Iranian-affiliated actors are targeting US water systems through internet-exposed programmable logic controllers (PLCs), according to a recent US government advisory. Recent attacks disrupted more than 30 water systems in Minnesota, with related incidents reported across at least seven US states, although no specific actor has been formally confirmed for the Minnesota incidents.
This week’s Weekly Intelligence Summary examines how exposed remote-access services and misconfigured industrial devices can give threat actors access to operational systems, the potential consequences for water services, and the steps operators and third-party providers should take to reduce risk. It also covers actively exploited Cisco Secure FMC and Arista VeloCloud vulnerabilities, five VMware flaws, and recent activity involving Cl0p and Laundry Bear.
Download the full Weekly Intelligence Summary
See how Orpheus Cyber Threat Intelligence turns emerging threat activity into prioritised, actionable risk intelligence.