The group compromised major U.S. telecommunications providers, including AT&T, Verizon, and Lumen, gaining access to sensitive communications and U.S. law enforcement wiretap systems.
CISA shares advice on isolating vital systems during cyberattacks
- July 28, 2026
- 02:41 PM
- 0

The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
The guidance, titled "CI Fortify – Advice for isolating vital systems," was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), the FBI, and international partners.
It provides recommendations for disconnecting critical operational technology (OT) and associated systems from corporate, Internet-facing, and other less-trusted networks while continuing to provide essential services for an extended period.
Operational technology includes the hardware and software used to monitor or control processes, such as water treatment equipment, electrical systems, manufacturing machinery, transportation systems, and telecommunications infrastructure.
The agencies say state-sponsored threat actors routinely target critical infrastructure for espionage and to establish access that could later be used for disruptive or destructive attacks during a crisis or military conflict.
"Cybercriminals continue to opportunistically target CI operators," reads the advisory.
"The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes."
In February 2024, CISA, the FBI, NSA, and other Five Eyes agencies warned that the Chinese Volt Typhoon hacking group had breached organizations in the communications, energy, transportation, and water sectors.
The hackers remained undetected in at least one critical infrastructure network for five years, with U.S. officials warning that they were positioning themselves for potentially disruptive attacks during a future crisis or conflict.
Chinese state-sponsored hackers tracked as Salt Typhoon have also breached government, telecommunications, transportation, lodging, and military networks worldwide since at least 2021.
The group compromised major U.S. telecommunications providers, including AT&T, Verizon, and Lumen, gaining access to sensitive communications and U.S. law enforcement wiretap systems.
The hackers also exploited known vulnerabilities in edge networking devices and used compromised equipment and trusted connections to pivot into other networks.
Water infrastructure has also repeatedly been targeted. In October 2024, American Water, which provides water and wastewater services to more than 14 million people, deactivated some systems following a cyberattack. Around the same time, a Kansas water treatment facility switched to manual operations after its systems were compromised.
Government agencies have also warned that pro-Russian hacktivists were seeking out unsecured OT systems used by water facilities and other critical infrastructure organizations to disrupt operations.
The new CI Fortify guidance aims to help organizations prepare before such an incident occurs, rather than attempting to determine how vital systems can be disconnected while an attack is already underway.
Isolating vital systems
The agencies recommend critical infrastructure entities first identify the minimum systems and networks required to continue delivering a critical service.
Organizations should then document every connection between those systems and corporate networks, remote-access services, cloud environments, Internet-facing infrastructure, vendors and contractors, and other critical infrastructure operators.
They should also determine where those connections can be disabled or physically disconnected and account for the manual processes, communication failures, and loss of external resources or dependencies that isolation may trigger.
Some of the terms and processes that the advisory recommends organizations become familiar with include:
- Vital systems: The minimum OT and supporting systems needed to provide a critical service, such as controlling water distribution, delivering electricity, or operating a telecommunications network.
- Isolation point: A predetermined location where connectivity between critical and non-critical networks or systems can be disconnected to contain an attack and prevent lateral movement into other vital systems.
- Physical isolation: Completely disconnecting vital systems so they do not share network or computing infrastructure with non-critical systems. The guidance describes this as the most effective form of protection.
- Graduated isolation: Gradually restricting access as the threat increases, such as first blocking remote workers and vendors, then disconnecting corporate networks, connected systems, and eventually all external connections.
- Administrative network controls: Various administrative controls to modify or manage VLANs, access-control lists, and routing. The guidance says these can be useful temporary protections but that physical isolation should be the ultimate goal.
- Data diode: Specialized equipment that allows data to flow in only one direction, reducing the risk that data or malicious traffic can travel in the opposite direction.
- Post-isolation: Monitor routing tables, network traffic, and intrusion detection systems to verify that isolation controls remain effective. Administrators should also secure the network management zones used to administer routers, firewalls, and other network infrastructure so they are isolated from attackers.
While physical isolation provides the best protection, the cybersecurity agencies say that it may not be practical for organizations that depend on Internet-facing services, carrier networks, cloud services, or geographically distributed facilities.
In those environments, operators are advised to strengthen OT network boundaries, use dedicated or encrypted communications links, remove unnecessary dependencies on corporate systems, and maintain the ability to rapidly rebuild systems.
Isolation plans should also define who can authorize each step, the conditions that would trigger it, which systems must remain available, and how operations will continue without normal network connectivity.

Organizations are urged to test the complete isolation of their vital systems regularly, rather than testing only individual systems, because partial tests may fail to identify shared infrastructure and other hidden dependencies that could cause problems when the isolation plan is initiated.
The guidance also recommends keeping a secure offline or printed copy of the isolation plan so that it remains available in the event that access to corporate network or storage servers are disrupted.
After systems have been isolated, operators should continue monitoring network traffic, routing information, and management systems to ensure that unauthorized or accidental connections have not restored access between critical and non-critical networks.
However, the agencies warn that isolation also introduces risks, including systems falling behind on security updates, reduced monitoring, and increased use of removable media to transfer data between systems
Organizations must therefore prepare not only to disconnect vital systems, but also to operate, monitor, update manually until they can eventually reconnect systems again.
LAATEST ARTICLES
-
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations.
- July 29, 2026
- 12:04 PM
0
-
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack."
- July 29, 2026
- 10:55 AM
0
-
[Webcast] How Drata scaled IT governance in the AI era

Running IT for a fast-growing org with a small team sounds like a recipe for chaos. Not for the Drata team. Learn how they got visibility into shadow SaaS, scaled governance, and kept up with a fast-moving org in the AI era.
-
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI.
- July 29, 2026
- 10:02 AM
0
-
Windows 11 KB5101684 update released with 42 changes and fixes
Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system.
- July 29, 2026
- 09:56 AM
0
-
These near-mint ASUS Chromebook refurbs are only $145
Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97 (reg. $369.99) on sale.
- July 29, 2026
- 07:12 AM
0
-
CubePilot drone software dev hit by DNS hijacking to intercept traffic
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack.
- July 28, 2026
- 05:17 PM
0
-
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face.
- July 28, 2026
- 04:37 PM
3
-
CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
- July 28, 2026
- 02:41 PM
0
-
vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering.
- July 28, 2026
- 02:08 PM
0
-
Use Claude AI to become an Excel pro with this $20 course bundle
For just $19.99, the Claude AI for Microsoft Excel Mastery Bundle gives you lifetime access to five courses that teach you how to use Claude AI to simplify everyday spreadsheet work instead of wrestling with it on your own.
- July 28, 2026
- 02:06 PM
0
-
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect.
- July 28, 2026
- 10:00 AM
0
-
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
- July 28, 2026
- 08:10 AM
0
-
Lifetime access to ChatGPT, Claude, Gemini & more in one $70 AI app
1min.AI Advanced Business Plan is so appealing because instead of bouncing between platforms, it brings dozens of AI-powered tools together under one account for a one-time $69.97 through Aug. 9 (MSRP $540).
- July 28, 2026
- 07:11 AM
0
-
Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.
- July 28, 2026
- 05:10 AM
0
-
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
- July 27, 2026
- 07:49 PM
0
-
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.
- July 27, 2026
- 06:49 PM
0
-
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations.
- July 27, 2026
- 05:08 PM
1
-
New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.
- July 27, 2026
- 05:00 PM
0
-
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store.
- July 27, 2026
- 01:29 PM
1
-
Coca-Cola confirms data theft in Fairlife ransomware attack
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month.
- July 27, 2026
- 11:39 AM
0
===




No comments:
Post a Comment