Tag: technology
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology…
-
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities.Anyone who visited a site carrying the affected script on July 27 and copied a…
-
Public Water Systems Are Targeted by State Actors: How to Protect PLCs and HMIs in the Operational Technology Network
We hate to say I told you so, but in our recent blog post OT Cyber Resilience and Microsegmentation for AI Attacks, we discussed how hackers are increasingly targeting operational technology networks. And they’re doing so with good reason, tactically speaking; hacking OT doesn’t just compromise customer data or encrypt business systems for a ransom……
-
To Ban or Not Ban Chinese Open-Weight AI Models
Tags: ai, backdoor, china, control, cybersecurity, data, defense, finance, government, infrastructure, international, malicious, microsoft, military, network, nvidia, open-source, openai, regulation, risk, software, supply-chain, technology, usaShould the US ban American companies from using Chinese open-weight AI models? That is the ugly question. US officials have openly expressed concerns and a desire to implement regulations. The technology community has aggressively responded, with over 20 leading AI companies, including Microsoft, Nvidia, Meta, and Dell, urging legislators not to rush imposing restrictions on…
-
US CISA Urged to Order OT Security Improvements
Minnesota Water System Hacks Should Be Call to Action, Says OTCC. The U.S. Cybersecurity and Infrastructure Security Agency should order federal agencies to secure operational technology to head off hacks like those blamed on Iran, which targeted water utilities in Minnesota this week, a trade association representing OT manufacturers and security companies said. First seen…
-
CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.” First seen on therecord.media Jump to article: therecord.media/cisa-warns-of-spike-in-water-system-attacks
-
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019.The…
-
Suspected Iranian Campaign Disrupts Minnesota Water Systems
U.S. and Minnesota investigators believe Iranian hackers were likely responsible for a cyberattack on roughly 36 municipal water systems in Minnesota, The New York Times reported Thursday. Officials cautioned that the attribution remains a preliminary assessment and could change as investigators gather more evidence. The attacks occurred Monday and were focused on technology that municipalities..…
-
FTC Sues Telehealth Firm Hims & Hers Over Data Sharing
Feds May Renew Crackdown on Violations Related to Online Health Data Trackers. The Federal Trade Commission, along with Utah and California, have filed a lawsuit against telehealth firm Hims & Hers accusing the company of using online tracking technology unlawfully by sharing consumers’ sensitive health information with third-party advertising platforms, including Meta. First seen on…
-
Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state’s technology bureau. First seen on statescoop.com Jump to article: statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/
-
CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital-systems-during-cyberattacks/
-
Nvidia Launches Open-Source AI Security Alliance
Anthropic, OpenAI and Google Absent as 37 Firms Back Open AI Security Tools. Nvidia and 36 other technology giants launched the Open Secure AI Alliance to build and share open-source AI security tools, arguing open models are critical defensive assets – while Anthropic, OpenAI and Google, makers of the most capable closed models, are absent…
-
NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security
Tags: ai, crowdstrike, cyber, cybersecurity, linux, microsoft, nvidia, open-source, technology, toolNVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance. This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open…
-
Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
Tags: advisory, automation, cisa, cyber, cybersecurity, exploit, hacker, infrastructure, Internet, iran, technology, threatIranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation, Schneider Electric, and Siemens, targeting U.S. critical infrastructure sectors. A joint cybersecurity advisory (AA26-097A) released by the FBI, CISA, NSA, DOE, EPA, Treasury, and U.S. Cyber Command highlights sustained exploitation activity against operational technology…
-
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
Tags: advisory, cyber, cybersecurity, defense, email, espionage, exploit, government, group, hacker, russia, technology, threat, vulnerability, zero-dayRussian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education,…
-
Exclusive signs ServiceNow to bolster AI options
Distributor makes vendor signing as Sophos warns criminals are using the technology to launch more attacks First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366646176/Exclusive-signs-ServiceNow-to-bolster-AI-options
-
KI greift eigenständig an Unternehmen müssen ihre Cyberabwehr neu denken
