CISA is urging water facilities to change the default passwords on their Unitronics PLCs and disconnect them from the internet after a water treatment facility in Pennsylvania was hit by a cyberattack.
Article here (w/ input from @Gate15_Jen@WaterISAC):
https://t.co/zv91j1OKBW
We appreciate the work you and your team at @CISAgov is doing to help protect our water and wastewater systems!
Check out details on the free cyber vulnerability scanning offered for water & wastewater utilityies by CISA here - https://t.co/xpfuxiZ4cc
#cybersecurity
Q2 2023 proved to be an exceptionally active period for #ransomware groups, posing significant threats to industrial organizations and infrastructure. Learn more in our detailed analysis: https://t.co/KbT0VJBCLL #OTsecurity
The ICS[AP] CISA KEVs for CISA ICS Advisories dashboards are updated with the one known exploited vulnerability added 07/31:
CVE-2023-35801 - Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
No correlation to any CISA ICS Advisory CVEs.
#cybersecurity
New #Security Sprint! @Gate15_Jen & @andyjabbour return! New SEC Rules & #cybersecurity for everyone, not-so-subtle #China cyber threat foot-stomping plus anger, radicalization and political violence, the critical-ist of infrastructure and…so much more! https://t.co/q0IKZiXfQJ
📢 July's Cyber Threat Briefing is next week!
Join speakers from @MITREcorp and @LoudounWater to hear about Water and Wastewater OT Cyber Resilience.
WaterISAC Members Only. Details and registration here - https://t.co/1EeyV1y0IX
#cyber#resilience#water
ICS[AP] has released 2 New Interactive CISA KEV Catalog Dashboards that provide a tool to filter on CVE CVSS Vector and CWE metrics as well as a filter for the 2023 CWE Top 25 Most Dangerous Software Weaknesses. Visit: https://t.co/eqhgVQ7RSR #cybersecurity#CISA#CVSS#CWE
ICS[AP] Dashboards are updated w/9 new & updated CISA ICS Advisories released on 7/13/23:
Siemens: 4 New
Rockwell Automation: 1 New
Honeywell: 1 new
BD: 1 New
Mitsubishi Electric: 1 Update
Enphase Envoy: 1 Update
https://t.co/RYgIO2xqyD
#ICS#Cybersecurity
Check out the latest @Gate_15_Analyst Security Sprint podcast where @Gate15_Jen and I talk about hostile events, cyber-punk scams (Prime Day), weather and more! https://t.co/neLyeUCo6T
ICYMI: Dragos OT-CERT best practice blogs feature advice tailored for small-to-medium businesses, with practical insights for industrial #cybersecurity asset owners and operators, with limited experience in #OTsecurity. Check out the growing collection at: https://t.co/4Hv7lcH0ZQ
In Today's Security & Resilience Update: Cyber Threat Briefing Tomorrow, BlackLotus Mitigation Guide from @NSAGov, Research from @JumpsecLabs on New #MicrosoftTeams Vulnerability, Updated @CISACyber ICS Vulnerability Advisories & more.
Full bulletin - https://t.co/OX6WpVmbGQ