Connect with us

Infosecurity

CISA warns of spike in attacks on water systems as Minnesota incidents probed

Published

on

attacks on water systems

CISA issues urgent alert over water utility intrusions

The federal cybersecurity agency is reporting a “significant increase” in malicious activity aimed at water utilities, as investigators are reportedly trying to determine whether recent incidents in Minnesota might be the work of Iran-linked hackers.

The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.” PLCs — programmable logic controllers — are at the core of processes in multiple industries.

Multiple news outlets reported that state and federal investigators were working to determine whether disruptions to water systems in Minnesota earlier this month were connected to Iran. Wired magazine reported that a memo from the WaterISAC, the industry’s cybersecurity information-sharing body, said the attacks were tied to Iran.

What happened in Minnesota?

Minnesota’s state IT agency said earlier this week that “more than 30 Minnesota community water systems” were affected by a coordinated cyberattack beginning July 26. The threat actor is “targeting water entities of all sizes,” CISA said.

The intruders “have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses,” CISA said. “This activity has resulted in boil water notices and sustained manual operations.”

CISA, the FBI and the Environmental Protection Agency are all involved in the response. The FBI said “utility companies in at least seven states” have reported incidents involving PLCs to the bureau.

Iran connection remains unclear

At a Cabinet meeting at Camp David on Friday, President Donald Trump placed the blame on Minnesota’s Democratic government. “Iran’s got bigger problems than worrying about Minnesota,” he said.

Earlier this month, CISA updated previous warnings that industrial OT was facing malicious activity linked to Iran. Thursday’s alert does not mention Iran.

“Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans,” CISA said. “OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.”

Broader context: OT security under siege

Hostilities continued around the Strait of Hormuz on Friday, as oil companies reported massive profits related to the conflict’s effects on energy prices.

This wave of intrusions fits a troubling pattern. Operational technology security has become a prime target for state-sponsored groups, and water utilities — often running on aging infrastructure — are particularly exposed.

For utilities, the immediate takeaway is clear: audit every internet-facing device, including those cellular modems that might have slipped off the radar. Document all external connections. And if you find a PLC exposed, don’t wait — pull it offline.

For more on how cybercriminals are exploiting industrial systems, see our explainer on PLC cyberattack vectors. And for a broader look at how federal agencies are responding, check out CISA’s evolving role in critical infrastructure defense.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

NCSC Pushes Device Makers to Build Forensic Observability Into Every Network Product

Published

on

Why the NCSC Is Turning Up the Heat on Device Vendors

When a firewall gets compromised, the clock starts ticking. Incident responders need to know exactly what happened, how deep the intrusion goes, and whether the device can ever be trusted again. But too often, that evidence is locked away inside proprietary hardware and software.

The UK’s National Cyber Security Centre (NCSC) has had enough. In a blog post on July 29, Chris A, the agency’s technical director for networking and infrastructure, laid out a clear demand: device manufacturers must embed forensic observability into their products from the ground up.

Firewalls, VPN gateways, and other network appliances are prime targets for attackers. When they fall, organizations are left scrambling. “When incidents occur, organizations need reliable ways to understand what happened and assess whether a device can still be trusted,” Chris A wrote. “This is why forensic observability matters.”

The concept is straightforward: give defenders supported, built-in capabilities to investigate a compromise, rather than forcing them to reverse-engineer the device or hunt for vulnerabilities just to collect basic forensic data. That’s still the norm in many shops, and it’s a costly, time-consuming nightmare.

What Forensic Observability Actually Means

According to the NCSC, forensic observability isn’t a single feature. It’s a bundle of capabilities that should be baked into every network device:

  • Comprehensive telemetry and structured logging
  • Access to configuration state
  • Ability to collect forensic data from memory and data at rest
  • Transparency about the software running on the device, either via version info or a software bill of materials (SBOM)

That last point matters more than most people realize. If you don’t know exactly what software is on a device, you can’t assess its exposure to known vulnerabilities. An SBOM changes that equation entirely.

