CISA alert: PLC attacks on water utilities escalate
PLC attacks on water utilities by Iranian APTs triggered a CISA alert after attackers locked operators out and caused boil water notices across the US.
10 stories tagged threat-intel.
PLC attacks on water utilities by Iranian APTs triggered a CISA alert after attackers locked operators out and caused boil water notices across the US.
PLC attacks on water utilities spread to 7 states after 30 Minnesota systems were hit. CISA says remove exposed controllers from the internet now.
Cl0p affiliates exploit unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM to steal data. Patch, segment, and block external access now.
Citrix Bleed 2 is now an Anubis ransomware access path. Patch NetScaler, kill sessions, and hunt RMM plus credential abuse.
Langflow RCE is being used to mine Monero on exposed AI app endpoints. Patch, isolate, and treat public workflows as production attack surface.
VS Code Tasks supply chain attack is a package hijack pattern that can run outside npm lifecycle scripts, so scan editor configs now.
Signal backup recovery keys can expose historical chats after one phishing win. Treat messenger backups like identity infrastructure now.
FortiBleed FortiGate credentials are an active edge risk: rotate VPN and admin access now, then hunt for persistence.
FortiBleed credential theft turns compromised FortiGate firewalls into sniffers. Rotate secrets and hunt traffic capture now.
Mastra npm supply chain attack exposed AI build pipelines through more than 140 packages, so treat installs as secret exposure events.