logo

CISA roasts unnamed critical national infrastructure body for shoddy security hygiene

ID: 468200d9-eed1-5f7f-8fc4-7ed602a0880a

STIX ID: report--468200d9-eed1-5f7f-8fc4-7ed602a0880a

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-08-02

Date Updated: 2026-04-26

Author: Connor Jones

...
...

CISA and the US Coast Guard published findings from a probe of an unnamed critical infrastructure organization that uncovered severe security deficiencies—shared plaintext local admin credentials, non-unique/non-expiring passwords, insufficient logging, unrestricted remote admin access, poor IT/OT segmentation, and device misconfigurations—that could enable lateral movement and pose real-world safety risks to SCADA/HVAC systems; investigators found no evidence of active malicious activity but recommended remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.