You are here

Cybersecurity

(TLP:CLEAR) WaterISAC Notification – Post-Exploitation Technique Used to Maintain Read-Only Access to Fortinet SSL-VPN

Members using Fortinet FortiGate / FortiOS with SSL-VPN enabled are encouraged to review this notification and address accordingly.

What you need to know: Fortinet warns that threat actors are using a post-exploitation technique that helps them maintain read-only access to previously compromised FortiGate VPN devices even after the original attack vector was patched.

(TLP:CLEAR) Federal Partners Release Cybersecurity Advisory “Fast Flux: A National Security Threat”

Summary: Today, CISA—in partnership with the NSA, FBI, Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Canadian Centre for Cyber Security (CCCS), and New Zealand’s National Cyber Security Centre (NCSC-NZ)—released a joint Cybersecurity Advisory “Fast Flux: A National Security Threat.” This advisory warns organizations, internet service providers (ISPs), and cybersecurity service providers of the ongoing threat of fast flux enabled mal

(TLP:CLEAR) CISA Releases Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure

Summary: CISA has published a Malware Analysis Report (MAR) with analysis and associated detection signatures on a new malware variant CISA has identified as RESURGE. RESURGE contains capabilities of the SPAWNCHIMERA malware variant, including surviving reboots; however, RESURGE contains distinctive commands that alter its behavior.

(TLP:CLEAR) Water OT Systems Seen as Strategic Targets in Global Power Struggles

Summary: According to Waterfall Security’s 2024 Threat Report “OT Cyberattacks with Physical Consequences”, the overall number of cyber attacks that caused physical consequences for OT organizations was lower in 2024 than in 2023. However, attacks targeting North America’s water and wastewater sector surged in both frequency and severity over the same period. 

(TLP:CLEAR) Check Point’s Recent Assessment of Cyber Attacks in the Water Sector, What to Expect

Summary: Recent research by Check Point indicates that cyber attacks on the energy and utilities sector, including water, in North America have increased significantly. Thus far in 2025, there has been an 89% rise in weekly attack attempts per organization compared to the same time period last year.

(TLP:CLEAR) The U.S. Intelligence Community’s 2025 Annual Threat Assessment Highlights the Growing Cyber Threat to the Water Sector and the Enduring Threat of Violent Extremists

Summary: This week, the Office of the Director of National Intelligence (ODNI) published its “Annual Threat Assessment of the U.S. Intelligence Community.” The assessment focuses on the most direct, serious threats to the U.S. in 2025 and beyond and reflects the collective insights of the U.S. Intelligence Community (IC). The report notably underscores the growing cyber threat to water and wastewater utilities, as well as the heightened threat environment from violent extremists.

Pages

Subscribe to Cybersecurity