this post was submitted on 01 Aug 2026
129 points (100.0% liked)

Technology

86735 readers
4324 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

top 16 comments
sorted by: hot top controversial new old
[–] A_Random_Idiot@lemmy.world 3 points 32 minutes ago

why is any critical control equipment internet accessible.

I understand some machines might need internet to send reports and make document filings and shit. But it should not be the critical control equipment that makes the system function. And there should be a massive physical gap between the internet machines and the critical machines.

Jesus christ, even by the abysmally low bar I have for humanity, it still finds ways to dig itself a path under it.

[–] sylver_dragon@lemmy.world 46 points 2 hours ago (3 children)

The hacks target internet-facing programmable logic controllers (PLCs)

Why the fuck
is your PLC
facing the fucking internet!

Jesus Zombie Christ an a pogo stick. Has no one been paying attention for the last two decades? Seriously, we learned this sort of lesson in Two Thousand and fucking Three. Your critical assets do not get public IP addresses.

[–] atomicbocks@sh.itjust.works 1 points 16 minutes ago

2003??? We were learning this shit from Ferris Bueller back in the early 80s!!!

[–] dgriffith@aussie.zone 6 points 1 hour ago

I did some work for a company that owned a /16 public IP range and used it on their internal network. I had to put a safety rated control system on it that ran mining machines that weighed 60 tons and cost a couple of million bucks each.

They gave me a subnet range for the system that was clearly non-private and I was like, "ummmmm, is that on the Internet?"

Apparently it wasn't routed to the rest of the Internet but it always felt like it was one misconfigured router away from disaster.

[–] Godort@lemmy.ca 27 points 2 hours ago* (last edited 2 hours ago) (2 children)

It usually happens in 2 steps.

First step is that everything gets connected to the LAN and you can only access the PLC network from within the building's network. Then some time later, management finds out that keeping someone on-call to go out costs a fortune, so they request that access be made so they can make the change from anywhere.

The IT team argues security, but no new hardware can be provisioned and a developing a new process is too hard. Then the magical phrase is uttered: "Just make it work". So IT punches a hole in the firewall, adds a NAT rule, and job done.

[–] Carl@anarchist.nexus 10 points 1 hour ago

Literally this. It starts with “everything needs to be on an air gapped LAN so we can control it.” And then suddenly that air gapped LAN isn’t air gapped, because someone got tired of paying the call-out fee every time the on-call person had to drive to the site to push a few buttons on a keyboard. But figuring out a proper VPN (or at least a reverse proxy with access control) was too difficult or expensive, (management thinks the point is to save money on call out fees, not spend money on proper hardware) so they just poked a bunch of port-forwarded holes in the firewall and called it a day.

[–] sylver_dragon@lemmy.world 16 points 2 hours ago (1 children)

Sadly yes, this is exactly what happens. And it ends up being IT holding the bag at the end, with the managers having long since cashed out their stock options and left.

[–] blargh513@sh.itjust.works 1 points 41 minutes ago

"Well, we just bought this new monitoring platform from my cousin's company and they need access to it. No, their platform doesn't support any real secure protocols and won't route over a VPN, it needs to be on the same subnet as the devices. Ok, then just open all ports to the network so they can connect. No, they don't know what port or protocol, it also runs out of my cousin's house so it's on a dynamic IP so you can't create some type of access rule for it. Just put an any/any rule in and it's good. What do you mean we already have a monitoring platform? Well, this one is better!"

[–] khepri@lemmy.world 1 points 28 minutes ago* (last edited 21 minutes ago)

So are we just kind of admitting that there exists no way to expose any networked device to the internet securely? Because if it's not possible for PLCs I don't see why it would be possible for any device. If water utilities have to take these offline, then how does that advice not apply for every internet-capable device in every commercial and industrial facility worldwide?

[–] orbituary@lemmy.dbzer0.com 20 points 2 hours ago (1 children)

I am repeating what I said elsewhere on a different comm:

I call FULL bullshit on this being Iran.

I personally worked on the cybersecurity incident that happened to St Paul municipal and water systems last year as the Incident Response Technical lead.

The threat actors were not Iranian then. They were Russian.

I personally rebuilt most of their networks, VMware hosts, storage, and servers. The majority of the VMware environments did not have config backups and were running 5 and 6 branches of VMware, only two had 7+.

Their network was insecure. They had IPSEC VPNs between the various location, but there was no further security in that respect. Their firewalls were not being kept up. AAAAND... I warned them that we thought they were still compromised.

In fact, the forensics team called them out as being clean on a group call one week into the incident, but while we were on the call with leadership, they got RE-infected.

I had my team compile a massive set of recommendations for them and I wrote the report. Water Systems specifically. They did not listen to us, apparently. The forensics team also did this.

They had FBI, national guard (fucking incompetent), and law enforcement (useless) in all meetings.

If they got into Water, they’ll get back into city and municipal again. I guarantee it.

This is not Iran. It's the fucking incompetence of city government and Russian threat actors.

[–] nymnympseudonym@piefed.social 10 points 1 hour ago

Minor nit: Russia and Iran are already working together on shaheds and targeting

No surprise at all if they also coordinate cyber

[–] meathorse@lemmy.world 1 points 41 minutes ago* (last edited 38 minutes ago)

A lot of this is often down to shitty IT practices by the vendor who has little IT knowledge let alone decent security insight.

I helped support a new PCL installation (technician control PCs and software upgrade) in this exact scenario many years ago. The vendor came in expecting to treat our system as their own. Direct remote access to several over-specced, physical servers from the outside world, available on our core network, shared account names (and passwords!) across all devices, every account a local admin and their own domain admin account so they can make changes as required... Needless to say our security guy almost broke a rib from laughing so hard!

What they got was very different. I ended up doing fairly basic troubleshooting to get the shitty software working without it needing admin rights to run - XP era software running on Win7 clients so it was meeting basic folder and reg key write permissions - everything else was locked down as tight as we could. They didn't even get admin on the servers.

A few years later I heard they'd reported that our site was their most reliable. Probably due to the fact that they (or the techs) couldn't fuck with anything without our permission. Apparently their original configuration is normal in the industry... Shudder

[–] skvlp@lemmy.wtf 7 points 2 hours ago

Yup, Sleepy-Don really do have the whole Iran situation under control.