CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
ID: 2c3641e0-8c59-54e8-8e1a-06e0464bb95c
STIX ID: report--2c3641e0-8c59-54e8-8e1a-06e0464bb95c
Feed Name: Security Affairs
CISA and state investigators are responding to coordinated attacks that impacted operational technology at over 30 Minnesota water systems (with PLC-related incidents reported across at least seven states). Attackers remotely accessed internet-facing PLCs, changed passwords and IPs to lock out operators, and in some cases exfiltrated PLC project files; CISA warns of active exploitation of CVE-2021-22681 in Rockwell devices (no patch available) and recommends immediately removing PLCs from the internet, segmenting OT, changing default credentials, and auditing all remote-access paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
