| 2026-07-30 |
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.
|
CISA
FBI
|
| 2026-06-02 |
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the (EPA), the Transportation Security Administration (TSA), the Department of Transportation (DOT), and the U.S. Department of Agriculture (USDA)—hereafter referred to as “the authoring organizations”—are aware of malicious cyber activity targeting U.S.-based automatic tank gauge (ATG) systems.
|
CISA
DOE
FBI
NSA
TSA
USDA
|
| 2026-04-07 |
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss. U.S.
|
CISA
CNMF
DOE
FBI
NIST
NSA
|
| 2025-12-09 |
Opportunistic Pro-Russia Hacktivists Attack US and Global Critical Infrastructure
This advisory, published as an addition to the joint fact sheet on Primary Mitigations to Reduce Cyber Threats to Operational Technology (OT) released in May 2025 , details that pro-Russia hacktivist groups are conducting less sophisticated, lower-impact attacks against critical infrastructure entities, compared to advanced persistent threat groups.
|
CISA
DOE
FBI
NSA
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
Actions for Operational Technology Owners and Operators to Take Today to Mitigate Cyber Threats Related to Pro-Russia Hacktivists Activity Reduce exposure of operational technology (OT) assets to the public-facing internet. Adopt mature asset management processes, including mapping data flows and access points. Ensure that OT assets are using robust authentication procedures.
|
ASD/ACSC
BSI
CCCS
CISA
DC3
DOE
EC3
FBI
NCSC-NZ
NCSC-UK
NSA
NUKIB
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against U.S. and Global Critical Infrastructure
FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by proRussia hacktivists: The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lowerimpact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups.
|
ASD/ACSC
BSI
CCCS
DC3
DOE
EC3
FBI
NCSC-NZ
NCSC-UK
NSA
NUKIB
|
| 2025-08-13 |
CISA and Partners Release Asset Inventory Guidance for Operational Technology Owners and Operators
CISA, along with the National Security Agency, the Federal Bureau of Investigation, Environmental Protection Agency, and several international partners, released comprehensive guidance to help operational technology (OT) owners and operators across all critical infrastructure sectors create and maintain OT asset inventories and supplemental taxonomies.
|
CISA
FBI
NSA
|
| 2025-08-13 |
Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators
Using these tools helps owners and operators identify which assets in their environment should be secured and protected, and structure their defenses accordingly to reduce the risk a cybersecurity incident poses to the organization’s mission and service continuity. An asset inventory is an organized, regularly updated list of an organization’s systems, hardware, and software.
|
ASD/ACSC
BSI
CCCS
CISA
DOE
FBI
NCSC-NL
NCSC-NZ
NSA
|
| 2025-05-06 |
Primary Mitigations to Reduce Cyber Threats to Operational Technology
The authoring organizations urge critical infrastructure entities to review and act now to improve their cybersecurity posture against cyber threat activities specifically and intentionally targeting internet connected OT and ICS. The authoring organizations recommend critical infrastructure asset owners and operators implement the following mitigations1 to defend against OT cyber threats. internet.
|
CISA
DOE
FBI
|
| 2025-01-13 |
Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products
Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems.
|
ASD/ACSC
BSI
CCCS
CISA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2024-12-18 |
CSA: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities (December 2024 update)
IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and
|
CCCS
CISA
FBI
NCSC
NSA
|
| 2024-12-13 |
CISA and EPA Release Joint Fact Sheet Detailing Risks Internet-Exposed HMIs Pose to WWS Sector
This joint fact sheet provides Water and Wastewater Systems (WWS) facilities with recommendations for limiting the exposure of Human Machine Interfaces (HMIs) and securing them against malicious cyber activity. HMIs enable operational technology owners and operators to read supervisory control and data acquisition systems connected to programmable logic controllers.
|
CISA
|
| 2024-05-01 |
Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity
|
CCCS
CISA
DOE
FBI
MS-ISAC
NCSC-UK
NSA
USDA
|
| 2024-03-21 |
PRC State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders
This fact sheet provides an overview for executive leaders on the urgent risk posed by People’s Republic of China (PRC) state-sponsored cyber actors known as “Volt Typhoon.” CISA—along with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and other U.S. government and international partners1—released a major advisory on Feb. 7, 2024, in which the U.S.
|
ASD/ACSC
CCCS
DOE
FBI
NCSC-NZ
NCSC-UK
NSA
TSA
Treasury
|
| 2024-02-07 |
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
For a downloadable copy of indicators of compromise (IOCs), see: MAR-10448362.c1.v2.CLEAR_stix2.json (JSON, 51.
|
ASD/ACSC
CCCS
CISA
DOE
FBI
NCSC-NZ
NCSC-UK
NIST
NSA
TSA
|
| 2024-02-07 |
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
Prioritize patching critical sponsored cyber actors are seeking to prevulnerabilities in appliances known to be position themselves on IT networks for disruptive frequently exploited by Volt Typhoon. or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States.
|
ASD/ACSC
CCCS
CISA
DOE
FBI
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2024-02-07 |
CTR: Joint Guidance: Identifying and Mitigating Living Off the Land Techniques
This guide, authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), agencies (hereafter referred to as the authoring agencies), provides information on common living off the land (LOTL) techniques and common gaps in cyber defense capabilities. U.S. Department of Energy (DOE) U.S. Environmental Protection Agency (EPA) U.S.
|
ASD/ACSC
CCCS
CISA
DOE
FBI
NCSC-NZ
NCSC-UK
NSA
TSA
|