You are here

Cybersecurity

(TLP:CLEAR) Water OT Systems Seen as Strategic Targets in Global Power Struggles

Summary: According to Waterfall Security’s 2024 Threat Report “OT Cyberattacks with Physical Consequences”, the overall number of cyber attacks that caused physical consequences for OT organizations was lower in 2024 than in 2023. However, attacks targeting North America’s water and wastewater sector surged in both frequency and severity over the same period. 

(TLP:CLEAR) Check Point’s Recent Assessment of Cyber Attacks in the Water Sector, What to Expect

Summary: Recent research by Check Point indicates that cyber attacks on the energy and utilities sector, including water, in North America have increased significantly. Thus far in 2025, there has been an 89% rise in weekly attack attempts per organization compared to the same time period last year.

(TLP:CLEAR) Supply Chain Compromise of Third-Party GitHub Action, CVE-2025-30066

Summary: A popular third-party GitHub Action, tj-actions/changed-files (tracked as CVE-2025-30066), was recently compromised. This GitHub Action is designed to detect which files have changed in a pull request or commit. The supply chain compromise allows for information disclosure of secrets including, but not limited to, valid access keys, GitHub Personal Access Tokens (PATs), npm tokens, and private RSA keys. This has been patched in v46.0.1. 

(TLP:CLEAR) Mitigating People’s Republic of China (PRC) Living Off the Land (LOTL) Techniques Training Course

Summary: CISA is hosting a training course titled “Navigating the Storm - Understanding, Detecting, and Mitigating PRC LOTL Techniques in Critical Infrastructure Training Course.” The two-hour session will include presentations by CISA and the FBI and will help participants gain insights into the sophisticated methods used by PRC-actors to help them blend into legitimate network activities to avoid detection.

(TLP:CLEAR) DEF CON Franklin - Securing Water Infrastructure in Rural Communities

Summary: A new collaboration initiative called DEF CON Franklin has established a Cyber Volunteer Task Force for water that provides DEF CON technologist volunteers to critical infrastructure in need of cybersecurity help. The effort is being established between the Cyber Policy Initiative (CPI), DEF CON, and NRWA. It specifically targets water systems across the nation that are the most vulnerable  and least protected from cyber threats.

(TLP:CLEAR) Supplemental Cyber Highlights – March 20, 2025

The following posts are useful for general awareness of current cyber threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

Critical Infrastructure Resilience & OT/ICS Vulnerability Management

Pages

Subscribe to Cybersecurity