Someone attempted to poison water supply in Florida city during hack
tampabay.com
tampabay.com
who wants to bet this might have been as simple as improper usage/implementation of Teamviewer gone wrong?
when dealing with persons/organizations who are not focused on infosec/netsec issues, given the opportunity and ability to do so, never underestimate the workarounds and kludges that people will install to "make their job easier", such as putting teamviewer on control system PCs running water systems.
Well the superbowl was being played that weekend a few miles away on Sunday and so there was a large amount of media and visitors in town for the game(also heavy national coverage). Glad they reverted it as who knows what would have happened if left unchecked.
Either someone messed up, or there is a resourceful attacker.
* Remote access to systems that could kill people must be limited to people with the following thought out permissions and secured credentials
And more:
* The list of people who can access this system must be documented
* The accounts must have their password be changed every 6 months
* A committee must review the set of outstanding patches and upgrades for known issues every 4 months and prioritize what to fix
* I hope that someone is actually installing those patches and upgrades.
Surely they'll be capable of configuring a corporate VPN without a fat budget to have Cisco do it for them...right?