logo

CISA Alert: Water Sector PLC Targeting

Posted by speckx |5 hours ago |39 comments

fathermarz 6 minutes ago

https://www.linkedin.com/pulse/end-complacency-i-can-hope-an...

I much prefer the non-vendor perspective on this. Andy Krapf, co-chair of the Water ISAC, has a great breakdown about the status quo systemic problems that water faces today.

ilikeitdark13 7 minutes ago

Some people allegedly say that the US should treat heads of companies like they do in China, when found guilty of certain crimes. Allegedly.

BlackRabbit1 2 hours ago[1 more]

> Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts).

Describe the network security of the industrial automation industry and their customers in a single statement. Lol.

pudgywalsh 3 hours ago[8 more]

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will.

CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration.

Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords. You cross a threshold where you're being deliberately careless.

When you are putting more effort into securing your Plex server on your home network then public utilities are taking on machinery that dumps chemicals into the local water, something is not right and finger-pointing isn't going to fix it.