Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA: Over 100 Water Systems Hit by July Cyberattacks

CISA: Over 100 Water Systems Hit by July Cyberattacks

Posted on August 26, 2026 By CWS

The Cybersecurity and Infrastructure Security Agency (CISA) has reported that over 100 internet-exposed water systems were targeted in cyberattacks this past July. This revelation was part of CISA’s guidance aimed at helping organizations minimize the internet exposure of their systems to prevent such attacks.

Cyberattacks on Critical Water Systems

In a statement, CISA highlighted that in July 2026, over 100 systems within the Water and Wastewater Systems (WWS) sector were compromised through programmable logic controllers (PLCs) connected to cellular modems. This represents a significant breach in cybersecurity for critical infrastructure.

Prior to this disclosure, no federal agency had provided a detailed count of the affected systems. The attacks, reportedly linked to Iranian threat actors, targeted operational technology (OT) systems, raising concerns about potential operational disruptions.

States Affected by Cyber Threats

The cyberattacks impacted various states, with confirmed reports from Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. Although the exact number of affected states remains unspecified, at least 12 states were involved.

Despite no significant disruptions reported, the incidents underscore the vulnerabilities in the water sector and highlight the need for stringent cybersecurity measures.

Steps to Mitigate Internet Exposure

CISA is proactively urging organizations to minimize their internet attack surface, particularly focusing on OT systems in critical infrastructure sectors. Their guidance suggests identifying all internet-accessible systems, assessing their necessity, and removing unnecessary exposures.

For systems that must remain online, CISA recommends changing default passwords, applying regular security updates, routing remote access through secure gateways, enforcing multifactor authentication, and continuous traffic monitoring.

The guidance cautions against leaving PLCs and other industrial control systems accessible via cellular modems or the public internet, a factor contributing to the recent malicious activities against water and wastewater systems.

Regular reassessments of systems are advised as network configurations and third-party connections evolve. This guidance follows warnings of Iranian-linked attacks on industrial control systems by major manufacturers.

Ensuring the cybersecurity of water systems and other critical infrastructure remains a priority, as underscored by recent legislative efforts and security initiatives.

Security Week News Tags:CISA, critical infrastructure, Cyberattacks, Cybersecurity, ICS security, internet exposure, Iranian threat actors, OT systems, PLC, water systems

Post navigation

Previous Post: OpenAI Blocks Russian Accounts for Influence Operations
Next Post: Critical SonicWall NetExtender Flaws Expose Linux Systems

Related Posts

Cisco SD-WAN Vulnerability Exploitation Grows Rapidly Cisco SD-WAN Vulnerability Exploitation Grows Rapidly Security Week News
Apache Patches Critical Vulnerabilities in HTTP Server Apache Patches Critical Vulnerabilities in HTTP Server Security Week News
Google Rolls Out Emergency Chrome Update to Patch Zero-Days Google Rolls Out Emergency Chrome Update to Patch Zero-Days Security Week News
Sedgwick Confirms Cyberattack on Government Subsidiary Sedgwick Confirms Cyberattack on Government Subsidiary Security Week News
136 NPM Packages Delivering Infostealers Downloaded 100,000 Times 136 NPM Packages Delivering Infostealers Downloaded 100,000 Times Security Week News
Kosovar Administrator of Cybercrime Marketplace Extradited to US Kosovar Administrator of Cybercrime Marketplace Extradited to US Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 24 Malicious npm Packages Exploit Mirrors for Phishing
  • Rethinking MFA: Beyond Authentication to True Identity Security
  • Kaltura Vulnerabilities Permit Remote File Access and Code Execution
  • Fake Claude App Exploits Windows, Installs Malware
  • Adobe, Nvidia Release Critical Security Patches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 24 Malicious npm Packages Exploit Mirrors for Phishing
  • Rethinking MFA: Beyond Authentication to True Identity Security
  • Kaltura Vulnerabilities Permit Remote File Access and Code Execution
  • Fake Claude App Exploits Windows, Installs Malware
  • Adobe, Nvidia Release Critical Security Patches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark