Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Ot Threats And Notifications topic

No spam. Unsubscribe anytime.

CISA details OT threats, vendor/MSP misconfigurations and use of administrative subpoenas

The Cybersecurity and Infrastructure Security Agency (CISA) · December 8, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

CISA vulnerability team described how threat actors exploited programmable logic controllers to cause a water-site outage, highlighted persistent scanning via Shodan and Censys, and said CISA uses administrative subpoenas to identify owners of exposed OT devices and notify them.

CISA's Vulnerability Management team used the webinar to illustrate the real-world risks that insufficient OT visibility creates, describing concrete cases where online discovery, default credentials and misconfigured third-party providers enabled disruptive attacks.

Sean McCoy, who leads risk and vulnerability exposures and notification at CISA, cited a case in which a threat group identified in his briefing as "Cyber Avengers" exploited a programmable logic controller model used to regulate water pressure at a booster pump station. "That was targeted and disabled ... causing damages and operational outages, as well as over 20k in repairs," McCoy said, attributing the details to vulnerability-notification work his team performed.

McCoy said attackers commonly locate targets through internet scanning services (mentioning Shodan and Censys) and then exploit IT-adjacent services such as VNC or RDP that provide remote access to OT sites. He urged operators to perform external audits of their networks to discover exposed devices and reduce attack surface.

CISA’s enforcement and outreach tools: McCoy described the agency's use of its administrative subpoena authority to go to internet service providers and managed-service providers to identify the owners of exposed devices when public scanning shows only an ISP. "When we take a look at these devices externally ... all we see is the internet service provider, and we don't really see who the actual owner is," he said, explaining that subpoenas allow CISA to identify affected owners and notify them of vulnerabilities.

Third-party risk: McCoy also warned that integrators and managed-service providers can replicate misconfigurations across multiple utilities, creating widespread exposure. He recommended that inventories explicitly capture third-party relationships and delineate responsibilities for configuration and auditing.

Takeaway: CISA recommended external scanning and immediate remediation for internet-exposed OT devices, tracking firmware and patch levels in inventories, and including third-party providers in inventory and audit processes to reduce repeated misconfiguration risks.