Chris A emphasized that investigating a compromised device “should not require discovering or exploiting vulnerabilities in the product itself.” Instead, manufacturers should provide supported mechanisms for gathering evidence, assessing impact, and restoring trust in affected systems.

The NCSC isn’t asking for the moon here. “Small design decisions can significantly reduce the time needed to triage and investigate incidents,” he noted.

Three Myths That Hold Vendors Back

The NCSC’s technical director also took aim at misconceptions that keep manufacturers from making these design improvements. These myths, he argued, are preventing progress in network device security.

Myth 1: Observability Helps Attackers

Some vendors worry that exposing telemetry gives attackers a roadmap. The NCSC disagrees. Well-designed features like structured logging, authenticated collection mechanisms, and clearly defined forensic interfaces strengthen security rather than undermine it. Attackers don’t need your logs to exploit your device; they need your vulnerabilities.

Myth 2: Customers Will React Negatively

The fear here is that customers will see forensic features as complexity or backdoors. The reality, per the NCSC, is the opposite. Clear telemetry and forensic capabilities build trust through improved visibility. Buyers want to know what their devices are doing, especially after an incident.

Myth 3: It’s Too Difficult to Build

Yes, forensic observability requires careful engineering. But it’s absolutely achievable, especially when prioritized early in the design process. Waiting until after a product ships makes it exponentially harder — and far more expensive.

What Vendors and Buyers Should Do Now

The NCSC isn’t just publishing blog posts and walking away. The agency released formal guidance on building forensic observability into products back in February 2025. Now it’s pushing vendors to follow it.

Chris A also had a message for IT buyers: push your vendors. If you’re procuring firewalls, VPN gateways, or any other network appliance, ask what forensic capabilities are built in. Demand SBOMs. Make forensic observability a checkbox in your procurement process.

In parallel, the NCSC is working with global partners to develop a reference architecture for forensic observability in network appliances. Once finalized, this should give manufacturers a blueprint for providing “safe, reliable forensic access” without weakening the security of their products.

For incident response teams, this shift can’t come soon enough. The gap between what attackers exploit and what defenders can investigate is a serious problem. Forensic observability closes that gap — but only if vendors actually build it.

Want to dig deeper into related topics? Check out our coverage of Android spyware forensics tools and the broader push for software bill of materials adoption in enterprise security.

Continue Reading

Infosecurity

LogoKit Phishing Kit Now Screenshots Your Real Website to Build Fake Login Pages

Published

on

LogoKit phishing kit

The Hook: A Login Page That Looks Exactly Like Yours

Imagine getting a phishing email that warns your password is about to expire. You click the link. The login page that loads isn’t a generic clone — it’s a real-time screenshot of your company’s actual website, complete with your logo, your branding, even your latest announcements. That’s not hypothetical. That’s what the LogoKit phishing kit is doing right now.

Researchers at Barracuda published findings on July 29 detailing how this phishing-as-a-service platform has evolved. It no longer relies on static templates. Instead, it builds a unique login page for each victim on the fly, pulling live data from commercial web services.

From Brand Impersonation to Environment Impersonation

The shift is subtle but significant. Older phishing kits tried to copy a brand’s look. LogoKit goes further — it recreates parts of the victim’s genuine web environment. Barracuda calls this “environment impersonation.” The page doesn’t just look like the brand; it looks like your specific instance of that brand.

Here’s how it works, step by step:

  1. The phishing URL contains the victim’s email address.
  2. The kit extracts that address and identifies the victim’s employer from the domain.
  3. It calls Clearbit to fetch the company’s official logo.
  4. It uses Thum.io, a commercial screenshot service, to capture a live image of the victim’s actual website.
  5. Additional APIs — Google Favicon, ImageKit, Microlink — load more authentic imagery as the page renders.

The result? A login page that mirrors the real thing down to the pixel. No two victims see the same page.

Legitimate Services Doing the Heavy Lifting

What makes this particularly sneaky is the reliance on reputable third-party services. Thum.io isn’t a malicious tool — it’s a legitimate screenshot API used by developers worldwide. Clearbit is a standard data enrichment service. By piggybacking on these platforms, the kit avoids hosting its own infrastructure.

