Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities.
Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew’s previous raids, noting the timing relative to recent government warnings.
The Cybersecurity and Infrastructure Security Agency (CISA) updated an advisory on Iran-linked attackers targeting programmable logic controllers (PLCs) across critical infrastructure on July 22, four days before Minnesota said the attacks targeted its systems.
Read more…
Source: The Register
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- US Coast Guard Suffers Data Breach, Pay Delayed for 1,135 Members
February 14, 2025
The Coast Guard’s personnel and payroll system experienced a data breach resulting in a delay in pay for 1,135 service members. The breach will affect bi-weekly pay for 1,135 members, according to a Coast Guard statement to USNI News. “The Coast Guard Investigative Service and Coast Guard Cyber Command are leading an exhaustive investigation to determine ...
- Trump administration fires over 400 DHS employees as mass firings continue
February 14, 2025
The Trump administration on Friday moved to fire more than 400 employees at the Department of Homeland Security, the latest effort in a government-wide campaign to dramatically reduce the federal workforce. Officials at DHS said they had fired hundreds of employees across several of its agencies after supervisors identified “non-mission critical personnel in probationary status” within ...
- China’s Salt Typhoon hackers continue to breach telecom firms despite US sanctions
February 13, 2025
Security researchers say the Chinese government-linked hacking group, Salt Typhoon, is continuing to compromise telecommunications providers, despite the recent sanctions imposed by the U.S. government on the group. In a report shared with TechCrunch, threat intelligence firm Recorded Future said it had observed Salt Typhoon — which the company tracks as “RedMike” — breaching five telecommunications ...
- Upper Michigan: Cyber attack hits Sault Tribe offices
February 13, 2025
A ransomware attack that shut down gaming at all five Kewadin Casino locations also impacted other offices at an eastern Upper Peninsula tribe. The tribe made the announcement Monday and said it could be a week or more before regular operations can resume. “On Sunday morning, the Sault Ste. Marie Tribe of Chippewa Indians suffered a ...
- Paris AI summit: Why won’t US, UK sign global artificial intelligence pact?
February 12, 2025
The United States and United Kingdom have refused to sign an Artificial Intelligence Action Summit declaration calling for policies “ensuring AI is open, inclusive, transparent, ethical, safe, secure and trustworthy”. The summit in Paris on Monday and Tuesday brought together representatives from more than 100 countries to discuss how to reach a consensus on guiding the ...
- US, UK crack down on Russian bulletproof hosting service ZServers for LockBit partnership
February 12, 2025
Russia-based bulletproof hosting services provider (BPH) ZServers has been sanctioned by the United States, Australia, and the United Kingdom for its alleged involvement with the LockBit ransomware group. In a press release, the Australian Federal Police (AFP) said ZServers was providing services to threat actors responsible for the Medibank Private breach that happened in October 2022. ...

