Ransomware Resilience – MFA Bypass is Seen as the Largest Attack Vector for Ransomware Attacks
As ransomware threat actor tactics continue to advance, it’s important to remember that common cybersecurity “best-practices” are also in flux.
As ransomware threat actor tactics continue to advance, it’s important to remember that common cybersecurity “best-practices” are also in flux.
On Sunday, a cyber attack on a water utility in Arkansas City, Kansas prompted its treatment facility to revert to manual operations. The city manager, Randy Frazer, confirmed that the water supply remains unaffected and safe, with no disruption to service reported. The plant's manual operation is a precautionary measure to enhance security while the situation is being addressed. Arkansas City has notified relevant authorities and is collaborating with cybersecurity experts to manage the incident, which is believed to be a ransomware attack.
The following posts are useful for general awareness of current cyber threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.
Critical Infrastructure Resilience
In practice, a microgrid is a miniature version of the main electric grid but has the ability to connect and disconnect its power generation sources from the grid as needed. This makes microgrids a valuable resource for water and wastewater utilities offering redundancy when it comes to keeping the power on. However, while utilities may be using microgrids for a variety of necessary reasons, it’s important to assess the threat landscape that these systems could pose as they can potentially open your utility up to a variety of additional threats and vulnerabilities.
Yesterday, The NSA, FBI, the U.S.
Yesterday, the EPA released “Improving Cybersecurity at Drinking Water and Wastewater Systems”, developed to assist owners and operators of drinking water and wastewater systems with assessing gaps in their current cybersecurity practices.
The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS security advisories, along with additional alerts, updates, and bulletins:
ICS Advisories:
In today's digital landscape, cyber attacks are not a question of if, but when. Traditional cybersecurity strategies often focus solely on prevention, which may have been sufficient in the past, but is now becoming more and more inadequate. Adopting a cyber resilience framework helps shift this perspective, prioritizing readiness to mitigate impacts and facilitate swift recovery from cyber threats. With the threat of cyber attacks rising, establishing a proactive framework for managing and recovering from threats is essential.
While service accounts often enhance productivity and perform essential automated functions for organizations of all sizes, if left unchecked they can pose a serious security hazard. In 2023, as many as 94% of organizations were found to have a lack of visibility into their service accounts, highlighting the prevalence and potential severity of this vulnerability.
CISA has published an analysis and infographic outlining the results from 143 Risk and Vulnerability Assessments (RVAs) conducted by both CISA and the US Coast Guard across various critical infrastructure sectors during fiscal year 2023 (FY23).