Sabitlenmiş Tweet

READ ---> Joint CSA from FBI, CISA, NSA, EPA, DOE, and CNMF: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
---------- break ----------
I'm going to sum up the longwinded rant I just hit my wife with into:
There's zero reason to have an HMI publicly exposed other than it being a honey pot. Z E R O
None of that cybersecurity marketing bullshit organization fall for and implement is going to save them from terrible network and system hygiene.
They must take control of those environments and secure them... YESTERDAY.
Her response: Why are you telling me, tell them. 😅
---------- break ----------
Check your logs for the IOCs listed within the CSA. If you find any hits, engage an incident response firm.
Publicly exposing an HMI suggests your current team likely lacks the capacity to properly and thoroughly investigate and remediate this. Bring in qualified external help to review the situation and get your systems and environment secured.
---------- break ----------
For the security teams overseeing OT infrastructure: There are too many people that rely on you to protect critical infrastructure, and it seems your orgs are failing to do so. Respectfully, get your shit together. It's not rocket science to put some security controls in front of these environments. I understand execs push back; flood them with every shred of evidence of attacks on OT environments and the outcomes of such. When something happens, you did what you could and hopefully their disinterest leads them to being held accountable.
cisa.gov/news-events/cy…
English









