data

Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses,