New security research has found that well over a thousand U.S. water and wastewater providers are exposed to hacks due to malware that’s capable of stealing their employees’ passwords and active logged-in sessions.
The findings by cybersecurity defense firm SpyCloud underscore how water providers and other critical infrastructure can be compromised with relative ease amidst a wave of hacks targeting the water supplies of dozens of communities across the United States.
Read more…
Source: TechCrunch
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
September 16, 2026
The ShinyHunters hacking group has published hundreds of thousands of files from a Florida state database of vehicles and driver information. The hackers said they published the stolen data on its leak site “because the victim did not pay a ransom or cooperate and comply” with the hackers’ demands. The hackers said they breached the database, ...
- Iranian Cyber Targeting of Dissidents, Activists and Journalists
September 15, 2026
CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. Iran almost ...
- CISA, NSA, FBI warn Chinese AI firms of industrial‑scale knowledge distillation
September 9, 2026
Chinese AI companies’ core development strategy is to steal proprietary functionalities and capabilities from their US counterparts, law enforcement agencies have warned. The US Cybersecurity and Infrastructure Security Agency (CISA) has published a new security advisory, drafted jointly with the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI), warning American AI companies about an ongoing “aggressive, malicious, ...
- FBI Cyber Strategy
September 9, 2026
This Strategy sets the course for FBI Cyber Division to defend the American people and the nation’s critical infrastructure in cyberspace. It defines our priorities, objectives, and framework for countering malicious cyber activity directed at the United States. It guides how the FBI uses its unique combination of law enforcement, intelligence, and national security authorities ...
- Russian National Extradited to United States for Bank Account Takeover Fraud Scheme Causing Millions of Dollars in Losses
September 8, 2026
Sergei Anatolyevich Filimonov, 36, a Russian national and web developer who was allegedly involved in a transnational cyber‑fraud conspiracy responsible for large‑scale bank account takeover activity, was arraigned Friday in the Northern District of Georgia after being extradited from the Republic of Georgia. Filimonov was indicted by a federal grand jury on Nov. 4, 2025, ...
- US military disabled ad tracking on troops’ devices following reports of targeted attacks
September 4, 2026
The U.S. Department of Defense has disabled advertising tracking on troops’ phones and computers as part of an effort to protect them from threats that target their locations, according to a letter shared with Sen. Ron Wyden. Per a letter shared with the senior Democrat on the Senate Intelligence Committee, Wyden said that the U.S. Army, ...
