Cyber experts urge mandatory US federal OT security rules
A coalition of cybersecurity companies and infrastructure operators wants the US cyber defense agency, CISA, to require all federal agencies to adopt basic security rules for their operational technology—the hardware running critical systems like HVAC, water, and access controls. After recent cyberattacks hit water utilities, experts say voluntary guidance has failed, pointing out that most agencies still haven't even counted their networked devices. CISA has not yet responded publicly.
- Coalition calls for new CISA binding directive
- Recent attacks exposed OT vulnerabilities in water systems
- Most agencies lack a network inventory of their devices
- GAO found only 7 out of 22 agencies met inventory deadlines
- AI risks make these lax controls more dangerous
Sources covering this
More in Cybersecurity
Four states sue TP-Link over router security claims
Florida and three other US states have filed lawsuits against TP-Link, alleging the company misled consumers about its routers' security…
Outlook will block MSIX file attachments in November
Microsoft will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows starting in November.
Major software vendors patch critical vulnerabilities
Cisco Talos researchers reported multiple vulnerabilities in products from Microsoft, Adobe, Apple, and Foxit.
PoeLLM malware builds botnet targeting AI services
Researchers have identified malware named PoeLLM that has compromised over 3,400 servers since April by targeting open-source AI services.