Reading view

Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says

An anonymous reader quotes a report from NBC News: Cyberattacks targeting municipal water systems have been reported in at least seven states this week, prompting the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure. In a public service announcement Thursday, the agencies said water and wastewater utilities have reported incidents to the FBI, with some malicious activity degrading water operations. The announcement does not name the states. The warning comes after hackers targeted more than 30 municipal water facilities in Minnesota in an attack that had hallmarks of Iranian meddling, according to a law enforcement official. It is still under investigation. A spokesperson for Minnesota's information technology services agency said Thursday there was no indication the breaches contaminated any municipal water supplies. The federal Cybersecurity and Infrastructure Security Agency said in a separate alert that some larger attacks on water infrastructure had "resulted in boil water notices and sustained manual operations," though it did not say where. [...] The federal advisory said the malicious cyber actors, or MCAs, targeted specific brands of control systems used by municipal water utilities, though the FBI and the EPA urged operators of all systems to take precautions. [...] The agencies said the hackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities. The federal advisory calls on system operators to remove programmable logical controllers, or PLCs, from direct internet exposure by putting them behind secure gateways and firewalls; use strong passwords; and limit communications between authorized control system devices through access control lists.

Read more of this story at Slashdot.

  •  

Flock Cameras Are Being Destroyed Across the US

An anonymous Slashdot reader writes: Surveillance cameras owned by Flock Safety have been cut down with electric saws in New York State, vandalized with paint in Oakland, California, and rammed with a truck in Idaho. Flock claims its services fight crime, but law enforcement agencies also use their services to track vehicles based on license plate numbers and reconstruct the their movements, even when the drivers and owners of these vehicles have never been accused or convicted of any crime. (Flock states it has 120,000 automated cameras that record license plate data, as well as pan-tilt-zoom cameras, across the United States.) A guerilla mindset among average citizens have seen these cameras forcibly disabled within recent weeks with sympathy directed toward the vigilantes. In June, a West Virginia man accused of destroying several Flock cameras was arrested. Under a Facebook post from the local NBC affiliate announcing his arrest are dozens of people volunteering to provide alibis. "He was out fishing with me that day, you got the wrong guy," one man wrote.

Read more of this story at Slashdot.

  •  

AI Companies Are Recruiting Electricians and Carpenters By the Thousands

An anonymous reader quotes a New York Times report on how AI companies are pouring money into training and recruiting electricians, carpenters, and other skilled tradespeople to build data centers: There is no parallel in American history for the boom underway in the construction of data centers, fueled by companies with functionally unlimited cash that are racing to supply skyrocketing demand for their A.I. models. The explosion has offset flagging activity in other sectors, like office construction, which never recovered after the pandemic. Housing has been depressed by high interest rates, and offshore wind felled by political opposition. Still, competition for labor -- never mind land and materials -- is starting to weigh on other parts of the industry. "There's no question the resources are very limited, so decisions to build one thing kind of drag from another," said Mario Iacobacci, who runs the construction and infrastructure advisory practice at Oxford Economics. Developers are paying a premium for workers, especially in the rural areas where they are building data centers. According to an analysis by Indeed, the job listings website, hourly installation and maintenance jobs at data centers pay 42 percent more than similar jobs in other fields. Behind that inflated pay is a bidding war. In markets with a lot of data center construction, like Dallas and Northern Virginia, workers can jump ship for bonuses or higher per diem rates. The competition has driven contractors to staffing services like Aerotek. "It is creating a labor tension that is really delicate," said Marty Schager, Aerotek's director of data center market development. "You've got a passive job-seeker community out there right now that I think is looking to potentially capture opportunity with this once-in-a-generation data center gold rush." [...] The question looms over the apprentices who will become journeymen as the build-out reaches fever pitch. Fully trained electricians could shift to nuclear plants, apartment buildings or pharmaceutical factories. But it's hard to imagine anything on the scale of what's underway. "The best-case scenario would be you train all these skilled workers up and right when the data centers start to become less popular is we'd have a housing boom," said Jeff Strohl, director of Georgetown University's Center on Education and the Workforce. "That's probably not likely." "If we have an influx of workers at this point with the data centers being built, what happens when they're done? Where do those workers go?" he said. "How many people does it take to run a data center after taking up all this property and all this land that could have been used for something else?"

Read more of this story at Slashdot.

  •  

New Orleans Cops Published Policy Document Allowing Weaponized Drones

A draft New Orleans Police Department drone manual briefly published online would have allowed police drones to carry weapons with written approval from the superintendent, according to 404 Media. NOPD says the document was only an early draft and that its current policy (PDF) bans drones from carrying weapons or hazardous materials. 404 Media reports: The current version, live as of July 1, has different language: "The sUAS shall not be equipped with weapons or hazardous materials of any kind," referring to small Unmanned Aerial Systems, or drones. According to the NOPD, the operations manual it published to the internet with the rules for weaponized drones was an early draft. "The manual published on July 1 is the current published version of the policy. Earlier versions were draft versions that were presented for review before adoption of the current policy," NOPD told 404 media. "NOPD has made it clear we are not and will not be equipping drones with weapons or other hazardous materials." NOPD didn't answer follow-up questions about how or why the draft version of the manual was published. But the publication of a police drone manual that opens the door for weaponized quadcopters is important, and comes as drone companies and police flirt with the idea of putting weapons on their drones. New Orleans has long been a pioneer of camera and drone driven policing and the cops have used controversial tactics to get around public scrutiny and regulations. It shows that what the police are circulating amongst themselves and thinking about privately, what they perhaps want to happen, does not match public policy.

Read more of this story at Slashdot.

  •  

Head of US Safety Agency Resigns

Chris Fall has resigned as director of the U.S. Center for AI Standards and Innovation just three months after being appointed to lead the Commerce Department's federal AI testing institute. Arvind Raman, who oversees the Commerce office responsible for the institute, will serve temporarily in the role. "The Commerce Department did not provide a reason for Fall's departure," reports Reuters. From the report: Fall's exit marks the latest change in direction for Trump's approach to AI. The president upon returning to office in 2025 said the federal government should take a hands-off approach to the tech sector. He has since taken a more active role in monitoring the technology, though his public statements and policies appear to change week by week. The institute is responsible for working with leading AI labs such as Anthropic, Google's DeepMind and OpenAI to test their unreleased models for vulnerabilities. The group is staffed by scientists and engineers, who are focused on calculating the "demonstrable risks" posed by advanced AI models, according to the institute's website. They want to limit opportunities for U.S. adversaries to use AI to develop chemical or biological weapons, or corrupt the data used to train American AI models.

Read more of this story at Slashdot.

  •  

US Water Utilities Hacked After Default Passwords Set to '1111', Cybersecurity Officials Say

An anonymous reader shared this report from Fast Company: Providers of critical infrastructure in the United States are doing a sloppy job of defending against cyber intrusions, the National Security Council tells Fast Company, pointing to recent Iran-linked attacks on U.S. water utilities that exploited basic security lapses [earlier this month]. The security council tells Fast Company it's also aware of recent intrusions by hackers linked to China's military at American infrastructure entities that include water and energy utilities in multiple states. Neither the Iran-linked or China-linked attacks affected critical systems or caused disruptions, according to reports. "We're seeing companies and critical services facing increased cyber threats from malicious criminals and countries," Anne Neuberger, the deputy national security advisor for cyber and emerging tech, tells Fast Company. The White House had been urging infrastructure providers to upgrade their cyber defenses before these recent hacks, but "clearly, by the most recent success of the criminal cyberattacks, more work needs to be done," she says... The attacks hit at least 11 different entities using Unitronics devices across the United States, which included six local water facilities, a pharmacy, an aquatics center, and a brewery... Some of the compromised devices had been connected to the open internet with a default password of "1111," federal authorities say, making it easy for hackers to find them and gain access. Fixing that "doesn't cost any money," Neuberger says, "and those are the kinds of basic things that we really want companies urgently to do." But cybersecurity experts say these attacks point to a larger issue: the general vulnerability of the technology that powers physical infrastructure. Much of the hardware was developed before the internet and, though they were retrofitted with digital capabilities, still "have insufficient security controls," says Gary Perkins, chief information security officer at cybersecurity firm CISO Global. Additionally, many infrastructure facilities prioritize "operational ease of use rather than security," since many vendors often need to access the same equipment, says Andy Thompson, an offensive cybersecurity expert at CyberArk. But that can make the systems equally easy for attackers to exploit: freely available web tools allow anyone to generate lists of hardware connected to the public internet, like the Unitronics devices used by water companies. "Not making critical infrastructure easily accessible via the internet should be standard practice," Thompson says.

Read more of this story at Slashdot.

  •  
❌