< Back to all clusters
[TECHNOLOGY] · United States, Australia, United Arab Emirates, Colombia, Switzerland · 3 sources

US CISA warns water utilities of PLC cyberattacks as INC ransomware targets SonicWall devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory noting a significant rise in cyberattacks on programmable logic controllers (PLCs) used by water and wastewater utilities. Attacks have been identified in at least seven states, with Minnesota first reporting activity and Michigan confirming impacts on multiple municipal systems. While no public‑health effects have been reported, the incidents prompted boil‑water notices and forced manual operations. CISA advises operators to remove publicly exposed PLCs from the internet and cautions that Iranian actors are the leading suspect, though attribution remains preliminary.

Separately, the INC ransomware group has become the dominant threat exploiting newly disclosed vulnerabilities (CVE‑2026‑15409 and CVE‑2026‑15410) in SonicWall Secure Mobile Access 1000 series VPN appliances. The group claims 885 victims worldwide, including organizations in Australia, the United States, the United Arab Emirates, Colombia and Switzerland. Exploits involve zero‑day attacks, custom scripts and web shells to obtain credentials and maintain persistent access.

Entities: INC ransomware group · Iran · Minnesota · SonicWall · U.S. Cybersecurity and Infrastructure Security Agency

Sources

Water you waiting for? [thecyberwire.com]
about 2 hours ago