You are here

Cybersecurity

(TLP:CLEAR) Fake Browser Update Threats Observed on Water Industry-Related Websites

Summary: WaterISAC has been made aware of water industry-related websites that have been infected with SocGholish malware. Certain links on these websites have been observed re-directing users to fake browser update webpages. This is done to trick the user into downloading a payload which ultimately infects the system with SocGholish malware.

(TLP:CLEAR) Multiple Vulnerabilities in VMware ESXi, Workstation, and Fusion Could Allow for Local Code Execution

Summary: On March 3, 2025, Broadcom patched three actively exploited vulnerabilities, all of which threat actors are actively exploiting, affecting VMware ESXi, Workstation, and Fusion products that could lead to code execution and information disclosure. These vulnerabilities affect VMware ESXi versions 7.0 and 8.0, VMware Workstation 17.x, and VMware Fusion 13.x.

(TLP:CLEAR) INL Partners with the State of Florida to Safeguard Water Infrastructure Against Cyber Threats

Summary: The Idaho National Laboratory (INL) and the state of Florida are working together on an innovative cybersecurity project focused on safeguarding Florida’s water infrastructure from cyber threats. The Florida Institute for Cybersecurity Research at the University of Florida (UF) will lend support and expertise to the program.

(TLP:CLEAR) Supplemental Cyber Highlights – March 6, 2025

The following posts are useful for general awareness of current cyber threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

Critical Infrastructure Resilience & OT/ICS Vulnerability Management

(TLP:CLEAR) Supplemental Cyber Highlights – February 27, 2025

The following posts are useful for general awareness of current cyber threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

Critical Infrastructure Resilience & OT/ICS Vulnerability Management

Pages

Subscribe to Cybersecurity