On this week's Security Sprint, Dave and Andy are joined by Chase Snow to talk about the latest cyber incident involving water facilities. They covered some of these topics:
Opening:
• Crypto security breaches surpass $1B in H1 2026, hit record high — Crypto Briefing
• CISA, ASD’s ACSC, and Partners Release Joint Guidance on Isolating Vital Operational Technology and Enabling Systems During Crisis. The Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation (FBI) and international partners, published joint guidance CI Fortify – Advice for isolating vital systems.
• CI Fortify – Advice for isolating vital systems — Australian Signals Directorate
• When cyber attacks happen: helping organisations recover — United Kingdom National Cyber Security Centre
Water Sector Cyberattacks:
• Iran’s CyberAv3ngers claim ‘attacks on U.S. infrastructure,’ vow more in first statement since Minnesota water hacks
• Trump rejects Iran blame for Minnesota cyberattack, points finger at 'corrupt' political foe
• Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world — CyberScoop — 31 Jul 2026. With commentary from Gate 15 and WaterISAC.
• Several states report cyberattacks as spy agencies suspect Iran is targeting water — The Washington Post — 01 Aug 2026. WaterISAC analyst Alec Davison said attackers used relatively unsophisticated methods against internet-connected programmable logic controllers, then changed passwords, locked out operators, and disconnected controllers, resulting in boil-water notices and sustained manual operations.
• (TLP:CLEAR) CISA Issues Alert Urging Water and Wastewater Utilities to Protect OT Against Activity Targeting PLCs — WaterISAC
• Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control