This isn’t entirely new. RiskIQ first named LogoKit back in 2021, noting it already pulled logos from Clearbit and embedded victim email addresses in URLs. What’s new is the live screenshot element and the scale of customization.

The Lures: Boring but Effective

The bait itself is routine. Barracuda observed campaigns covering password expiry warnings, certificate expirations, access restrictions, delivery failures, timesheet updates, and ICANN verification notices. Nothing exotic — just the everyday anxieties that push people to act fast.

The emails appeared in six languages: English, German, French, Spanish, Chinese, and Korean. That’s a global operation, not a hobbyist experiment.

No Server, No Template, No Signature

Here’s the part that keeps security teams up at night. Credential harvesting doesn’t go to an attacker-controlled backend. It goes to a Telegram bot. After the victim submits their password, they’re redirected to the real website — where they likely assume they mistyped their password the first time. The attacker is already gone with the credentials.

Because there’s no static template, there’s no signature for antivirus or URL filters to fingerprint. Each page is assembled at request time from live data. Blocklisting a domain? Useless. The same problem was flagged with the Starkiller phishing kit back in February, which also bypasses MFA.

How to Defend Against LogoKit and Its Ilk

Barracuda’s recommendations are straightforward but require commitment:

  • Deploy phishing-resistant MFA. FIDO2 security keys and passkeys bind authentication to the legitimate domain. A fake page can’t present the correct cryptographic challenge, so stolen passwords become useless.
  • Use conditional access rules. Restrict logins based on location, device compliance, and risk signals.
  • Consider browser isolation. Render web content in a sandboxed environment so malicious pages never touch the user’s device.
  • Filter URLs aggressively. Flag newly registered domains and links that contain an email address in the path — a telltale sign of this kit.

The bigger lesson? Traditional phishing defenses are crumbling. Static analysis, reputation lists, and user training alone won’t cut it. Attackers have moved to dynamic, per-victim campaigns that look exactly like the real thing. Your defense needs to move just as fast.

For more on how phishing kits are evolving, check out our coverage of phishing kit evasion techniques and MFA bypass attacks.

Continue Reading

Infosecurity

Agents Versus Agents: Microsoft’s Big Bet on AI Security

Published

on

Microsoft AI security

Microsoft’s Answer to AI Threats? More AI

David Weston, Microsoft’s corporate VP for AI security, put it plainly during a July 27 security launch preview: you need agents to fight agents. That single idea drove nearly everything the company announced that day.

The Redmond giant rolled out a batch of new products and initiatives aimed at defending against AI-enabled attacks. The lineup includes a new agentic security system, a custom cyber-focused AI model, a research lab staffed by DARPA competition winners, and a global red teaming alliance.

Here’s a breakdown of what Microsoft announced and why it matters for security teams.

Project Perception: Red, Blue, and Green Agents Working Together

The centerpiece is Project Perception, an agentic security system designed to continuously identify, evaluate, and reduce security risk. It coordinates three types of specialized agents that work in tandem to improve security posture over time:

  • Red agents probe for potential attack paths and vulnerabilities before they can be exploited.
  • Blue agents investigate findings, apply security context, and determine what constitutes meaningful risk.
  • Green agents take corrective action and strengthen defenses across the environment.

This approach mirrors Google’s AI Threat Defense platform, powered by Wiz’s Red, Blue, and Green agents, which launched in May 2026.

Hayete Gallot, executive VP at Microsoft Security, explained why this matters at scale. Microsoft sees about 100 trillion signals a day. That’s an overwhelming amount of raw data.

“We sit at your identity, data, cloud, code and even AI level,” she said. “If you add our security research, threat intelligence and red teaming efforts, you end up with even more signals.”

But raw data alone isn’t useful. “If you were to apply an agent to that raw data, it would be very slow and you would get terrible results,” Gallot added. “That’s why we are connecting and correlating all those signals so we can provide a ‘security context,’ which is organized efficiently for our agents.”

