CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

  • Dave.@aussie.zone
    link
    fedilink
    English
    arrow-up
    10
    ·
    4 hours ago

    I did some work for a company that owned a /16 public IP range and used it on their internal network. I had to put a safety rated control system on it that ran mining machines that weighed 60 tons and cost a couple of million bucks each.

    They gave me a subnet range for the system that was clearly non-private and I was like, “ummmmm, is that on the Internet?”

    Apparently it wasn’t routed to the rest of the Internet but it always felt like it was one misconfigured router away from disaster.