Inside the North American Water Utility Hacking Crisis

Inside the North American Water Utility Hacking Crisis

Inside the North American Water Utility Hacking Crisis: Iran Links, PLC Tactics, Insurance Fallout, and Volunteer Fixes This special Cybersecurity Today episode examines the expanding wave of water utility intrusions across North America, including a WIRED-obtained memo linking attacks on Minnesota systems to Iran and a joint FBI/EPA alert reporting activity in at least seven U.S. states targeting internet-exposed Rockwell MicroLogix PLCs by rewriting configurations, altering passwords, and manipulating project files, with effects like loss of pressure, flooding, and tampered operator displays. It also covers a separate Quebec incident in Saint-Noël shared by "Z Pen Test Alliance," where attackers adjusted chlorine settings and the plant entered safe mode without contamination. The show reviews competing attributions (Cyber Avengers vs. Hondala), procurement and triage challenges for small utilities, an insurance war game simulating a mass water-sector crisis, concerns about uninsurability and act-of-war exclusions, and the DEF CON Franklin volunteer program helping rural utilities implement basics like password resets, MFA, and incident response plans.

00:00 Sponsor NordLayer 00:37 Deep Dive Setup 01:25 Iran Linked Water Hacks 02:27 Attack Mechanics Impact 03:38 Who Did It 04:13 Canadian Utility Breach 04:54 BSides Lessons Learned 05:51 Insurance War Game 07:59 Uninsurable Risk Fixes 09:00 DEF CON Franklin Volunteers 10:11 Franklin Findings Challenges 11:24 Local Sharing Next Steps 11:55 Wrap Up Listener Notes 12:46 Sponsor NordLayer Again

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(100)

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next   In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—for...

22 Aug 36min

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA ...

21 Aug 14min

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where V...

19 Aug 12min

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 lead...

17 Aug 9min

Cybersecurity Today Weekend Month in Review: August 2026

Cybersecurity Today Weekend Month in Review: August 2026

AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July devel...

15 Aug 56min

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Windows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that explo...

14 Aug 11min

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carr...

12 Aug 9min

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulner...

10 Aug 16min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
popradet
stopp-verden
dine-penger-pengeradet
nokon-ma-ga
rss-gukild-johaug
det-store-bildet
rss-espen-lee-usensurert
hanna-de-heldige
rss-ness
rss-penger-polser-og-politikk
aftenbla-bla
lydartikler-fra-aftenposten
e24-podden
frokostshowet-pa-p5
rss-borsmorgen-okonominyhetene
grasoner-den-nye-kalde-krigen