Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Critical Infrastructure Security - CISA Urges Action as Attackers Exploit Critical Systems Using Basic Tactics
Critical Infrastructure Security Attacks Latest News News & Analysis Security Threats and Vulnerabilities

CISA Urges Action as Attackers Exploit Critical Systems Using Basic Tactics

ISB Staff ReporterBy ISB Staff ReporterSeptember 30, 2024Updated:November 8, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Critical Systems
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Cybersecurity and Infrastructure Security Agency (CISA) has once again raised alarms about the ongoing exploitation of operational technology (OT) and industrial control systems (ICS) across critical infrastructure sectors.

The warning comes amid an active investigation into a cybersecurity incident at the City of Arkansas’s Water Treatment Facility, which was targeted early Sunday on 22 September, 2024.

While the City of Arkansas City has reassured residents that its water supply remains safe and operations continue uninterrupted, the incident shines a light on the fact that malicious actors are targeting vital OT/ICS systems using relatively unsophisticated methods.

Unsophisticated Attacks Still a Major Threat

In its recent advisory, CISA detailed how attackers are capitalizing on exposed and vulnerable OT/ICS systems, particularly in the Water and Wastewater Systems (WWS) sector. The simplicity of these attacks is what makes them so concerning.

Systems that fail to implement fundamental security measures—such as changing default credentials and restricting internet access—are prime targets for bad actors.

CISA’s warning is the latest in a series of alerts concerning the vulnerability of OT/ICS systems. As the technology running critical infrastructure becomes more interconnected, it remains a high-value target for threat actors.

According to the agency, malefactors are exploiting internet-accessible devices using default credentials, brute force attacks, and other basic techniques, often with severe consequences.

Arkansas Incident Underscores Broader Risk

In the case of the Arkansas Water Treatment Facility, City Manager Randy Frazer emphasized that there was no impact on water quality or service disruption. As a precaution, the plant switched to manual operations, and enhanced security measures have been implemented.

Although no immediate damage was reported, cybersecurity experts warn that this incident could be a precursor to more serious attacks. Water treatment facilities, often under-resourced in cybersecurity defenses, are attractive targets for attackers looking to cause widespread panic or extort municipalities.

CISA’s Call to Action for OT/ICS Operators

CISA has urged operators in critical infrastructure sectors to follow best practices outlined in its report, Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity. Recommendations include securing OT/ICS systems by changing default credentials, patching vulnerabilities, and segmenting critical devices behind firewalls.

CISA also stressed the importance of adhering to secure-by-design principles, ensuring that security is baked into the architecture of critical systems rather than being an afterthought.

To further assist operators, CISA has made available its Cross-Sector Cybersecurity Performance Goals, offering guidance on how to protect against the most common and impactful cyber threats.

Expert Commentary: Emphasizing Practicality and Efficiency

Evan Dornbush, a former NSA cybersecurity expert, weighed in on the practicality of CISA’s recommendations.

“CISA’s guidance of recommended practices may be ideal for defenders who are well-staffed or are perhaps building out new networks. But for established OT/ICS operators, the reality of changing default passwords, patching, and moving HMI devices behind firewalls or hardened VNC can be laborious,” said Dornbush.

Instead, he advocates for a more streamlined approach: “Keeping with the defense-in-depth philosophy, it may be more efficient for operators to add a network detection capability to their existing infrastructure. Using modern advancements in computation, the market is full of quality options for those looking to glean intelligence from their network data.”

Additionally, subscribing to a cyber threat intelligence platform can be a low-effort way for operators to stay ahead of known exploited vulnerabilities (KEVs), guiding their efforts to protect the most critical aspects of their infrastructure.

ISB Staff Reporter
  • ISB Staff Reporter
    Mass Exploit Lets Attackers Install Plugins Arbitrarily
  • ISB Staff Reporter
    Cyberattacks Soar 47% Globally – Attacks on Education Increase by 73%
  • ISB Staff Reporter
    CISA Warns of Two Known Exploited Vulnerabilities
  • ISB Staff Reporter
    JFrog Becomes an AI System of Record, Debuts JFrog ML

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The evolution of cyber risk: Addressing geopolitical threats

May 13, 20265 Mins Read

“Recovery Is the New Prevention”: a Q&A with CSO of Health-ISAC, Errol Weiss

May 7, 20266 Mins Read

Pro-Russian threat actors target Swedish heat and power plant in failed cyberattack

April 20, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}