You are here

Cybersecurity

(TLP:CLEAR) AWWA’s New and Revised Cybersecurity Resources

Summary: WaterISAC is pleased to share that the American Water Works Association (AWWA), with the help of many subject matter experts (SMEs) within the water sector including WaterISAC, has released significant updates and revisions to its cybersecurity resources to aid utilities in building their cyber resilience. This comes as water and wastewater systems in the U.S.

(TLP:CLEAR) Fortinet Report: 2025 State of Operational Technology and Cybersecurity

Summary: Fortinet recently released its “2025 State of Operational Technology and Cybersecurity Report” which draws on data from a global survey of more than 550 OT professionals conducted by an independent research firm. The report highlights key areas where organizations need to bolster their defenses, especially as IT and OT environments become interconnected and exposed.

(TLP:CLEAR) Active Exploitation of CitrixBleed 2 (CVE-2025-5777), Check for Compromise Even if You’ve Patched

Summary: Due to several security research companies’ findings of active exploitation of a high-severity vulnerability in Citrix devices affecting NetScaler ADC and Gateway (CVE-2025-5777) dubbed CitrixBleed 2, members are encouraged to check for probing or compromise of these devices.

(TLP:CLEAR) Cross-Sector ISAC Report: Threat Overview and Mitigations for the North Korea IT Worker Problem

Summary: WaterISAC is sharing a cross-sector report co-authored by several leading Information Sharing and Analysis Centers (ISACs), including WaterISAC, that focuses on the continuing threat of North Korea IT workers on U.S. organizations. The report brings further awareness to what appears to be an enduring threat that many communities and sectors may not fully understand or appreciate the extent of.

(TLP:CLEAR) High Severity Vulnerabilities Patched in Fortinet and Ivanti Products (Updated June 26, 2025)

June 26, 2025

Summary: WaterISAC’s federal partners have shared new information indicating that nation state threat actors who routinely target critical infrastructure are actively researching the below vulnerabilities in Fortinet products, which could allow them to conduct future attacks.

Pages

Subscribe to Cybersecurity