Weston noted that Project Perception will be multi-model. He demonstrated several “playbooks” based on operations a security operations center (SOC) might face. Perception enters Preview mode for all Microsoft customers on August 3.

MAI-Cyber-1-Flash: Microsoft’s First Cyber-Focused AI Model

Gallot also unveiled MAI-Cyber-1-Flash, a generative AI model built specifically for cybersecurity use cases, particularly software vulnerability analysis.

Developed by Microsoft AI (MAI), the model builds on the company’s internally developed MAI-Thinking-1 reasoning model. It’s integrated into Microsoft Security’s multi-model agentic scanning harness (MDASH).

Mustafa Suleyman, CEO at Microsoft AI, said the system is further enhanced by GPT-5.4. In CyberGym benchmarking, it outperformed competing solutions from Anthropic, OpenAI, and Google.

The numbers are striking. MAI-Cyber-1-Flash, combined with the GPT-4.5 enhancement, achieved a 95.95% success rate on the CyberGym benchmark. For comparison:

  • OpenAI’s GPT-5.5 Cyber scored 85.6%
  • GPT-5.6 Sol achieved 83.6%
  • Anthropic’s Mythos recorded 83.8%
  • Google’s Gemini 3.5 Flash Cyber reached 83.2%

Within MDASH, MAI-Cyber-1-Flash handles roughly 90% of queries, identifying and patching software vulnerabilities before verifying the fixes work. The remaining 10% of more complex tasks go to the larger GPT-5.4 model.

Suleyman said GPT-5.4 is about ten times larger than MAI-Cyber-1-Flash and can resolve the queries handed off to it. He also claimed the collaboration delivers stronger performance than competing systems while costing roughly 50% less.

From DARPA AIxCC Winners to the Microsoft Security FORGE Lab

Microsoft also announced the launch of the Security Frontier Offensive Research and Generative Exploration (FORGE) Lab.

The lab will be led by Team Atlanta, the cybersecurity researchers who won DARPA’s AI Cyber Challenge (AIxCC) at DEFCON in summer 2025. Microsoft hired the team to head the initiative, Gallot said.

Taesoo Kim, who led Team Atlanta, will head the FORGE Lab. He described the DARPA competition as a “real world AI cyber challenge” and said the winning teams combined cutting-edge research with practical engineering.

DARPA’s process encouraged teams to “strike the balance between engineering and high-risk, high-return research throughout the competition,” Kim reported. Microsoft, he said, provided the ideal environment to translate those advances into production given its scale across Azure and GitHub.

The lab’s mission, Kim explained, is to “advance the frontier of offensive security research and accelerate the evolution from AI-assisted vulnerability discovery to autonomous security research.” In other words, FORGE is meant to be the bridge from DARPA-level breakthroughs to enterprise defenses.

External Red Team Alliance: Spreading AI Safety Research Worldwide

Finally, Microsoft announced the External Red Team Alliance (EXTRA), a two-pronged initiative to broaden AI safety research.

The first piece involves Microsoft’s in-house AI red team distributing “unrestricted gifts” to 18 university labs across six continents, all in support of AI safety-related research.

Ram Shankar Siva Kumar, Microsoft’s head of the AI red team, explained in a blog post published July 17 that the funding comes with no strings attached. The goal isn’t to steer research toward specific products or predetermined outcomes.

Some of these universities are digging into the cybersecurity risks posed by AI systems themselves, looking at how models might be exploited, manipulated, or misused in real-world settings. Others are tackling the flip side: how AI can be leveraged to strengthen defenses and enhance cyber operations.

The initiative’s second component focuses on assembling a distributed network of specialized experts who can contribute to red teaming efforts in niche areas. According to Siva Kumar, this network will draw on researchers, practitioners, and regional specialists with knowledge of particular attack methods, languages, cultural nuances, or technical fields, areas where Microsoft’s internal teams may lack complete coverage.

For security teams watching the AI arms race, Microsoft’s message is clear: the defenders need the same weapons as the attackers. Whether that bet pays off will depend on execution, but the company is certainly not sitting still.

Continue Reading

Trending