CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

  • Bytemeister@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    28 days ago

    The things you mentioned probably aren’t the problem. It’s not hard or expensive to setup secure remote access for systems.

    The real problem is that a lot of this very expensive and very specific infrastructure equipment is also very old, and frequently does not support newer and more secure protocols.

    Source : I’ve been trying to get gas generators to fire off email alerts using modern authentication with conditional access for about a week now.