CISA along with the FBI, EPA, and Department of Energy, issued an urgent advisory, warning that cyber actors are actively targeting industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems within the U.S. oil and natural gas sector. Just weeks earlier, on April 22, 2025, CISA released five urgent advisories highlighting critical vulnerabilities in widely-used Industrial Control Systems from major manufacturers including Siemens, ABB, and Schneider Electric. Changing default passwords is especially important for public-facing internet devices that have the capability to control OT systems or processes [CPG 2.A][CPG 2.B][CPG 2.C],” the advisory emphasizes. Despite using elementary intrusion techniques, these attacks pose significant risks due to widespread poor cyber hygiene within critical infrastructure organizations. The attackers use “simple, repeatable, and scalable tool sets available to anyone with an internet browser” to identify vulnerable systems through search engine tools that scan for open ports on public IP ranges. The alert concludes by directing organizations to CISA’s comprehensive resources, including guidance on identifying internet-exposed devices, implementing strong passwords, deploying phishing-resistant MFA, and establishing proper network segmentation. Officials believe these threat actors are likely hacktivist groups or individuals claiming to be hacktivists who have been targeting internet-exposed OT systems since at least 2022. Critical infrastructure organizations are also strongly encouraged to review their relationships with third-party service providers, as misconfigurations are frequently introduced during standard operations, by system integrators, or as part of default product configurations. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Kaaviya is a Security Editor and fellow reporter with Cyber Security News.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 07 May 2025 12:10:00 +0000