Tag: critical infrastructure
574 articles

US Treasury Targets Iranian Hackers in Cyber Sanctions Push
The US Treasury Department has launched a bold crackdown on Iranian hackers, designating four individuals for sanctions for their alleged roles in targeting critical US infrastructure and stealing sensitive information. This economic onslaught aims to disrupt Iran's global financial connections and hold its malicious cyber actors accountable.

Iran-linked hackers disrupt UK power plant operations
A recent cyberattack linked to Iran caused a small UK power plant to shut down, but fortunately, the incident was contained and posed no risk to the broader energy system. The UK government assured that the country's energy infrastructure is highly resilient and that they're working closely with the sector to protect it.

US Warns of AI-Powered Attacks on Siemens PLCs
The US government has issued a stark warning: hackers are harnessing the power of artificial intelligence to launch targeted attacks on vulnerable Siemens PLCs, critical infrastructure devices used in water, energy, and manufacturing sectors. This is no hypothetical threat - it's a very real and active danger.

Iranian Hackers Expose UK Power Plant Vulnerability
Can a UK power plant vulnerability leave millions in the dark? Iranian hackers recently caused a four-day blackout at an unnamed UK facility, raising concerns about the potential for a larger, more critical attack.

ASPI Celebrates 25 Years of Shaping National Security Debate
For 25 years, ASPI has been at the forefront of shaping Australia's national security debate, providing critical insights that challenge the status quo and inform government decision-making. From its roots in 2001, ASPI has remained committed to delivering contestable advice, fostering public discussion, and cultivating the next generation of security leaders.

US Urges AI Sector to be Designated Critical Infrastructure
The US government is being urged to recognize the AI sector as critical infrastructure, a designation that would highlight its importance to the country's well-being and security. This call to action comes from a new report by Americans for Responsible Innovation, which argues that the AI sector already has all the hallmarks of a vital industry.

US Agencies Warn of AI-Fueled Attacks Targeting Industrial Controls
Threat actors are now using AI to supercharge their attacks on industrial control systems, dramatically lowering the bar for technical expertise and development time. This alarming evolution puts critical facilities like water, energy, and food production at risk.

Feds Warn of AI-Generated Code Threat to Critical Infrastructure Controllers
The feds have issued a dire warning: AI-generated code is being used to actively threaten critical infrastructure controllers, putting industries like water, energy, and manufacturing at risk. This is a very real and present danger, not just a hypothetical threat.

US Agencies Warn of AI-Driven Attacks on Siemens PLCs
US agencies have sounded the alarm on a growing threat: hackers are using artificial intelligence to launch automated attacks on critical infrastructure, including factories, power plants, and water systems, by targeting Siemens PLCs. This active threat has prompted a joint warning from the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency.

CISA Warns of Active Exploitation of Critical Flaws in macOS, SharePoint, vCenter, and Microsoft IKE
Critical flaws in macOS, SharePoint, vCenter, and Microsoft IKE are under active attack, with 361 victim IP addresses across 47 countries already compromised. CISA has sounded the alarm, adding these vulnerabilities to its Known Exploited Vulnerabilities catalog.

Medusa Ransomware Targets Over 500 Infrastructure Orgs, Expands Tactics
Medusa ransomware has hit a staggering 500+ critical infrastructure organizations, with healthcare being a prime target, as reported in a recent FBI advisory. The attacks are happening at an alarming rate, with exploitation windows as short as 24 hours or even less.

Medusa Ransomware Targets Over 500 US Critical Infrastructure Orgs
The Medusa ransomware gang has struck a staggering 500+ US critical infrastructure organizations across multiple sectors, including healthcare, defense, and finance, since June 2021. This alarming surge in attacks has prompted a joint warning from top US agencies, highlighting the urgent need for heightened cybersecurity measures.

Autonomous AI Attacks Target Critical Infrastructure
The threat of autonomous AI attacks on critical infrastructure is no longer a distant possibility, but a looming reality that could unleash devastating kinetic disasters, warns Tom Kellermann, VP of AI security and threat research at TrendAI. The perfect storm of rising geopolitical tension and increasingly powerful off-the-shelf AI agents makes a crippling attack on our infrastructure not just plausible, but imminent.

US Space Command Urges Evolution in Protecting Space Assets
The US Space Command is pushing for a major upgrade in protecting its space assets, driven by a key lesson from recent conflicts: fixed infrastructure is a sitting duck for enemy attacks. Gen. Stephen Whiting cites Iranian drone and missile strikes during Epic Fury, which damaged multiple radar sites and exposed the vulnerability of high-value systems.

Gunra Ransomware Targets Infrastructure via Fortinet Flaws
Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

US Abruptly Halts Voting System Security Review
The government's sudden halt of a voting system security review has left experts stunned, with the CEO of Mojave Research, Jason Wareham, calling it one of the worst decisions of his life. The six-week federal engagement, which had grown to involve around 60 people, was abruptly shut down just as the team was set to press forward.

Water Utilities Fortify Defenses Against Rising Cyber Threats
The Water Watch Center, a game-changing partnership between the National Rural Water Association and DEF CON Franklin, is revolutionizing cyber defense for small water systems by providing targeted support against rising threats. This innovative hub brings together top cyber firms to safeguard community water systems serving fewer than 10,000 people.

US Local Governments Targeted in Wave of Cyber Attacks
Local governments are under siege, with a growing wave of cyber attacks crippling their operations - just like Suisun City, which was forced to declare a state of emergency after a malicious software attack shut down its entire IT network. The attacks are leaving communities vulnerable, with city services and internal operations grinding to a halt.

DEF CON Bolsters Water Utility Cyber Defenses With AI, Managed Detection
DEF CON and the National Rural Water Association are teaming up to revolutionize cyber defenses for small water utilities, which make up 98% of the nation's water systems, by launching the Water Watch Center, a managed cybersecurity program. This game-changing initiative will bring AI-powered protection and expert support to these vulnerable yet critical organizations.

Ex-NSA Chief Warns of Water System Cyber Risks
Retired General and ex-NSA chief Paul Nakasone warns that water systems are vulnerable to cyber threats, urging stricter defenses and cautioning that PLCs should be kept offline. He calls for higher standards and new partnerships to protect critical infrastructure.

Thousands of U.S. Water System Controllers Remain Exposed Online
A recent scan revealed over 4,000 vulnerable water system controllers exposed to the public internet, including 22 in cities that have already faced cyberattacks on their water and wastewater systems. This alarming discovery highlights the urgent need for increased security measures to protect these critical systems.

FBI, EPA Warn Water Sector of Rising Cyberattacks
Water and wastewater utilities in at least seven states have come under cyberattack, with internet-facing programmable logic controllers (PLCs) compromised, causing operations disruptions, pressure loss, and flooding. The FBI and EPA have sounded the alarm, warning of the growing threat to the water sector.

Rockwell PLCs Exposed in Water Utilities Hit by Cyberattacks
A recent scan revealed 4,407 Rockwell Automation programmable logic controllers (PLCs) exposed to the public internet, including 2,844 in the United States, leaving critical water utilities vulnerable to cyberattacks. Many of these exposed PLCs are concentrated in areas that have already reported recent cyber incidents, raising serious security concerns.

Australia's Housing Crisis Threatens Strategic Interests
In northern Australia, the housing crisis is sounding alarm bells - employers are struggling to attract and retain workers due to dire housing shortages, threatening critical infrastructure, defence expansion, and the region's ability to support national priorities. It's a pressing issue that's limiting recruitment, delaying projects, and putting the region's growth at risk.