Multistate Cyberattacks Expose Critical Infrastructure and Identity Risks

TL;DR Water system cyberattacks
TOPICS
MORE LIKE THIS

This week’s leading stories show attackers targeting two essential layers of modern operations: industrial control systems and digital identities. Water utilities face immediate operational disruption, while new passkey research demonstrates that phishing-resistant authentication still depends on secure endpoints and careful implementation.

Dark Reading reports that cyberattacks against water and wastewater systems have spread across at least a dozen US states. The attackers are targeting Internet-exposed programmable logic controllers, or PLCs, using relatively simple techniques to change passwords, alter network settings, and lock operators out of essential equipment.

More than 30 water systems in Minnesota were reportedly targeted, with related incidents disclosed in Georgia, Michigan, South Dakota, Alabama, and New Jersey. Although this has not caused a prolonged loss of service, some utilities have been forced to switch to manual operations. An incident in Georgia reportedly contributed to reduced water pressure and a boil-water advisory.

The activity has not been conclusively attributed. However, researchers and government warnings have identified similarities to previous operations associated with Iranian actors, including the CyberAv3ngers group.

The incidents underline a common weakness in operational tech: equipment designed for isolated environments is connected to the Internet without modern security or oversight. Utilities should remove direct Internet exposure, inventory remote connections, change default credentials, and place properly secured access controls between business networks and operational systems.

Multistate Water System Attacks – TL;DR

Attackers are exploiting exposed industrial controllers at US water utilities. The immediate priority is finding and securing every Internet-accessible OT device before a low-complexity intrusion causes serious physical disruption.

The Hacker News examines three research projects showing how attackers can undermine passkey-protected accounts without defeating the underlying cryptography. The techniques instead exploit weaknesses in operating systems, browser storage, cloud synchronization, and authentication workflows.

One attack chain reused authentication material exposed through Windows logging to impersonate privileged Microsoft Entra ID users. Microsoft’s July 2026 security updates reportedly break that chain, including remediation for CVE-2026-34348.

Other research found that malware already running on a Windows endpoint could recover Google Password Manager’s master secret from Chrome or use a Windows Hello for Business key from an active user session without requesting another PIN or biometric check. These attacks require an existing endpoint compromise, but they demonstrate that passkeys cannot contain every breach.

Organizations should continue adopting phishing-resistant authentication, while treating passkeys as one control rather than a complete identity-security solution. Priorities include applying Windows updates, strengthening endpoint detection, monitoring unexpected device registrations, enforcing least privilege, and investigating unusual passkey authentications that lack expected device information.

Passkey Attacks – TL;DR

Passkey cryptography remains strong, but compromised endpoints and weak implementation details can still let attackers impersonate users. Identity protection must combine passkeys with hardened devices, monitoring, and rapid patching.

The common lesson is that strong security controls lose their value when the systems around them remain exposed. ThinScale Technology can help organizations strengthen endpoints, access controls, and operational resilience. Book a demo today.

Ready to see it in action?