One minute
US Water Sector Cyberattack
ในช่วงวันที่ 26 ก.ค.–3 ส.ค. ระบบ water and wastewater ในหลายรัฐของอเมริกา (Minnesota, Michigan, Georgia, …) โดนโจมตีทางไซเบอร์ นับเป็นเหตุการณ์โจมตีระบบ OT แบบ coordinated attack ที่ค่อนข้างใหญ่ (มีที่ยืนยันว่าโดนโจมตี อย่างน้อย 45 ระบบ) 😑
มีการวิเคราะห์กันว่าผู้โจมตีน่าจะเป็นกลุ่ม CyberAv3ngers ของอิหร่าน
ใน OT cybersecurity community มีหลายคนรวบรวมข้อมูลและให้ความคิดเห็นไว้ (Bob Radvanovsky, Dale Peterson, Andrew Krapf, …) เนื่องจากช่วงนี้ยังไม่มีเวลาศึกษารายละเอียด เลยมาจดไว้ก่อน 😅
- Water Sector Cyberattack Consolidated Report
- Daily Water Utility Cyber Intelligence Report
- Water Incident Correlation Matrix v12
- US Water Sector OT Security Plan(s)
- The End of Complacency? (I can hope…)
- The CyberSecureOT Report: State-Sponsored Threats and the Fragility of Municipal Water
- Read the Gauge, Not the Screen
เท่าที่อ่านแบบผ่านๆ หลายคนพูดคล้ายกันว่าต้องมี regulation ที่กำหนด security baseline สำหรับ sector แต่ก็ควรกำหนดระดับความเข้มข้นของ controls ให้เหมาะสมกับระดับผลกระทบที่มีต่อประชาชนของแต่ละหน่วยงานด้วย
ส่วนการป้องกันขั้นพื้นฐานก็ทำตาม best practices สำหรับระบบ OT ทั่วๆ ไป เช่น
- แยกเครือข่ายระหว่าง IT/OT
- ไม่เอา PLC หรืออุปกรณ์ระบบ OT เชื่อมต่อเข้าอินเทอร์เน็ตโดยตรง
- ไม่เปิด ports หรือ services ที่ไม่จำเป็น
- เปลี่ยน default password ของอุปกรณ์
- physical switch ที่บล็อกการแก้ไข code/firmware
- offline backup
- manual operating mode ที่ทำงานร่วมกับ local indicator (ไม่ใช่ดูจากหน้าจอ HMI อย่างเดียว)
- ฯลฯ
cybersecurity operational technology water sector CyberAv3ngers
140 Words
2026-08-09 20:10 (Last updated: 2026-08-15 09:28)
dce348e @ 2026-08-15