CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.
The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.
Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.
I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency
3 Comments
far_university1990@reddthat.com · 6 pts · 1d
I once went to company to visit science exhibit. When got to future section guide proudly say that powerplant will be connected to internet and no local staff necessary. I ask what happend once it hacked. They say company security will figure out good security protocol. Lol.
Someone need to put actual cyber security people in charge, not CEO without brain.
Malyca@lemmy.zip · 3 pts · 19h
It's the default passwords for me. If such little care goes into the public water supply, think about how much other shit is painted with a brush of incompetence?
dregan@lemmy.world · 5 pts · 1d
Absolutely should have been that way from the beginning. The fact that enforced Critical Infrastructure Protection standards only apply to power utilities is shocking.