WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Supplemental Cyber Highlights – October 3, 2023
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Supplemental Cyber Highlights – October 3, 2023

Author: April Zupan

Created: Tuesday, October 3, 2023 - 18:11

Categories: Cybersecurity

The following posts are useful for general awareness of current threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

ICS/OT/SCADA Vulnerabilities & Threats

  • Protecting the Phoenix: Unveiling Critical Vulnerabilities in Phoenix Contact HMI – Part 2 (Nozomi Networks)
  • Johnson Controls cyberattack disrupting operations, may involve sensitive DHS info (The Record)

Critical Infrastructure Resilience

  • Transforming Vulnerability Management: CISA Adds OASIS CSAF 2.0 Standard to ICS Advisories (CISA)
  • 2022 NCSR: SLTTs Excel in Recovery Planning and Mitigation (CIS)
    • A total of 3,681 SLTT government organizations participated in the 2022 NCSR. That’s up from 3,267 participants in the previous year’s report. Of those that participated, 3,122 were local organizations, 466 were state agencies, and 15 were tribal organizations.
  • SANS ICS Security Awareness – New Series: Managing Human Risk in Industrial Control System Environments (SANS)
  • Protecting Critical Infrastructure With OT Risk Management (Otorio)
  • ICS Environments and Patch Management: What to Do If You Can’t Patch (Tripwire)
  • Moxa Earns IEC 62443-4-2 Certification for Routers (ISS Source)
  • NIST SP 800-82 Rev. 3 Guide to Operational Technology (OT) Security (NIST)
  • Distributed ZTNA enables simple and scalable secure remote access to OT assets (Cisco)
  • Cyber Resilient 911 Symposium (CISA)
  • IT and OT Cybersecurity: Similar But Different (Radiflow)
  • What is NERC? Everything you need to know (Tripwire)

IT Malware, Risks, & Threats

  • Please share with your older loved ones: “Phantom Hacker” Scams Target Senior Citizens and Result in Victims Losing their Life Savings (FBI)
  • Phishing via Dropbox (Check Point)
  • Don’t Let Zombie Zoom Links Drag You Down (Krebs on Security)
  • Data never dies: The immortal battle of data privacy (Security Intelligence)
  • 4 Legal Surprises You May Encounter After a Cybersecurity Incident (Dark Reading)
  • Are You Still Storing Passwords In Plain Text Files? (SANS ISC)

IT Vulnerabilities

  • Logic Flaws Let Attackers Bypass Cloudflare’s Firewall and DDoS Protection (Heimdal Security)
  • Critical zero-days in Exim revealed, only 3 have been fixed (Help Net Security)
  • Critical Vulnerabilities: WS_FTP Exploitation (Huntress)

Ransomware

  • Ransomware gangs now exploiting critical TeamCity RCE flaw (Bleeping Computer)
  • Combating Ransomware Attacks: Insights from Unit 42 Incident Response (Palo Alto Networks)
  • 9 essential ransomware guides and checklists available for free (Help Net Security)
  • A Closer Look at the Snatch Data Ransom Group (Krebs on Security)
  • Meet LostTrust ransomware — A likely rebrand of the MetaEncryptor gang (Bleeping Computer)
  • CL0P Seeds ^_- Gotta Catch Em All! (Palo Alto Networks)

Cyber Resilience

  • Endpoint security: How to protect end users from themselves (SC Magazine)
  • The Path to the Cloud is Filled with Holes: Exploiting 4G Edge Routers (Claroty)
  • Network, Meet Cloud; Cloud, Meet Network (Security Week)

Cybersecurity Awareness Month

  • This is a good post by Cyware mostly discussing ISACs/ISAOs: Cybersecurity Awareness Month 2023: Why we need more than just cybersecurity awareness (SC Magazine)
  • Strong Password Best Practices and MFA (Fortinet)
  • AT&T Cybersecurity: championing global cybersecurity education & awareness (AT&T)

General Awareness

  • Time-to-Exploit: What It Means and Why It’s Going Down (Duo)
  • Chinese threat actors stole around 60,000 emails from US State Department in Microsoft breach (Security Affairs)

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar