Attackers changed passwords and modified IP addresses on internet-facing programmable logic controllers and locked the operators out. Nobody at a water utility decided one morning to put a controller on the open internet. Critical infrastructure is always going to need remote privileged access, so the goal was never to get rid of it, it’s to make every connection intentional, limited, visible, and removable. And when one changed password can put a whole town on a boil-water notice, I don’t think this counts as an IT security issue anymore, it’s part of keeping the water on. The post Someone Changed the Password on a Water Utility’s PLC appeared first on 12Port.