en.osm.town is one of the many independent Mastodon servers you can use to participate in the fediverse.
An independent, community of OpenStreetMap people on the Fediverse/Mastodon. Funding graciously provided by the OpenStreetMap Foundation.

Server stats:

257
active users

#ot

4 posts4 participants1 post today

#Moxa warns of two flaws in its #routers and security #appliances that enable privilege escalation and remote command execution.

"Moxa addressed privilege escalation and OS command injection #vulnerabilities in cellular routers, secure routers, and network security appliances."

CVE-2024-9138 (CVSS 4.0 score: 8.6)
CVE-2024-9140 (CVSS 4.0 score: 9.3)

#KRITIS #OT #RCE
securityaffairs.com/172770/ics

Security Affairs · Moxa router flaws pose serious risks to industrial environmetsMoxa warns of two flaws in its routers and security appliances that enable privilege escalation and remote command execution.

📌 Claroty is growing and looking to hire a Partner Services Offering Architect who embodies our core values: People First, Customer Obsession, Strive for Excellence, and Integrity. This individual will manage the technical implementation and execution of our partner-focused services program and drive long-term customer value. More info and apply here: claroty.com/open-positions/05.

Ahoy infosec.exchange!

After I've been lurking around here for quite a while, I think it's time for an #introduction.

My current Mastodon mode of operation is to randomly stick my head into this collaborative stream of consciousness from time to time, observe whatever floats by quietly and most likely leave without any interaction.

In general, I seek to understand the reality we live in and try to figure out how to improve it. This involves far too many details and unfortunately I tend to engage in all kinds of side quests instead of working on what matters the most.

I've not decided yet how much and what parts of myself I want to disclose around here. So, expect some more lurking. If I post something, it will probably revolve around #automation, #communication, #cybersecurity, #education, #it, #networks, #ot, #privacy or #python.

Last week I mentioned a SCADA mgr position available at Seattle Public Utilities (SPU).

That listing is now live:

governmentjobs.com/careers/sea

This position leads, manages, organizes, and directs SPU’s SCADA 23 person OT team. They maintain a standalone zero trust network, servers, workstations, and 250 remote sites used to monitor and control the public water and wastewater systems.

#water #OT #ICS #infosec

I am not the hiring mgr. I am just a deeply invested colleague.

PLEASE BOOST!!

www.governmentjobs.comSCADA Operations Technology Manager (Mgr. 3)An online application must be fully completed to receive consideration. This position is open continuous until filled. First consideration will be given to candidates who apply by 5:00pm (PT) on January 10, 2025.Are you a seasoned SCADA Operations Technology Manager who's interested in protecting Seattle's public water and wastewater systems?Seattle Public Utilities (SPU) is recruiting for a SCADA Operations Technology Manager. This position leads, manages, organizes, and directs SPU’s Supervisory Control and Data Acquisition (SCADA) Operations Technology (OT) team consisting of 23 highly skilled professional staff which maintains a standalone zero trust network, servers, workstations, and 250 remote sites used to monitor and control the public water and wastewater systems.Additionally, this team engineers Industrial Control Systems (ICS) which consists of combining various control components (e.g., electrical, mechanical, hydraulics, pneumatic, etc.) and SPU’s ability to collect real-time data within our systems. The services supported by SCADA support safe and reliable delivery of drinking water to 1.6M customers regionally, and wastewater services for all 750,000 City of Seattle residents.SCADA is mission critical in the safety of our systems from cyber-attacks, and this team enables the secure monitoring and control with this division's Control Center operations of SPU's regional infrastructure and prevents any outside parties from accessing SPU’s critical systems. An outside attack could paralyze part or all of SPU’s water and wastewater systems.About Seattle Public Utilities: Seattle Public Utilities (SPU) is a community-centered utility that delivers vital services to Seattle residents and businesses including drinking water, drainage and wastewater, and garbage/recycling/compost. SPU also provides drinking water for 1.5 million customers in the region. SPU’s work includes system maintenance and improvements and keeping Seattle clean. Over 1,400 SPU employees work with our community to provide affordable and equitable stewardship of our water and waste resources for future generations.  For more information about Seattle Public Utilities (SPU), checkout the:  SPU Website SPU Workplace Expectations Strategic Business Plan  SPU commits to Our City Values and Race and Social Justice as core principles that guide our work. We actively take steps to dismantle systemic racism and increase service equity. We value diverse life experiences and strive to create a workplace that is welcoming to all. We take steps to be inclusive and equitable in our recruiting, hiring and promotional opportunities. 

