❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help

31 August 2026 at 14:36

The Trump administration rolled out a six-month test program in Texas on Monday that will draw on volunteer expertise and technology from cyber and artificial intelligence companies to protect the water sector.

“Project Watershed 250” is the first of the state-based, industry-centric pilot projects to cross the finish line that the Office of the National Cyber Director has previewed since the publication of its national cybersecurity strategy earlier this year. Water systems have long been viewed as among the most vulnerable and neediest critical infrastructure sectors, and in recent months the sector has been the victim of a spree of attacks.

“Project Watershed 250 is a commitment from the states, industry and federal government that we will continue to prioritize our nation’s safety and deliver on America-first policies for the American people,” National Cyber Director Sean Cairncross said at a rollout event in San Antonio Monday.

“U.S. companies are providing world-class cyber capabilities, red teaming that tests utilities’ current defenses, system hardening using the latest private sector cyber tools and AI tooling that helps utilities’ frontier cyber defenders to protect Texas water systems and scale proven solutions across the country,” he said. “This six-month pilot program is designed to make our water and wastewater critical infrastructure more resilient and resistant to cyber attacks by proactively finding and fixing system weaknesses.”

The pilot program, featuring collaboration between federal and state governments, stands in contrast to how the Biden administration tried to tackle the issue, with audit requirements that some GOP states challenged in court, forcing Biden’s Environmental Protection Agency to withdraw its rule.

“For too long, at least on the federal level, the government has admired the problem of cybersecurity in water systems,” Cairncross said. “We are going to find out what works. We’re going to target that, and we are going to scale off of this and learn lessons.”

A dozen companies — Parsons, Microsoft, Fortinet, Google Cloud, Palo Alto Networks, Amazon Web Services, Reflection AI, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos — appeared at the rollout Monday to praise the initiative and tout their contributions to it.

Not everyone praised the initiative elsewhere, however. One cyber professional who works on water security issues, speaking on condition of anonymity, said the program was “all smoke” and that “there’s no real money behind it.”

“The White House did what it always does — reached out to industry with their hands out asking for industry to pay for things the government should be doing, at least in part,” the person said.

Texas Gov. Greg Abbott said the program would be overseen by Cairncross’s office and Texas Cyber Command, which was established just last year. Abbott cited the need for the program by mentioning “an Iranian-backed cyberattack” on 30 water systems across 12 states and a 2024 attack on the water system in Muleshoe, Texas, suspected to be the work of Russian hackers.

“The need for cyber resilience is overwhelming,” Abbott said. “Many rural providers simply don’t have the resources they need to be able to protect themselves.”

Watershed 250 isn’t the only federal effort to bolster water cybersecurity, with lawmakers introducing legislation in the aftermath of the recent attacks. Past legislation that Congress has enacted also sought to tackle the problem.

Updated 8/31/26: with comment from cyber professional.

The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help appeared first on CyberScoop.

Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online

By: Greg Otto
6 August 2026 at 15:10

A new scan of internet-connected industrial equipment found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on U.S. water systems.

The findings, published Wednesday by Forescout’s Vedere Labs, show that direct internet access to equipment used in water and wastewater operations remains common despite years of warnings from manufacturers and federal agencies.

The exposed devices use EtherNet/IP, an industrial protocol that allows for communication between control equipment, engineering workstations and other systems. When the port is open to the public internet, outside users may be able to identify devices and, depending on their setup, change settings or write new configurations.

The scan, run through the Shodan search engine Monday, found that 2,844 of the exposed controllers (65%) were in the United States.

The FBI and Environmental Protection Agency issued a joint advisory last week confirming attacks at water and wastewater utilities in at least 12 states since July 27. Officials have since named Michigan, South Dakota and Georgia among the affected states. Nine systems were hit in Michigan, and one wastewater lift station was hit in South Dakota.

Several reports have linked the attacks to Iranian actors, but Sai Molige, senior manager of threat hunting at Forescout, says the company has not attributed this activity to any actor or group.  

“The evidence supports opportunistic, at-scale exploitation of a known class of vulnerabilities affecting internet-exposed devices,” Molige told CyberScoop. “The scale and speed of the activity are more consistent with mass scanning and enumeration than with zero-day exploitation, a months-long intrusion campaign, or custom malware.”

The advisory said attackers targeted programmable logic controllers (PLCs) made by Rockwell Automation under its Allen-Bradley brand, specifically the MicroLogix 1100 and 1400 models. In at least one case, attackers reached controllers remotely and changed their IP addresses and passwords, cutting off the utility’s own view and control of the equipment. The advisory said the attacks caused pressure loss and flooding.

Forescout’s research states that the most common exposed device family was the MicroLogix 1400, which made up half of the devices found. Other versions, such as AllenBradley’s CompactLogix 1769 controllers, made up 22%. MicroLogix 1100 and ControlLogix 5590 devices each accounted for about 8%.

Forescout cross-referenced those machines against the recently targeted cities and municipalities and found 22 devices still exposed to the internet. However, the company did not say those systems had been attacked or that they belonged to the affected utilities.

The research also found that 19 of the 22 hosts in affected cities appeared, based on firmware versions, to be open to CVE-2017-16740, a remote code execution flaw disclosed in 2017 that impacts MicroLogix 1400 devices. An attacker would need Modbus TCP enabled to use that flaw, and the researchers could not confirm whether the affected systems had it enabled.

Rockwell Automation and other industrial equipment makers have warned customers not to place controllers directly on the public internet as far back as 2018.

Beyond the controllers, the researchers also looked at the digital records tied to these utilities. They found expired certificates, remote-access web addresses left unrenewed for months or years, and servers that appear abandoned — in one case, a server that has shown nothing but a default Microsoft webpage since April 2019. 

“These stale services can increase the attack surface; however, we have not yet confirmed how the observed attacks occurred,” Molige told CyberScoop.

The post Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online appeared first on CyberScoop.

❌
❌