WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Supplemental Cyber Highlights – August 15, 2023
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Supplemental Cyber Highlights – August 15, 2023

Author: Jennifer Walker

Created: Tuesday, August 15, 2023 - 18:04

Categories: Cybersecurity, OT-ICS Security

The following posts are useful for general awareness of current threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

ICS/OT/SCADA Vulnerabilities & Threats

  • Microsoft Discloses Codesys Flaws Allowing Shutdown of Industrial Operations, Spying (Security Week)
  • XWorm, Remcos RAT Evade EDRs to Infect Critical Infrastructure (Dark Reading)
  • The analysis of this malware is included in the security analyst section below: New SystemBC Malware Variant Targets Southern African Power Company (The Hacker News)

Critical Infrastructure Resilience

  • Enhancing OT Vulnerability Management with Visibility (SynSaber)
  • OT Security is Less Mature but Progressing Rapidly (Trend Micro)
  • Thinking outside of the box: Mastering OT security is not about defending against threats (Langner)
  • The Critical MOVEit Transfer Vulnerability and What it Means for Your OT Infrastructure (TX One)

IT Vulnerabilities & Threats

  • Indicators of Compromise Scanner for Citrix ADC Zero-Day (CVE-2023-3519) (Mandiant)
  • Almost all VPNs are vulnerable to traffic-leaking TunnelCrack attacks (HelpNetSecurity)
  • Major vulnerabilities discovered in data center solutions (HelpNetSecurity)
  • CISA: New Whirlpool backdoor used in Barracuda ESG hacks (Bleeping Computer)
  • Cyber Criminals Targeting Victims through Mobile Beta-Testing Applications (FBI Internet Crime Complaint Center)
  • How executives’ personal devices threaten business security (HelpNetSecurity)
  • Safeguarding Against Silent Cyber Threats: Exploring the Stealer Log Lifecycle (Bleeping Computer)

Ransomware Awareness

  • This was research presented at BlackHat. It’s an interesting read: ‘DoubleDrive’ attack turns Microsoft OneDrive into ransomware (SC Magazine)
    • “What if I told you that I can encrypt all your files without even infecting your computer?”
    • “When I started this research, I wanted to create a fully undetectable-by-design ransomware,” Yair explained.
  • Why detection and response technology won’t solve all ransomware attacks (SC Magazine)

Technical Posts (for security analysts, sysadmins, and other nerds)

  • From Google DNS to Tech Support Scam Sites: Unmasking the Malware Trail (Sucuri)
  • Focus on DroxiDat/SystemBC (Kaspersky Securelist)
  • Investigating New INC Ransom Group Activity (Huntress)

Cyber Resilience & General Awareness

  • 5 Ways CISA Can Help Cyber-Poor Small Businesses & Local Governments (Dark Reading)
    • WaterISAC particularly likes this one!! “1. Streamline Membership and Access to ISACs”
  • Here’s how to contain supply chain attacks (SC Magazine)
  • Email – The System Running Since 71’ (Security Week)

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 7, 2026)

May 7, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:GREEN) Gate 15 TARGET Report – Identity Centric Attacks: The Shift from Network to Identity as the Primary Attack Surface

May 7, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) CISA and Partners Release Guidance for Careful Adoption of Agentic AI Services

May 7, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar