this post was submitted on 01 Aug 2026
253 points (99.6% liked)

Technology

86780 readers
4869 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

you are viewing a single comment's thread
view the rest of the comments
[โ€“] A_Random_Idiot@lemmy.world 24 points 20 hours ago (1 children)

why is any critical control equipment internet accessible.

I understand some machines might need internet to send reports and make document filings and shit. But it should not be the critical control equipment that makes the system function. And there should be a massive physical gap between the internet machines and the critical machines.

Jesus christ, even by the abysmally low bar I have for humanity, it still finds ways to dig itself a path under it.

[โ€“] uriel238@lemmy.blahaj.zone 4 points 14 hours ago

The entire tech sector screamed about the vulnerability of IoT devices, plenty of which are now participants in zombie botnets.

Does anyone remember in 2015 when YESCO billboards by the thousands were hacked to show Goatse instead of an AT&T ad? Pepperidge Farm remembers. IoTs are still vulnerable, including big municipal ones and, yes, Flock Safety cameras.

And CISA ~~was severely broken~~ had its staff severely reduced by DOGE.

In unrelated news the CDC, also a victim of DOGE, is entirely unprepared for the next epidemic.