Manuel Urueña

@muruenya.bsky.social

Security Architect at Redeia. Entropy fighter. @muruenya@infosec.exchange

NEW: An industry memo obtained by @wired.com links dozens of cyberattacks on Minnesota’s water system to Iran-backed hackers. Clues point to the IRGC’s Cyb3rAvengers group, but other details point to another group, Handala. No official attribution has been made. @agreenberg.bsky.social w/ the scoop:

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.

wired.com

More than 30 water systems in Minnesota have been hit in what officials call a “coordinated cyberattack.” One said the hacking shared characteristics with those that federal agencies have been warning against — shortly after federal alerts about Iranian hacking. www.reuters.com/legal/litiga...

Minnesota IT officials disclose 'coordinated cyberattack' at more than 30 local water systems

A "coordinated cyberattack" targeted more than 30 ‌community water systems in the U.S. state of Minnesota on July 26 and July 27, the state's IT agency said in a statement.

reuters.com

New: A cyberattack that threatened to cut heating to half a million people in Poland last winter was formally attributed Monday to Russia’s Federal Security Service, as the United Kingdom and European Union imposed their first coordinated package of cyber sanctions against Russian hackers.

Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions

The allies blamed Center 16, the FSB’s signals intelligence arm, for acts of attempted cyber sabotage targeting Poland’s energy sector and water treatment facilities, alongside “a wide range of malici...

therecord.media

Every year we write about the exciting developments in post-quantum signatures. Last year didn't disappoint. But it's too late. As ekr wrote in 2024 "You go to war with the algorithms you have, not the ones you wish you had." ML-DSA will have to do for now. blog.cloudflare.com/ml-dsa-will-...

Why we cannot wait for better post-quantum signature algorithms

NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and sh...

blog.cloudflare.com

Personally I think Dashlane's update to its 2FA-busting data breach is still lackluster and doesn't say much more beyond its original post. That said, @dangoodin.bsky.social does a solid job of reading between the lines and filling in the gaps. tl;dr: Bruteforcing 2FA codes was relatively easy.

Dashlane explains how attackers managed to download encrypted password vaults

By targeting large numbers of users, attackers increased their chances of success.

arstechnica.com

Exclusive: Fast16 malware has raised questions about what it was designed to do. Researchers at Symantec finally confirm it was subverting software used to simulate nuclear weapons explosions. Nuclear experts also tell me Iran was the likely target and explain how it impacted nuclear weapons tests

Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran

Fast16 didn't predate Stuxnet but was contemporaneous with it. It also wasn't aimed at altering nuclear weapons but was simply feeding false data to engineers about the nuclear detonation tests they w...

zetter-zeroday.com

I ORDER MY COFFEE BLACK. NO SUGAR. NO MILK. NO WATER. NO CUP. THEY HAND ME THE BEANS. I EAT THEM IN THE PARKING LOT LIKE A HORSE. THE BARISTAS HAVE STOPPED CHARGING ME. I HAVE NOT SLEPT SINCE TUESDAY. I CAN HEAR THE WIFI

New: A British utilities company supplying drinking water to 1.6 million people failed to discover hackers hidden inside its computer network for nearly two years before the intrusion came to light through an IT performance slowdown, the UK's data protection regulator has found.

UK water company allowed hackers to lurk undetected for nearly two years, regulator finds

The Information Commissioner's Office (ICO) fined South Staffordshire Water £963,900 ($1.3 million) on Monday over an attack by the Cl0p ransomware group that led to the personal data of 633,887 custo...

therecord.media

Thank you Microsoft for removing TLS 1.0 & 1.1 support for POP & IMAP clients connecting to Exchange Online, starting July 2026. It is only 5 years and a month since RFC 8996 / BCP 195 was published, deprecating TLS 1.0 & 1.1 for use on the Internet 😎 www.bleepingcomputer.com/news/microso...

Microsoft to deprecate legacy TLS in Exchange Online starting July

Microsoft says it will start blocking legacy TLS connections for POP and IMAP email clients in Exchange Online starting in July 2026.

bleepingcomputer.com

Kaspersky has a report out on Lotus Wiper, which it believes was the malware behind the Petroleos de Venezuela "ransomware" attack in December of last year They don't specifically say it, but they imply it very obviously. They also don't mention the US once. securelist.com/tr/lotus-wip...

Lotus Wiper: a new threat targeting the energy and utilities sector

Kaspersky researchers analyze the attack chain of a highly destructive Lotus Wiper that can be linked to a targeted attack on the energy and utilities sector.

securelist.com

There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers. This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys

There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.

words.filippo.io