Top stories.
- CISA warns of cyberattacks targeting PLCs in the water sector.
- Russian espionage group tied to hotel WiFi hijacking campaign.
- INC ransomware gang claims credit for Australian healthcare provider hack.
CISA warns of cyberattacks targeting PLCs in the water sector.
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory warning of a "significant increase" in threat actors targeting programmable logic controllers (PLCs) in the water and wastewater sectors. The attacks have targeted systems in at least seven states: Minnesota first disclosed the activity, and Michigan later confirmed attacks affecting multiple municipal systems, though officials said there were no public health impacts. The New York Times says US officials consider Iran the leading suspect, but they stress the attribution remains preliminary and lacks definitive forensic proof.
CISA urges "critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible," noting that threat actors "have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses." CISA says this activity has led to boil water notices and long-term manual operations.