Our team at @censys has studied Internet exposure of #ICS for the better part of a year, learning more about the products, protocols, and nuances of this space.

Today I'm excited to share our third annual ✨State of the Internet Report detailing what we've learned! A few highlights:

🛜 Most ICS protocols and HMIs we've observed run on 5G/LTE (e.g., Verizon) or SOHO/business-grade ISPs (e.g., Comcast). We initially observed this in the U.S. and in this most recent research found that it's a global phenomenon. This surprised me initially, but industrial devices often need to run in places where a wired connection might not be available. While great for connectivity, use of such networks makes it often impossible to determine who owns or operates a given service, as the host metadata points back to the telco itself.

💧 Analysis of over 200 C-More human-machine interfaces (HMIs) revealed over a third appear to be related to water and wastewater systems (WWS). WWS has seen increased targeting over the last ~year, and these exposures suggest still more work is needed to adequately protect and defend this sector.

⛔️ We found nearly 200 hosts globally running HMIs alongside products banned by U.S. NDAA Section 889. While this act applies only to a specific set of operators within the U.S. federal government, it's interesting to note what technologies operators implement alongside potentially critical services.

#infosec #cybersecurity #OT

You can find a copy of the report with all the details here! 👇

censys.com/the-2024-state-of-t

Censys · The 2024 State of the Internet Report | CensysIn their third annual State of the Internet Report, the Censys Research Team is back with fresh insights into the state of internet security and its implications for organizations and their security teams.

Today in 'ask your internet pals this' requests, I'm looking for tips from #ActuallyAutistic #diabetes communities for an #Autistic adult (39) recently dxed with T2D (meds only, no insulin). They work, have lots of commitments, bad balance & hate exercise (vestibular over-responsiveness). The difficulty they need help with is new habit formation & saying goodbye to constantly stress stimming on cronchy foods. Any advice/resources/signposting welcome!
#Diabetic #OT #dietitian #SensoryFriendly

CISA has warned that hackers continue to be capable of compromising industrial control systems using "unsophisticated methods" - suggesting that much more still needs to be done to secure them properly.

Meanwhile, hackers claim to have changed chlorine levels at Lebanese water facilities...

Read more in my article on the Tripwire blog: tripwire.com/state-of-security

📣 Die neue Ausgabe unseres #KRITIS Newsletter von @HonkHase ist online!

Freuen Sie sich auf folgende Themen:

👉 Der HiSolutions-NIS2-Kompass hat eine BSI-Schwester erhalten
👉 Verabschiedeter Regierungsentwurf des #NIS2UmsuCG frei verfügbar
👉 #NIS-2-FAQ vom @bsi
👉 #Südwestfalen-IT (SIT) ist nach neun Monaten weitestgehend wieder online
👉 Cybersecurity-Dienstleister sorgt für weltweite #KRITIS-Ausfälle
👉 Deutsche Strategie zur Stärkung der #Resilienz gegenüber #Katastrophen
👉 #OT-Risiko-Kochbuch vom @vdmaonline zu #Industrial Security

Jetzt lesen + abonnieren ▶️ hisolutions.com/detail/kritis-

#KRITIS Sektor #Transport und #Verkehr

UR E27 Cyber resilience of on-board systems and equipment

"Technological evolution of vessels, ports, container terminals, etc. and increased reliance upon Operational Technology (#OT) and Information Technology (IT) has created an increased possibility of cyber-attacks to affect business, personnel data, human safety, the #safety of the #ship, and also possibly threaten the #marine environment. Safeguarding shipping from..."
iacs.org.uk/resolutions/unifie

iacs.org.ukSafer and Cleaner Shipping - IACS

Question #BoostWelcome

#5g for #OT/ #Manufacturing is a big topic. And i don't (completely?) get it 🤔

I find it hard to separate the marketing blah (basically 5g solves everything) from real information.

One thing i understand, 5g brings low latency and high throughout ✅

But, the first question I can't find definite information on:
Are we talking about private 5g networks or is it using the standard 5g networks by the mobile providers?

And depending on the answer, there are a lot of follow up questions

US warns of Russian #hackers targeting operational technology in water systems

Coming off the heels of an APT breaching a small water facility in Texas a couple weeks ago.

A reminder that #cyberattacks can have impacts on the real world. Encourage you to share with your friends who don’t think this is the case.

#cybersecurity #security #ot

nextgov.com/cybersecurity/2024

Nextgov.comUS warns of Russian hackers targeting operational technology in water systemsThe advisory represents official U.S. confirmation that Russian operatives have breached water systems.