WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships (TLP:CLEAR) Supplemental Cyber Highlights – May 22, 2025
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Supplemental Cyber Highlights – May 22, 2025

TLP:CLEAR

Author: Chase Snow

Created: Thursday, May 22, 2025 - 14:58

Categories: Cybersecurity, OT-ICS Security, Security Preparedness

The following posts are useful for general awareness of current cyber threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

Critical Infrastructure Resilience

  • Critical Flaw Allows Remote Hacking of AutomationDirect Industrial Gateway | SecurityWeek
  • ‘Whatever we did was not enough’: How Salt Typhoon slipped through the government’s blind spots | CyberScoop
  • A cyberattack was responsible for the week-long outage affecting Cellcom wireless network | Security Affairs
  • DHS releases GNSS Test Vector Suite to boost PNT security for critical infrastructure | Industrial Cyber
  • Experts found rogue devices, including hidden cellular radios, in Chinese-made power inverters used worldwide | Security Affairs
  • Up to 25% of Internet-Exposed ICS Are Honeypots: Researchers | SecurityWeek

IT Vulnerability Security Updates

  • Critical Zero-Days Found in Versa Networks SD-WAN/SASE Platform | Infosecurity Magazine
  • Cisco Patches High-Severity DoS, Privilege Escalation Vulnerabilities | SecurityWeek
  • Flawed WordPress theme may allow admin account takeover on 22,000+ sites (CVE-2025-4322) | Help Net Security
  • A critical flaw in OpenPGP.js lets attackers spoof message signatures | Security Affairs

IT Malware, Threats & Risks

  • Asia Produces More APT Actors, as Focus Expands Globally | Dark Reading
  • Hazy Hawk gang exploits DNS misconfigs to hijack trusted domains | Bleeping Computer
  • Duping Cloud Functions: An emerging serverless attack vector | Cisco Talos

Ransomware

  • Breaking Down Ransomware Attacks and How to Stay Ahead | Huntress
  • OT Ransomware on the Rise: What You Need to Know and How to Prepare | SANS

Cyber Resilience, General Awareness, & AI

  • How IoT Security Cameras Are Susceptible to Cyber Attacks | Tripwire
  • How Identity Plays a Part in 5 Stages of a Cyber Attack | Tenable
  • What good threat intelligence looks like in practice | Help Net Security
  • Ransomware takes a back seat to AI on IT administrator worry lists | SC Media

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 7, 2026)

May 7, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:GREEN) Gate 15 TARGET Report – Identity Centric Attacks: The Shift from Network to Identity as the Primary Attack Surface

May 7, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) CISA and Partners Release Guidance for Careful Adoption of Agentic AI Services

May 7, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar