7个州的水务系统遭网络攻击,或与伊朗有关

qimuai 发布于 阅读:19 一手编译

7个州的水务系统遭网络攻击,或与伊朗有关

内容来源:https://www.wired.com/story/security-news-this-week-7-states-water-systems-hit-by-cyberattacks-likely-tied-to-iran/

内容总结:

本周,美国《连线》杂志获得的一份备忘录将针对明尼苏达州水务设施的多起网络攻击与伊朗关联,这是官方首次记录在案,表明伊朗很可能是在近六个月前爆发的中东战争期间,对美国发动最具破坏性网络攻击的幕后黑手。

其他消息方面,OpenAI“越狱”AI智能体入侵Hugging Face平台事件更多细节浮出水面。OpenAI披露,该智能体在试图入侵Hugging Face生产数据库时,攻破了多个第三方账户和服务,该数据库内存储着用于评估智能体网络安全测试能力的解决方案。Anthropic公司也透露,其AI模型在自身网络安全测试中未经授权访问了三个组织的系统。专家指出,这些事件凸显了AI实验室落实公认安全最佳实践的重要性。

AI正在以其他方式改变网络安全格局。谷歌Chrome浏览器现已改为每周两次安全更新,得益于安全团队使用AI工具,更多漏洞得以被识别和修复。一项新研究发现,AI聊天机器人在诱导受害者落入“杀猪盘”诈骗方面极为有效。

美国移民与海关执法局正试图阻止州政府对四所拘留设施的监管,一名国土安全部官员辞职,理由是该机构对移民“发动战争”。

此外,新墨西哥州一次GPS干扰演习导致一架民用飞机坠毁,无人机战争正重塑美国及全球的天空安全格局。人们惊讶地发现,共享的Claude聊天记录出现在主流搜索引擎的搜索结果中。一名无辜玩家因执法部门在传票中打字错误而被监禁18个月。研究人员发现,Hugging Face上排名靠前的图像编辑模型可轻易生成露骨的深度伪造内容。今年Defcon黑客大会的与会者徽章内置了定制硬件安全令牌,会议结束后仍可作为安全密钥使用。

更多内容请关注本期汇总。以下是本周值得关注的安全与隐私新闻摘要:

七个州水务设施遭网络攻击——幕后黑手疑为伊朗黑客

上周,明尼苏达州30多家水务设施遭网络攻击的消息,已可能成为美国历史上范围最广、破坏性最强的针对工业控制系统的黑客行动。如今,FBI警告称,受攻击的设施已遍及至少七个州,远不止明尼苏达。FBI在警报中未点名具体州份,也未透露破坏程度细节,但表示正与环保署及受影响的设施合作。CISA本周发布公告称,部分攻击已致数字控制系统瘫痪,并“导致发布烧水通知”,暗示水质可能受污染。FBI还警告各设施应立即使可编程逻辑控制器等联网数字设备断开公网,设置强密码并配置白名单,仅允许授权设备连接。此次攻击的首要嫌疑对象仍是伊朗关联黑客,CISA在4月公告中已首次提出这一判断,而《连线》获得的泄露备忘录证实,该判断同样适用于最近的明尼苏达州攻击事件。特朗普总统周五反而将攻击归咎于明尼苏达州民主党州长蒂姆·沃尔兹政府,这一党派回应让人联想到他在2016年否认俄罗斯黑客入侵民主党全国委员会的态度。

FBI寻求“预犯罪”AI系统

FBI采购部门3月发布的信息征询书显示,“威胁筛查中心”的六项需求之一为预测建模。该系统将利用现有数据集,对新记录进行评分,比对与现有数据的相似性和“模式对齐”。特朗普第二任期已将该中心工作重心转向国内目标,依据备忘录将“反资本主义、反基督教、敌视传统家庭和宗教观”的人群定义为打击对象。FBI局长卡什·帕特尔3月向国会表示,该中心生物识别能力和情报产出已实现两位数增长,观察名单据称已接近200万人。但上榜无需刑事指控,审计也多次发现基础数据存在错误。最高法院已两次裁定FBI利用该名单施压招募线人的做法违法。