Die aktuelle Berichterstattung ruft erschreckende Zukunftsszenarien wach: Zum ersten Mal wurde ein selbstständiger Hackerangriff durch eine künstliche Intelligenz bekannt. Der KI-Anbieter OpenAI meldet einen neuartigen Sicherheitsvorfall, hervorgerufen von einer unternehmenseigenen KI-Technologie. Dan Schiappa, President Technology and Services bei Arctic Wolf, erklärt, was die Evolution eigenständig angreifender KI für die Cyberbedrohungslandschaft bedeutet. ‘KI ist zunehmend in…
-
Agentic AI Challenges Progress in Confidential Computing
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/agentic-ai-challenges-progress-in-confidential-computing
-
How AI-Driven Robotics Expands Industrial Cyber Risk
CEO: Connected Factories and Hospitals Expose Legacy OT Systems to Modern Threats. Claroty CEO Yaniv Vardi says physical AI will accelerate robotics and industrial automation while making cyber-physical security a strategic priority as connected operational technology exposes critical infrastructure to attacks with real-world consequences. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-ai-driven-robotics-expands-industrial-cyber-risk-a-32303
-
Japan Bets Big on AI-Powered Robots
Physical AI Plays to Decades of Industrial Manufacturing Strength. Japan is backing a different vision for artificial intelligence. As countries race to build more powerful language models, Tokyo is investing in physical AI, betting its decades of experience in robotics and manufacturing can shape the technology’s next phase. First seen on govinfosecurity.com Jump to article:…
-
KeeperPAM strengthens privileged access management for global construction SaaS provider Asite
Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations. The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform…
-
DigiCert expands its EMEA channel strategy with Ignition Technology
DigiCert,”¯a global leader in intelligent trust, has announced a strategic distribution partnership with Ignition Technology to scale its presence across EMEA, accelerate market entry and expand partner-led growth. Through the partnership, Ignition will bring DigiCert ONE® to customers and partners across the UK and Ireland, DACH, France,”¯Benelux”¯and the Nordics.”¯DigiCert’s”¯comprehensive platform unifies PKI,”¯DNS”¯and automated certificate lifecycle…
-
F5 CEO On Massive AI Security Opportunity: LLMs Are ‘A Vulnerable Technology Today’
F5 is doubling down on enabling solution and service providers to capitalize on surging AI adoption through the recent launch of its unified platform for discovering, testing and securing AI models, according to F5 CEO François Locoh-Donou. First seen on crn.com Jump to article: www.crn.com/news/security/2026/f5-ceo-on-massive-ai-security-opportunity-llms-are-a-vulnerable-technology-today
-
Digitale Zertifikate für die Gebäudeautomation
Moderne Gebäude sind hochkomplex egal ob Büroflächen, Krankenhäuser, Flughäfen oder beispielsweise Rechenzentren. Zutrittskontrolle, Heizung, Belüftung, Brandmeldesysteme, Sicherheitskameras und vieles mehr: alles ist heute vernetzt und kann im Zweifel remote überwacht oder gewartet werden. BxC Security, ein Cybersicherheitsunternehmen für den Bereich Operational Technology (OT) und Industrial Internet of Things (IIoT), erklärt, warum vernetzte Gebäudetechnik zum… First…
-
Attackers are Exploiting Trust in 2026, not Just Technology
Attackers are exploiting trust, not just technology, making continuous identity verification more critical than ever. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/attackers-are-exploiting-trust-in-2026-not-just-technology/
-
Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation
Tags: technologyDemocratic Sen. Ron Wyden says the Trump administration should pressure Canada not to enact a proposal that would “weaponize American technology infrastructure” for surveillance purposes. First seen on therecord.media Jump to article: therecord.media/canada-lawful-access-act-surveillance-wyden-letter
-
Palantir: Can anyone else do what it does?
Palantir is a US defence-intelligence company, born from the CIA’s venture arm that now operates inside the UK public sector. We examine the claim that its technology does what no other supplier can First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645878/Palantir-Can-anyone-else-do-what-it-does
-
Ukrainians rally against dismissal of tech-minded defense minister Fedorov
Ukraine President Volodymyr Zelensky dismissed Defense Minister Mykhailo Fedorov, who championed the push to integrate drone technology and digital innovation into the military. First seen on therecord.media Jump to article: therecord.media/ukraine-fedorov-drones-dismissal
-
UK Sees Data Infrastructure, Water System Cyberattack Risks
National Risk Assessment Cites CrowdStrike Lessons Learned, Hybrid Warfare Risks. The British government’s latest national security risk register sees a rising threat posed by cyberattacks disrupting operational technology in more critical national infrastructure sectors, and cites the CrowdStrike outage in digital resilience failure lessons to be learned. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/uk-sees-data-infrastructure-water-system-cyberattack-risks-a-32239

