Article Details

Scrape Timestamp (UTC): 2024-03-20 05:51:29.718

Source: https://thehackernews.com/2024/03/us-epa-forms-task-force-to-protect.html

Original Article Text

Click to Toggle View

U.S. EPA Forms Task Force to Protect Water Systems from Cyberattacks. The U.S. Environmental Protection Agency (EPA) said it's forming a new "Water Sector Cybersecurity Task Force" to devise methods to counter the threats faced by the water sector in the country. "In addition to considering the prevalent vulnerabilities of water systems to cyberattacks and the challenges experienced by some systems in adopting best practices, this Task Force in its deliberations would seek to build upon existing collaborative products," the EPA said. In a letter sent to all U.S. Governors, EPA Administrator Michael Regan and National Security Advisor Jake Sullivan highlighted the need to secure water and wastewater systems (WWS) from cyber attacks that could disrupt access to clean and safe drinking water. At least two threat actors have been linked to intrusions targeting the nation's water systems, including those by an Iranian hacktivist group named Cyber Av3ngers as well as the China-linked Volt Typhoon, which has targeted communications, energy, transportation, and water and wastewater systems sectors in the U.S. and Guam for at least five years. "Drinking water and wastewater systems are an attractive target for cyberattacks because they are a lifeline critical infrastructure sector but often lack the resources and technical capacity to adopt rigorous cybersecurity practices," Regan and Sullivan said. The development coincides with the release of a new fact sheet from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), urging critical infrastructure entities to defend against the "urgent risk posed by Volt Typhoon" by implementing secure by-design principles, robust logging, safeguarding the supply chain, and increasing awareness of social engineering tactics. "Volt Typhoon have been pre-positioning themselves on U.S. critical infrastructure organizations' networks to enable disruption or destruction of critical services in the event of increased geopolitical tensions and/or military conflict with the United States and its allies," the agency cautioned. Cybersecurity firm SentinelOne, in a report published last month, revealed how China has launched an offensive media strategy to propagate "unsubstantiated" narratives around U.S. hacking operations for over two years. "Repeating China's allegations helps the [People's Republic of China] shape global public opinion of the U.S. China wants to see the world recognize the U.S. as the 'empire of hacking,'" Sentinel One's China-focused consultant Dakota Cary said. "The fact that China is lodging allegations of US espionage operations is still notable, providing insight into the relationship between the US and China, even if China does not support its claims." Goodbye, Atlassian Server. Goodbye… Backups? Protect your data on Atlassian Cloud from disaster with Rewind's daily backups and on-demand restores. Take Action Fast with Censys Search for Security Teams Stay ahead of advanced threat actors with best-in-class threat intelligence from Censys Search.

Daily Brief Summary

NATION STATE ACTIVITY // U.S. EPA Launches Task Force Against Water System Cyberthreats

The U.S. Environmental Protection Agency (EPA) is creating a Water Sector Cybersecurity Task Force to protect water systems from cyberattacks.

EPA Administrator Michael Regan and National Security Advisor Jake Sullivan expressed concerns to U.S. Governors about the vulnerability of water and wastewater systems to cyber threats.

Cyber Av3ngers and China-linked Volt Typhoon are among the groups identified as targeting U.S. water systems.

There are significant risks involved as water systems are critical infrastructure, yet often lack adequate cybersecurity safeguards.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a fact sheet warning of the serious risk posed by Volt Typhoon and advised implementation of cybersecurity best practices.

SentinelOne reported China's media strategy aims to manipulate global perception of U.S. hacking activities and espionage.