Tag

Critical Infrastructure

All articles tagged with #critical infrastructure

Dimon Leads Expanded CEO Coalition to Fortify U.S. Infrastructure Against AI Threats

JPMorgan Chase CEO Jamie Dimon chairs the expanded Alliance for Critical Infrastructure, which now includes nearly 50 major U.S. CEOs. The group aims to coordinate defenses against AI-driven risks and cyber threats, marking a significant shift toward cross-industry collaboration on national security and economic resilience.

Tech Giants Urge Global Push to Strengthen Cyber Defences Ahead of AI-Driven Attacks
technology1 month ago

Tech Giants Urge Global Push to Strengthen Cyber Defences Ahead of AI-Driven Attacks

More than 100 firms including Google, Microsoft, Anthropic and OpenAI signed an open letter urging governments and critical‑infrastructure operators to harden cyber defences as AI makes attacks faster and more sophisticated; they call for defensive AI, testing at hospitals and water utilities, and broader, responsible access to frontier AI tools to aid defenders. The appeal follows recent breaches attributed to Chinese hackers and AI-enabled security incidents, and it comes amid policy discussions like the Kill Switch Act and warnings from experts like Geoffrey Hinton about AI risks.

Industry leaders warn AI-powered cyberattacks demand rapid, collective defense.
cybersecurity1 month ago

Industry leaders warn AI-powered cyberattacks demand rapid, collective defense.

OpenAI, Anthropic, AWS, Microsoft and 100+ organizations warn that AI-enabled cyberattacks could arrive within months and urge a coordinated push to harden critical infrastructure, raise security standards, accelerate AI-powered defense tools, and bolster threat intel sharing among businesses and governments; signatories stop short of concrete commitments, but call for action across private sector and policy makers.

Two Red-Team Breaches, Two Outcomes: CISA Links Detection Gaps to People and Processes
security1 month ago

Two Red-Team Breaches, Two Outcomes: CISA Links Detection Gaps to People and Processes

Two parallel CISA red-team assessments against two critical infrastructure orgs produced opposite results: Org A was fully compromised at the domain level with access to sensitive business systems and cloud resources, while Org B detected the phishing quickly and cut off command-and-control, then reproduced access via an assume-breach test. The common weaknesses—cleartext credentials, misconfigured AD CS, default machine account quota, static cloud keys, and over-permissioned Entra ID—are attributed more to people and processes than to tools.

US shuts down Chinese state-backed cyber operation targeting federal agencies
technology1 month ago

US shuts down Chinese state-backed cyber operation targeting federal agencies

US officials disrupted a PRC state-sponsored hacking operation tied to the QScan and QTRouter platforms, seizing domains and disabling the campaign that infiltrated U.S. agencies including DOJ, NASA, the Federal Reserve and the Senate via an IoT botnet and obfuscation network. The DOJ/FBI-led action marks a notable disruption of China’s cyber activity, while Beijing denies wrongdoing.

technology1 month ago

White House rolls out free cyber defenses for U.S. water systems

The administration plans to unveil a pilot program offering free cybersecurity services to vulnerable U.S. water facilities, beginning in Texas as a proof of concept, in response to a wave of attacks believed linked to Iran. Led by the Office of the National Cyber Director, the program would provide tools like network vulnerability scanning through private contractors, with expansion possible to other states. The effort comes amid bipartisan push in Congress and warnings from federal agencies about rising threats to water utilities and critical infrastructure, while concerns are raised about relying on private firms to fill government gaps.

DOJ seizures domains tied to China-backed hacking platforms targeting U.S. agencies
technology1 month ago

DOJ seizures domains tied to China-backed hacking platforms targeting U.S. agencies

The DOJ seized online domains used by a Chinese state-sponsored hacking group operating the QScan and QTRouter platforms, which targeted U.S. federal agencies including the Federal Reserve, U.S. Senate, Department of Justice, NASA, Energy, HHS, and NIH, as well as hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. Court filings say the group QTFY was employed by Nanjing Xinjiuwei Network Technology Company. No damage figures were disclosed, and Attorney General Todd Blanche pledged to stop such intrusions.

Putin Grants Temporary State Control Over Private Firms Hit by Drones
world1 month ago

Putin Grants Temporary State Control Over Private Firms Hit by Drones

Putin signed a decree allowing Russia to place privately owned “critical” facilities under temporary state management if they are deemed to have failed to protect against Ukrainian drone strikes, with no court order and a broad definition of what counts as critical. Legal experts warn it could be used to seize assets under the guise of security or to settle internal corporate disputes, effectively enabling redistribution of assets. The move comes amid a sustained Ukrainian drone campaign against Russia’s energy and logistics networks, with refinery strikes and drone hits on warehouses like Wildberries and Ozon; officials say the measure will be applied selectively and not as mass nationalisation, while some industry figures warn it could erode private control.

Putin authorizes temporary state control of Russia’s critical infrastructure amid Ukraine strikes
world1 month ago

Putin authorizes temporary state control of Russia’s critical infrastructure amid Ukraine strikes

President Vladimir Putin signed a decree allowing the Russian government to temporarily seize control of critical infrastructure—including fuel and energy facilities, communications, transport and logistics—when private owners fail to protect them from escalating Ukrainian attacks, a move aimed at stabilizing functioning amid fuel shortages and strikes deep inside Russia.

Iranian hackers reveal cracks in US-UK critical infrastructure
world1 month ago

Iranian hackers reveal cracks in US-UK critical infrastructure

Iran-backed hackers reportedly found vulnerabilities in U.S. and U.K. critical infrastructure, including water facilities in 12 states and a UK power plant, signaling Tehran’s intent to maximize disruption; experts warn the attacks expose lax defenses around water and energy networks and could presage further intrusions, following a U.S. advisory about Iran-linked groups targeting water systems.

Iran-linked cyberattack shuts UK small power plant down for four days
technology1 month ago

Iran-linked cyberattack shuts UK small power plant down for four days

A small UK power generator was shut for four days in July after a cyberattack attributed to hackers linked to Iran, with officials saying the wider energy system remained secure. The incident coincided with US warnings about Iranian cyber activity and led to government briefings for energy CEOs and updates to cybersecurity regulations.

Hackers Hit America's Tap Water: A Wake-Up Call for Local Infrastructure
technology2 months ago

Hackers Hit America's Tap Water: A Wake-Up Call for Local Infrastructure

A coordinated cyberattack briefly disrupted dozens of Minnesota water utilities and other states by breaching internet-connected controls at local plants, likely part of a broader Iranian operation. The incident exposed long-standing vulnerabilities in aging, under-resourced, small-town water systems and the ease with which PLCs can be accessed with weak or no passwords. While no deaths or widespread service loss occurred and taps remained drinkable, experts warn of greater risk and urge better cybersecurity, information sharing, and the possibility of unplugging critical controls from the internet to prevent future breaches.

Coordinated cyberattacks disrupt U.S. water utilities across 12 states
technology2 months ago

Coordinated cyberattacks disrupt U.S. water utilities across 12 states

A broad cyber campaign has hit local water systems in at least 12 states, causing degraded operations, pressure losses, and boil-water advisories in some areas, though drinking water remains safe. Officials point to vulnerable, internet-connected devices and long-standing underfunding of utility cybersecurity; attribution to Iran-linked actors is suspected by some, but not confirmed, as utilities increasingly shift to manual controls while defenses are strengthened.

Coordinated cyberattack targets U.S. water systems, raising security alarms
technology2 months ago

Coordinated cyberattack targets U.S. water systems, raising security alarms

A coordinated cyberattack hit the operational technology behind more than 30 U.S. water systems, including in Minnesota, over July 26–27, forcing some facilities to go offline or operate manually; Minnesota reported no drinking-water quality issues. Investigators say Iranian-affiliated actors are the leading, though not yet confirmed, suspects. The incident underscores vulnerabilities in aging, internet-connected water controls and the cybersecurity gaps facing smaller utilities, prompting CISA and EPA to urge isolating vital systems from untrusted networks and tightening access. Residents should follow official guidance, maintain emergency water, and beware scams as the nation reassesses water-system protections across roughly 170,000 U.S. facilities.

CISA warns of surge in cyberattacks on U.S. water systems after Minnesota breach
technology2 months ago

CISA warns of surge in cyberattacks on U.S. water systems after Minnesota breach

CISA warns of a rising trend of hackers targeting U.S. water and wastewater facilities by manipulating PLCs and changing passwords to lock operators, prompting boil-water notices and manual operation. Minnesota reported a coordinated attack affecting more than 30 community water systems earlier this week, with investigators briefly weighing a possible Iran link; the overall water infrastructure remains vulnerable as probes continue.