Speaking into the void...
Of course anyone with the slightest understanding of internet security has been screaming this for decades.
You are the feds. Start fining or shut up.
Attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities, in what five US federal agencies on Wednesday called an “active threat.” In this latest round of intrusions against American …
While the joint alert ..... doesn’t attribute the threats to a particular government or criminal group, Iranian cyber operatives are suspected of being behind recent attacks targeting PLCs at water and wastewater facilities across at least 12 states, including a cyberattack that disrupted more than 30 community water systems in Minnesota in late July.“This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs,” Cynthia Kaiser, Halcyon Ransomware Research Center SVP, told The Register
Appearances can be deceptive, perverse and subversive, and knowing what is well enough known of the crazed God's chosen few master race behaviour and computer hacking skillsets of a close Iranian neighbour and belligerent enemy, suspicion easily suggests such threats/attacks be trials and provocations of their making .... to create a corrupted reaction that continues to steer and demand an ailing and failing and bankrupted sugar daddy stay the course that leads to an increasingly more evident, self destruction.
Muppets and puppets in the Great Game running amok and trying out hallucinations as a viable base feed for future realities. And history tells one and all how that always ends for easily led tools and leading fools alike.
Take care out there. IT is an AI Jungle like nothing ever realised possible before, .... and therefore a very likely highly probable sure fire racing certainty.
And ..... way beyond all human means and memes of native solo or collective conspiratorial command and control .... so, something completely novel and ideally surprisingly rather than terrifyingly different and fully commensurate for such as be long overdue ... a Worlds Worthy Change.
And ..... just so that no one cannot plead ignorance to the fact in order to try to escape accountability for one's guilt in thoroughly unpleasant and unnecessary matters, y'all might like to think, accept and realise your actions and reactions responding to emerging freely shared news and remarkable views are directly responsible for the future different choice being surprising and good, or terrifying and bad.
who the heck thought it a good idea to put parts of critical infrastructure online?
I can only imagine it had something to do with cost cutting and convenience - no need for on premises monitoring.
The solution is obvious but now probably prohibitively expensive. A completely closed wired network. Some monitoring could still be done via the internet with careful system design, but that’s it. Just read only data.
How else do you remotely manage a fleet of unmanned locations?
I would hope that these satellite sites are behind a firewall with only VPN traffic back to the appropriate management 'hub', permitted (no open internet access)
Of cause as soon as the company LAN is compromised then all devices at your satellite sites are wide open too.
IT departments may update devices they manage (routers, servers, desktop PCs etc) but lots of other devices get put on company networks which are out of the IT departments control.
PLCs are but one...
We all have had to add security to everything with network access - this wasn't something even considered a few years ago, and it has come to applications on servers, and desktop devices, switches and routers, and has arrived on modern embedded systems. However such embedded infrastructure devices are long lived, and may not yet, been replaced with something even vaguely security capable.
IT & security managers only have so much budget, this sort of infrastructure is was often considered a lower risk of attack... but once the big ticket items became more secure the attackers move to more low hanging fruit. Yes I agree that this *should* have been considered from the very start as critical - but then that is true for everything else connected to the internet, mail severs, databases, cloud storage etc. and look how often they are compromised.
FML, you monitor them over a leased line, a phone line or some other private connection, these are critical infrastructure and it's worth the money to ensure they stay secure.
But obviously it costs money and eats into profits when the whole purpose of private business is to squeeze costs to the absolute minimum whilst extracting the maximum amount of profit.
So, a much as I hate legislation, this is one instance where it should be mandated that such CNI has to be on private networks, totally isolated from the internet
This post has been deleted by its author
Exactly this, there's some numpty in the comments on a similar article suggested hiding it all behind a Raspberry Pi.
Private circuits should beamdared, with encryption and authentication but still, private circuits.
Sure, they're expensive but nowhere near as expensive as a breach.
Okay. Does this mean that factories are going to start hiring competent network engineers, instead of having the local electrician get another 15$ hub from Amazon and put everything on the same subnet?
Are they going to set up a proper update procedure for critical systems, instead of running automation-facing software on a box that's never been patched, ever, because stopping production for 10 minutes is unacceptable?
Oh, and are automation companies going to stop selling software that only runs on Windows 7 with administrator rights? Will they stop saying that the Windows 11 version is only compatible with the newest machinery, so you can't have it unless you upgrade the entire production line for 300K?
No, not until inspectors start looking for this crap and handing fines.
Oxymoron of the century
25 years since "Win XP Embedded" poisoned the world's automation systems, and it still can't run without a framebuffer, or persistent, writeable storage (they have a kludge which can make writes to certain files/directories non-persistent i.e. will revert on next reboot, but it still can't boot from 100% read-only media). And SCADA vendors still encourage the use of VNC to administer their logic controllers.
> internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities
Everybody with more than the vaguest notions about the internet and/or computer security has known that exposing critical infrastructure is a very bad idea. Yet decision makers continue to deny the possibility that vulnerabilities (of any sort) need to be removed.
The problem with such a "head in the sand¹" approach is that sooner or later someone will use you as a bike stand
[1] Yes, I know
We've known this since the mid-1990s. I place all of the blame on personnel, humarn resources, whatever they're called these days. You should be hiring network administrators who are cynical bastards. We don't trust application developers or process control engineers when it comes to our networks, what so ever. That's not to say we don't like or respect them. Some of them would be in the running for the title of Smartest Person in the room, even if that room was The Superdome. However, just because they have multiple PhD's in chemistry or mechanical engineering on their wall, doesn't mean they understand anything about network security.
If you're in network security, and you don't upset important people on a regular basis, either you and your management aren't doing your jobs well enought, or you and your management are doing your jobs very well.
That would be Human Remains
Anyone who works in HR starts out as a bright-eyed, bushy-tailed fluffy bunny rabbit that loves hiring people and helping them in their careers, and quickly turns into a soulless hollowed-out husk as corporate reality bites.
As one cynical HR droid told me: "The role of HR is to protect the organisation from its employees." Unfortunately that often means firing / not hiring anyone with a clue, lest they embarass the executive management.
Except disasters tend to hit the vulnerable hardest while the comfortable plutocrats will blame it on another lot.
More than half of America did not vote this administration in. Telling them 'I told you so and stuff you' is unhelpful as many of them have been saying that since 2016. Resistance is futile is the administration's playbook. Only the brave might question that. Most will hope democracy corrects itself. To even have doubts it will is truly shocking but the alternative is too horrible to contemplate.
The FBI say to do some thing and say it's bad.
If the accountants/management don't say do this work to IT what happens?
I would expect IT to do the prep work. Taking external access down needs approval.
If the acces isn't revoked what happens do the FBI visit, local police visit? Is there a law that says do this?