🟠 High  |  Source: The Register — Security


A suspected Iranian-linked threat group, CyberAv3ngers, is believed to be behind coordinated cyberattacks disrupting more than 30 water treatment and distribution facilities across Minnesota. Officials have not yet formally attributed the attacks, but the group has previously targeted operational technology systems in critical infrastructure. This incident underscores the ongoing vulnerability of industrial control systems in public utilities to nation-state actors.

Security Architect’s Take: If your organisation supports or connects to operational technology (OT) or industrial control systems, urgently review network segmentation between IT and OT environments and ensure remote access to SCADA or ICS systems is restricted, MFA-enforced, and monitored — CyberAv3ngers has previously exploited internet-exposed PLCs with default credentials.

Original advisory: Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems