CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The Cybersecurity and Infrastructure Security Agency and the FBI warned that Iran-affiliated hackers are stepping up attacks targeting key industrial devices in an attempt to disrupt water, energy and other municipal infrastructure sites. 

The agencies previously warned that hackers were exploiting programmable logic controllers (PLCs) from Rockwell Automation/Allen-Bradley. Iran-linked groups have since expanded their target set to include devices from Schneider Electric, Siemens and, potentially, other manufacturers, according to the updated advisory. 

The agencies also urged organizations to apply strict limitations on who can access PLC devices and validate project files running the PLCs for any unauthorized activity. Security teams should also review previous guidance from manufacturers to make sure the devices are safely configured. 

“CISA is collaborating closely with government and industry stakeholders, including PLC vendors in the advisory,” a spokesperson told Cybersecurity Dive.

A spokesperson for Rockwell Automation said the company has been working with government agencies since the original advisory was issued and reminded customers to review advisories it previously issued in 2021 and earlier this year. 

The original advisory is related to an authentication bypass vulnerability, tracked as CVE-2021-22681, but was updated in March. The flaw in Studio 5000 Logix Designer software could allow a cryptographic key to be discovered. If successfully exploited, a non-Rockwell application would be able to connect with the controller. 

Newly targeted devices include Schneider Electric BMX P34/Modicon M340 PLCs and Siemens S7-1200 series PLCs, according to the updated advisory.

In one attack, hackers used Dropbear Secure Shell software to gain remote access to a targeted system. 

Insecure operations

OT security experts warned that security teams need to take every precaution to harden entry points around these systems. 

Iran-linked threat groups have been targeting U.S. water systems since the outbreak of the Gaza war in 2023. An investigation by the Environmental Protection Agency found hundreds of U.S. sites contained critical and high-severity vulnerabilities. 

Authorities in April confirmed that a number of water and energy sites had already been targeted in attacks that caused financial losses and other damage. 

In June, Handala, a group linked to Iranian intelligence, claimed credit for an attack against California Water Service, one of the largest water systems in the U.S. Cal Water in June said an investigation found the activity was limited to specific accounts within two third-party service provider platforms. 

There was no impact on Cal Water’s internal IT or OT systems. The hackers gained access to the online account of a customer using stolen credentials, according to the company.

“Once an attacker has a credential, compromises a workstation, or enters through a service provider, the question becomes whether they have a viable path to the controllers, engineering systems, and other operational crown jewels,” said Harry Thomas, co-founder and CTO at Frenos, told Cybersecurity Dive.

Authorities said organizations should change default passwords, implement multifactor authentication, update software patches and use a VPN, network proxy, firewall or gateway to secure these devices from the open internet.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW