A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.
The recommendation comes as critical infrastructure faces increasing threats from state-sponsored actors. Water treatment facilities and distribution networks have historically relied on isolated, air-gapped control systems to prevent remote compromise.
Connecting these systems to networks—often done for remote monitoring and operational efficiency—creates significant security risks. Attackers gaining access to water system controllers could disrupt service, contaminate supplies, or cause physical damage to infrastructure.
The suspected Iranian attacks underscore the vulnerability of interconnected systems. Water utilities have increasingly adopted internet connectivity for legitimate operational reasons, but the security tradeoff remains contentious among cybersecurity experts.
The ex-NSA official's position reflects a broader debate in critical infrastructure security: balancing operational convenience against the potential consequences of compromise. Water systems serve essential public health functions, making them high-value targets for adversaries seeking to cause widespread disruption.
Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.
A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.
A critical SQL injection vulnerability in Metabase is being actively exploited in the wild to steal customer data. The zero-day attack has already compromised instances at Framework and Tally.