Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CISA Warns Utilities to Remove Internet-Exposed PLCs After Minnesota Cyberattacks


CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks, Warns of Increased Threats Targeting Critical Infrastructure. The agency is urging organizations to take immediate action to secure their industrial control systems and remove internet-exposed Programmable Logic Controllers (PLCs) from the internet.

  • The US Cybersecurity and Infrastructure Security Agency (CISA) is warning utilities to remove internet-exposed Programmable Logic Controllers (PLCs) from the internet.
  • A coordinated cyberattack hit over 30 community water utilities in Minnesota, resulting in boil water notices and sustained manual operations.
  • The attack was linked to Iranian-affiliated actors using a critical vulnerability in Rockwell Automation PLCs with a CVSS score of 9.8.
  • CISA recommends disconnecting PLCs from the internet, enabling password protection, and implementing other mitigations to strengthen OT security.
  • Rockwell Automation has confirmed no security patch is available for vulnerable PLCs, highlighting the need for network isolation and compensating controls.



  • In a recent alert issued by the United States Cybersecurity and Infrastructure Security Agency (CISA), it has been emphasized that all utilities must remove internet-exposed Programmable Logic Controllers (PLCs) from the internet as soon as possible. The warning came after multiple attacks hit operational technology (OT) systems at over 30 community water utilities across Minnesota, with the attacks resulting in boil water notices and sustained manual operations at affected facilities.

    The attacks on Minnesota's water systems were part of a coordinated cyberattack that targeted operational technology at more than 30 community water systems between Sunday and Monday, July 26 and 27. The attacks have been linked to Iranian-affiliated actors, specifically the group known as CyberAv3ngers, which is believed to be associated with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command.

    The attackers exploited a critical vulnerability in Rockwell Automation PLCs, CVE-2021-22681, which has a CVSS score of 9.8, making it one of the most severe vulnerabilities ever identified. The vulnerability remained unexploited for years due to the difficulty in patching industrial control systems without disrupting essential services.

    The attackers modified passwords and IP addresses to lock out operators, causing disruptions to the water treatment process and resulting in boil water notices at affected facilities. In some cases, manual operations were forced, while drinking water remained safe in most cases. Contingency procedures held, but the attacks highlighted the importance of strengthening OT security.

    CISA has urged critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology systems from the internet as soon as possible. The agency also recommends that organizations implement specific mitigations, including:

    - Disconnecting the PLC from the internet
    - Enabling password protection and changing default passwords
    - Allowing only remote access from known engineering laptops or critical OT assets
    - Ensuring a known clean backup of the PLC image in case of lockdown by a modified password

    Rockwell Automation has confirmed that no security patch is available for the vulnerable PLCs, emphasizing the need for network isolation and other compensating controls to mitigate the risk.

    The attacks on Minnesota's water systems are a prime example of how attackers can exploit vulnerabilities in internet-exposed industrial control systems to disrupt critical infrastructure. As CISA emphasizes, even mature organizations should validate their external connections, as cellular modems installed by operators, vendors, or system integrators may not appear in routine network scans.

    The incident highlights the importance of prioritizing OT security and ensuring that PLCs are removed from public exposure. It also underscores the need for continuous vigilance and proactive measures to prevent similar attacks in the future.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CISA-Warns-Utilities-to-Remove-Internet-Exposed-PLCs-After-Minnesota-Cyberattacks-ehn.shtml

  • https://securityaffairs.com/196453/ics-scada/cisa-urges-utilities-to-remove-internet-exposed-plcs-after-minnesota-attacks.html

  • https://cybersecuritynews.com/cisa-urges-water-utilities-to-remove-plcs/

  • https://nvd.nist.gov/vuln/detail/CVE-2021-22681

  • https://www.cvedetails.com/cve/CVE-2021-22681/


  • Published: Sun Aug 2 01:36:36 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us