Minacce · 59 giorni fa
Il punto non è il singolo PLC compromesso. Quando un attaccante entra nel piano di controllo, può cambiare password e indirizzi IP fino a tagliare fuori chi gestisce l’impianto, lasciando il sistema acceso ma governato solo dalle sue modifiche e costringendo il sito alla modalità manuale.
CISA segnala un forte aumento degli attacchi contro PLC esposti nei settori acqua e acque reflue. L’allerta parla di operatori bloccati, boil water notices e operazioni manuali prolungate; le indagini coinvolgono anche possibili legami con attaccanti iraniani e casi in almeno sette stati, con attenzione estesa ai cellular modem e ad altri accessi OT spesso non documentati.
Per chi gestisce infrastrutture idriche, il rischio non si ferma al perimetro visibile: un collegamento remoto dimenticato o un modem installato da terzi può diventare il varco da cui trasformare un accesso interattivo in discontinuità operativa su scala di sito.
4 fonti che coprono questa storia
The Record from Recorded Future
CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
CISA warns of cyberattacks disrupting U.S. water utilities
Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs | CISA
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector.
Part of the PlainSec briefing for 2026-08-03