Securing Water and Wastewater Operational Technology Environments
Publisher update
The brief
NIST describes three reference approaches for protecting remote access to water and wastewater control systems: conventional on-premises access, a cloud-managed option, and encrypted communication between systems. Its guidance combines technical controls with access policies and monitoring. The agency emphasizes that remote-access protection belongs within wider risk management and depends on knowing which operational assets need protection.
AI-assisted brief
Source NISTBy CheeYee Tang , Robert Stea, John Wiltberger
CERT-EU's September threat review highlights stolen AI-service access and hijacked cloud workloads. Its roundup cites Google's reporting on LLM-jacking and Microsoft's account of passkey-themed phishing against Microsoft 365 users. It also covers spyware targeting civil society and alleged unauthorized AI-agent activity. The monthly report separates law-enforcement, espionage, cybercrime and AI developments across Europe and globally, drawing on attributed public reporting.
Source CERT-EUCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.
EFF reports that Ecuador ordered security researcher and free-software developer Ola Bini’s deportation and imposed a ten-year reentry ban. The advocacy group says officials relied on a secret security report that his defense could not inspect, and that his lawyers sought habeas corpus protection. EFF says Bini was held at Quito’s airport awaiting departure for Sweden and urges authorities to explain the accusations.
Source Electronic Frontier FoundationBy Veridiana AlimontiCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.
GitHub now lets repository teams discuss vulnerability reports inside security advisories using comments restricted to users who currently have write access. Reporters and invited collaborators lacking that permission cannot read them or receive notifications; losing write access also removes visibility. Comment visibility cannot be changed after posting. GitHub says the feature covers public repositories with private vulnerability reporting enabled across its Free, Pro, Team and Enterprise Cloud plans.
GitHub has introduced a public preview of REST endpoints for reading, adding and editing repository advisory comments on public repositories. Access requires advisory visibility and appropriate repository security advisory permissions or token scopes; non-collaborators cannot read internal comments, and confidential comments are excluded. Comment deletion remains unsupported. Repository advisory responses now report non-confidential comment counts, letting integrations check for discussion before retrieving it.
SANS' October 2 Stormcast describes attackers emailing legitimate ScreenConnect clients configured to give them remote access, rather than exploiting a defect in the tool. It also relays Huntress reporting on custom GPTs steering people toward ClickFix commands, and discusses email impersonation research involving iCloud and Proton Mail. The episode says the iCloud issue was patched; the Proton Mail display-name issue remained unresolved.
EFF reports that a federal judge temporarily blocked enforcement of Utah’s VPN-related location requirements in SB 73. The organization argues that websites cannot reliably determine every VPN user’s physical location and that the requirements would expand invasive age checks beyond Utah. The ruling is a preliminary injunction, rather than a final decision; the lawsuit does not challenge the separate restriction on sharing VPN instructions.
Source Electronic Frontier FoundationBy Rindala AlajajiCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.