You are here

Cybersecurity

ICS/OT/SCADA Vulnerability Awareness – Unitronics Vision Series PLCs | Storing Passwords in a Recoverable Format

Given recent attention and attacks against Unitronics Vision Series PLCs and their use in the water and wastewater systems sector, WaterISAC is amplifying this recent vulnerability advisory. Members using Unitronics Vision Series PLCs are highly encouraged to review the following ICS Advisory and address accordingly.

Unitronics Vision Series PLCs | ICSA-24-109-01

Vulnerability: Storing Passwords in a Recoverable Format

Threat Awareness – Global Increase in Brute-Force Attacks Targeting VPNs and SSH Services

A global increase in brute-force attacks has been identified against a variety of targets which include VPN services, web application authentication interfaces, and SSH services since at least March 18, 2024. Cisco Talos is actively monitoring the increase in attacks and is providing details on affected services.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – April 18, 2024

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – April 18, 2024

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Three Industrial Control Systems Advisories

Security Awareness – FBI Issues PSA on Social Engineering Techniques

As social engineering techniques continue to proliferate, it is still important to continually remind family, friends, and colleagues of the common themes that are designed to trick us into falling for cyber scams. As such, the FBI recently issued a public service announcement to inform individuals and businesses about current social engineering techniques, including:

Vulnerability Awareness: Palo Alto Firewalls Vulnerability and Guidance

Action may be required: Utilities using impacted PAN-OS firewalls, versions 10.2, 11.0, and 11.1 configured with GlobalProtect gateway or GlobalProtect portal (or both) and device telemetry enabled, are highly encouraged to review and address accordingly.

Over the weekend, Palo Alto Networks released workaround guidance for a command injection vulnerability (CVE-2024-3400) which affects PAN-OS versions 10.2, 11.0, and 11.1. Palo Alto Networks has reported active exploitation of this vulnerability in the wild. WaterISAC is sharing this for member awareness.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – April 16, 2024

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – April 16, 2024

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Four Industrial Control Systems Advisories

Pages

Subscribe to Cybersecurity