Cybersecurity grabbed the spotlight last week in the government tech media, driven by a state/local government-focused attack that has reverberated nationally. There was also a fair amount of discussion about threats and vulnerabilities related to open-source software. Here’s the week’s roundup:
Minnesota Water Facilities Under Attack
The Cybersecurity and Infrastructure Security Agency (CISA) has been busy over the past week. The agency responded to news that hackers brought down water utility systems in Minnesota, generating coverage across federal, state/local and cybersecurity trade publications – as well as the mainstream media. Here’s a sampling of the coverage we saw over the past week:
- More than 30 Minnesota communities saw their water and wastewater utilities disrupted by a coordinated cyberattack early last week, Colin Wood reported in StateScoop.
- Justin Doubleday of Federal News Network wrote that CISA issued a bevy of new cyber guidance to federal agencies, contractors and critical infrastructure organizations following the Minnesota attacks and reports of similar threats to other municipal water systems.
- CISA warned water and wastewater utilities that hackers were targeting internet-exposed programmable logic controllers and urged utility operators to remove those devices from direct internet access immediately, an article by Grace Dille in MeriTalk noted.
- David DiMolfetta wrote in Nextgov/FCW that CISA said the attacks locked water utility operators out of systems, disrupted facilities and triggered boil-water notices.
- In a separate article, DiMolfetta reported that industry group Operational Technology Cybersecurity Coalition (OTCC) urged CISA to strengthen defense against these attacks with a governmentwide directive establishing baseline cybersecurity requirements for operational technology used across federal civilian agencies.
- Shaun Waterman quoted OTCC Executive Director Tatyana Bolton in GovInfoSecurity stating the controls imposed by CISA should generally include asset inventory, persistent visibility across networks, microsegmentation and secure remote access.
- Waterman’s colleague Chris Riotta noted that disclosure of the Minnesota attacks came days after federal agencies updated a joint advisory warning that Iranian-affiliated actors are targeting internet-connected industrial controllers across U.S. critical infrastructure.
- As of late last week, cybersecurity experts were saying they were at least moderately confident that the attacks against the Minnesota water facilities were the work of hackers with ties to Iran, according to coverage in The Hill by Mira Bhakta.
- Going a bit further, researchers at Tenable said they suspect the Iran-linked “faux hacktivist outfit” CyberAv3ngers was behind the attack, as reported in an article by Connor Jones in tech trade pub The Register.
- Jule Pattison-Gordon authored a piece for Governing about how Minnesota municipalities responded to the attacks, noting that one city reverted to manual methods and got its systems back online within two days.
Is Open-Source Software Too Open?
Continuing CISA’s busy week, the agency also issued recommendations related to protecting open-source software from attack – which several publications noted comes at a time when open-source AI has become more prevalent:
- CISA published a guidebook for federal agencies to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models, Tim Starks reported in CyberScoop.
- The CISA guidance recommends that agencies have a formal review and approval process in place before adopting open-source tools, so that security risks are managed from the outset, Miles Jamison wrote in ExecutiveGov.
- Writing in FedScoop, Lindsey Wilkinson covered public comments last week by FBI official Todd Hemmen, who asserted that the Mythos AI model “found vulnerabilities in some of the open-source code that is so ubiquitous — it’s in the vast majority of our most foundational code for things like operating systems, security, web infrastructure, encryption…It presents future challenges for law enforcement.”
- Julia Shapero and Miranda Nazzaro noted in The Hill that security concerns have ignited a debate in Silicon Valley about “the recent push for open-source technology, which gained momentum earlier this year amid growing competition with China and the Trump administration’s ad hoc approach to AI regulation.”
- According to an analysis by Patrick Tucker in Defense One, industry leaders believe the future of AI will be driven in significant part by startups and small players using open-source software to make cheaper, more efficient versions of Claude or ChatGPT and “the challenge now is protecting those public tools from increasingly sophisticated attacks from China, Russia, North Korea, or other players.”
Upcoming Industry Events
Once again, we noted a few industry events this week we think are worth your time:
- August 1-6: Black Hat USA, Black Hat, Mandalay Bay Convention Center, Las Vegas, Nevada
- August 4-6: Irregular Warfare Center Annual Symposium, Federal Business Council, DoubleTree Hilton, Arlington, Virginia
- August 4: Federal Insights Exchange: Integrated Security and Emergency Management, ACT-IAC, Appian Headquarters, McLean, Virginia
- August 5: Google Defense Roadshow: The AI mission advantage, GovExec/Google Cloud, Google DC – Massachusetts Ave, Washington, D.C.
If you would like your event included in this list, please fill out this form.
That covers the biggest trending government tech stories for this week. I hope you’re finding these roundups useful. If so, please share this with a friend. And if a friend shared this with you, subscribe on LinkedIn or via the form below to receive it every week.