Skip to content

Water utility cyber incidents across at least seven U.S. states disrupted monitoring and control across at least seven U.S. states

Share
Source: Badtech.org

CBS News, NBC News, and CNN Newsource via KEYT reported that the FBI and EPA said water and wastewater utilities in at least seven U.S. states experienced malicious cyber incidents, with some activity degrading operations. The reporting says the activity targeted internet-facing programmable logic controllers, or PLCs, which utilities use to monitor and control equipment such as pumps, valves, pressure and chemical processes.

Those outlets reported that more than 30 Minnesota community water systems were affected. Some utilities temporarily shifted to manual operations, and reported impacts included loss of monitoring or control; some accounts also described pressure-related disruption. The supplied reporting says no contamination of Minnesota water supplies had been reported.

CBS News and NBC News said CISA urged operators to remove publicly exposed PLCs and other OT from the internet, secure necessary external connections, strengthen passwords, and review access controls. CBS News and CNN Newsource via KEYT also reported that U.S. investigators were examining possible Iranian involvement, but no formal attribution had been made.

Sources

Read more

Oracle August 2026 CPU ships 943 patches, including critical unauthenticated flaws in Fusion Middlew

Oracle released its August 2026 Critical Security Patch Update on August 18 with 943 new patches across its enterprise software portfolio, including 262 for Fusion Middleware, 120 for E-Business Suite, and 66 for Commerce. Covered products include WebLogic Server, PeopleSoft Enterprise PeopleTools, Oracle Internet Directory, Oracle Identity Manager, WebCenter,

By Adam Field Source: Badtech.org

Microsoft August Patch Tuesday includes exploited Windows privilege-escalation flaw and two publicly

Microsoft’s August 11 Patch Tuesday addressed hundreds of vulnerabilities across Windows, Office, Azure, Exchange Server, SharePoint, .NET, Teams, and other products. Qualys ThreatPROTECT and CyberHub Podcast counted 421 fixes, while other supplied coverage reported lower totals, with the difference attributed to counting method or update scope. The most urgent

By Adam Field Source: Badtech.org