OT Threats
Recommended Sources:
StateScoop
November 18, 2024
‘Critical’ cyber vulnerabilities found in many water utilities, warns EPA inspector general
A recent memo from the Environmental Protection Agency’s Office of Inspector General shows that 9% of the public drinking water systems it scanned last month had “critical” or “high” priority cybersecurity vulnerabilities.
SecurityWeek
September 24, 2024
OTAutomatic Tank Gauges Used in Critical Infrastructure Plagued by Critical Vulnerabilities
Bitsight finds critical vulnerabilities in several automatic tank gauge (ATG) products used in various critical infrastructure sectors.
Industrial Cyber
August 28, 2024
Critical infrastructure faces 30 percent surge in cyber attacks
A new report from security awareness training and simulated phishing platform vendor KnowBe4 revealed that critical infrastructure is under siege with cyber attacks increasing 30 percent in one year. The KnowBe4 report also identified that the consequences of these types of attacks are potentially devastating to nations, and thus geopolitical adversaries have made it a powerful addition to their arsenal of digital weapons.
Dark Reading
June 12, 2024
Rockwell's ICS Directive Comes as Critical Infrastructure Risk Peaks
Citing "heightened geopolitical tensions and adversarial cyber activity globally," industrial control systems (ICS) giant Rockwell Automation last month took the unusual step of telling its customers to disconnect their gear from the Internet. The move showcases not just growing cyber risk to critical infrastructure, but the unique challenges that security teams face in the sector, experts say.
Verdict
May 31, 2024
Cyberattacks on critical national infrastructure ‘have increased dramatically’
Cyberattacks on critical national infrastructure – the systems that are required for a country to run – continue to rise. The UK’s National Cyber Security Centre said that the country’s critical sectors were facing an “enduring and significant threat amid a rise of state-aligned groups, an increase in aggressive cyber activity and ongoing geopolitical challenges.”
FBI
April 18, 2024
Chinese Government Poses 'Bold and Unrelenting' Threat to U.S. Critical Infrastructure, FBI Director Says
FBI Director Christopher Wray on April 18 warned national security and intelligence experts, as well as students, that risks the government of China poses to U.S. national and economic security are “upon us now”—and that U.S. critical infrastructure is a prime target.
Axios
April 14, 2024
China's attacks on U.S. infrastructure aren't going anywhere
Nearly a year after the U.S. government first named and shamed an ongoing Chinese hacking campaign against American infrastructure, top cybersecurity leaders say the threat is still as palpable as ever.
Cybersecurity Drive
March 11, 2024
Ransomware attacks are hitting critical infrastructure more often, FBI says
In 2023, a total of 1,193 reported ransomware attacks reported to the FBI, more than 2 in 5 of the total number of attacks, occurred in the critical infrastructure sector. The proportion of ransomware attacks hitting critical infrastructure grew from one-third of attacks reported to the FBI in 2022. Losses reported jumped 74% to almost $60 million last year.
NPR
January 31, 2024
Wray warns Chinese hackers are aiming to 'wreak havoc' on U.S. critical infrastructure
Director Wray's Opening Statement to the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party
BusinessWire
January 24, 2024
At 13 Attacks Per Second, Critical Infrastructure is Under Siege
In the last year, the world’s critical infrastructure – the medical, power, communications, waste, manufacturing, and transportation equipment that connects people and machines – has been under near-constant attack. Forescout Research – Vedere Labs recorded more than 420 million attacks between January and December 2023. That is 13 attacks per second, a 30% increase from 2022.
Fast Company
December 22, 2023
U.S. water utilities were hacked after leaving their default passwords set to ‘1111,’ cybersecurity officials say
The White House is sounding the alarm as critical U.S. infrastructure fails to implement even the most basic cybersecurity measures as providers of critical infrastructure in the United States are doing a sloppy job of defending against cyber intrusions.
Washington Post
December 11, 2023
China's cyber army is invading critical U.S. services
The Chinese military is ramping up its ability to disrupt key American infrastructure, including power and water utilities as well as communications and transportation systems, according to U.S. officials and industry security officials. A utility in Hawaii, a West Coast port and a pipeline are among the victims in the past year, officials say.
whyy.org
December 2, 2023
Pa. water authority one of several organizations breached by Iran-affiliated hackers, federal agencies say
A small western Pennsylvania water authority was just one of multiple organizations breached in the United States by Iran-affiliated hackers who targeted a specific industrial control device because it is Israeli-made, U.S. and Israeli authorities say.
sektorcert.dk
November 14, 2023
White paper: The Attack Against Danish Critical Infrastructure
In the month of May 2023, Danish, critical infrastructure was exposed to the most extensive cyber-related attack we have experienced in Denmark to date. 22 companies, that operate parts of the Danish energy infrastructure, were compromised in a coordinated attack. The result was that the attackers gained access to some of the companies’ industrial control systems and several companies had to go into island mode operation. The report describes the most extensive, cyber-related attack against Danish, critical infrastructure that we know of so far.
Mandiant
November 9, 2023
Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology
In late 2022, Mandiant responded to a disruptive cyber physical incident in which the Russia-linked threat actor Sandworm targeted a Ukrainian critical infrastructure organization. This incident was a multi-event cyber attack that leveraged a novel technique for impacting industrial control systems (ICS) / operational technology (OT).
darkreading.com
July 31, 2023
China's Volt Typhoon APT Burrows Deeper Into US Critical Infrastructure
US officials are concerned that the Beijing-directed cyberattacks could be a precursor to military disruption and broader destructive attacks on citizens and businesses.
TechCrunch
July 24, 2023
Hackers exploit Citrix zero-day to target US critical infrastructure
Thousands of companies could be at risk from an actively exploited Citrix zero-day that hackers have already abused to target at least one critical infrastructure organization in the United States.
securityboulevard.com
July 19, 2023
Russia Expected to Increase Critical Infrastructure Attacks
Russia’s war strategy increasingly involves cybersecurity, with the country expected to ramp up attacks on critical infrastructure in Ukraine and countries that are members of NATO, according to Switzerland’s Federal Intelligence Service (FIS).
July 18, 2023
Utility Experts Highlight Chinese Threat to US Electric Grid
China poses a growing threat to U.S. electric infrastructure and could potentially disrupt the power grid, gas and pipeline systems by exploiting compromised equipment and harnessing emerging artificial intelligence technologies for cyberattacks, experts told Congress on Tuesday.
Security Intelligence
June 26, 2023
High-impact attacks on critical infrastructure climb 140%
In 2022, a 140% surge in cyberattacks against industrial operations resulted in more than 150 incidents, per a recent Waterfall Security report. In an ominous warning, the report says, “At this rate of growth, we expect cyberattacks to shut down 15,000 industrial sites in 2027, that is: in less than five years.”