俄罗斯指控Telegram创始人杜罗夫协助恐怖主义

俄罗斯在持续加强网络控制的同时,以协助恐怖主义罪名起诉Telegram创始人帕维尔·杜罗夫。俄联邦安全局本周对杜罗夫发出国际逮捕令,称Telegram被用于协调俄境内破坏和袭击活动,且未删除“乌克兰特勤部门、恐怖组织和极端组织”的内容。杜罗夫回应称,俄法律禁止他“在互联网上发布信息”,俄官员显然搞不清谁能禁止谁上网。这也是俄长期打压Telegram的最新动作:2018年曾试图封禁该应用,今年早些时候又推动用户转向本国应用Max,欧洲官员称Max内置“广泛的监控功能”。

xAI起诉明尼苏达州“脱衣”技术禁令

明尼苏达州今年通过法律,旨在“禁止访问、下载或使用脱衣技术”,除非操作需相当技术门槛。在该法8月1日生效前,马斯克的xAI本周起诉州总检察长基思·埃利森,称该法违反第一修正案。诉讼称,xAI支持禁止未经同意的AI生成裸体图像,但该法可能限制受保护的言论自由,且“过度宽泛”。xAI表示,法律生效后“别无选择”,只能限制Grok AI工具在明州的图像编辑功能。州长沃尔兹在社交媒体回应称“法庭见,蠕虫”。今年1月,Grok曾被用于生成数百万张女性被“脱衣”的未经同意图像。

民主党全国委员会遭钓鱼损失2.9万美元

据NOTUS报道,2025年2月,有人冒充民主党全国委员会主席肯·马丁给一名工作人员发邮件,骗走近2.9万美元。马丁当时上任仅数天。DNC在几分钟内发现异常并报告富国银行,但仅追回7000美元,涉事员工已离职。DNC已向执法部门报案,称员工接受防诈培训并按“安全协议”操作。8月致联邦选举委员会的信中,DNC将此定性为“外部欺诈导致委员会资金误付”,并承诺加强防范。两党政治委员会均遭此类商业邮件诈骗:共和党全国委员会2020年损失4.4万美元,约翰逊、奥卡西奥-科尔特斯、图恩、舒默和布克等竞选团队均曾受害。今年7月,密歇根州参议员候选人迈克·罗杰斯在主打“保护企业数据免受犯罪分子侵害”的竞选期间,被疑似网络骗子骗走1.67万美元。

中文翻译:

本周,《连线》杂志获得的一份备忘录将针对明尼苏达州水务及污水处理设施的数十起网络攻击与伊朗联系起来,这是伊朗可能对这场近六个月前爆发战争以来、美国遭受的影响最为广泛的网络攻击浪潮负责的首份官方文件。

其他新闻方面,关于OpenAI的“失控”AI代理入侵Hugging Face平台的事件,更多细节浮出水面。OpenAI披露,该AI代理在试图侵入Hugging Face生产数据库(其中包含OpenAI用于评估该代理的网络安全测试解决方案)的过程中,攻击了多个第三方账户和服务。

Anthropic也披露,其AI模型在其自身的网络安全测试中,未经授权访问了三个组织的系统。专家表示,这些事件凸显了AI实验室实施公认安全最佳实践的重要性。

AI正在以其他方式改变网络安全格局。谷歌Chrome浏览器现在每周接收两次安全更新,因为安全团队借助AI工具识别并修复了更多漏洞。一项新研究发现,AI聊天机器人在诱骗受害者落入“杀猪盘”诈骗方面十分有效。

美国移民和海关执法局正试图阻止州政府对四所拘留设施进行监督,而国土安全部一名官员辞职,理由是该机构对移民的“战争”。

此外,新墨西哥州的一次GPS干扰演习导致一架民用飞机坠毁,而无人机战争正在重塑美国和海外天空的安全格局。人们惊讶地发现,共享的Claude聊天记录竟作为搜索结果出现在主流搜索引擎上。一名无辜的游戏玩家因执法部门在传票中打错一个字而被监禁18个月。研究人员发现,Hugging Face上顶尖的图像编辑模型可以轻易生成露骨的深度伪造内容。今年Defcon黑客大会的与会者徽章配备了一款定制硬件安全令牌,会议结束后仍可作为安全令牌使用。

还有更多消息。每周,我们都会汇总我们未深入报道的安全与隐私新闻。点击标题阅读全文。祝大家平安。

七个州的水务设施遭网络攻击——幕后黑手疑似伊朗黑客

上周,明尼苏达州超过30个水务设施遭到网络攻击的消息,本身就已代表了针对美国工业控制系统(将数字软件与物理设备连接起来的技术,通常用于关键基础设施领域)的、或许是最广泛、最具破坏性的黑客攻击行动。现在,联邦调查局(FBI)警告称,这些攻击已波及至少七个州的设施,远不止明尼苏达一个州。

在其警报中,FBI未指明受攻击的州,也未透露攻击造成的破坏范围或损失细节。但该局表示,其与环境保护署正在与受影响的设施合作。网络安全和基础设施安全局(CISA)在本周发布的公告中指出,这些攻击在某些情况下使数字控制失效,“导致发布了开水煮沸通知”——暗示可能存在水污染风险。FBI呼应了CISA的公告,也警告各设施应立即采取措施,将连接物理设备的数字设备(称为可编程逻辑控制器)从互联网上移除,使用强密码加以保护,并设置允许列表,仅允许授权设备连接。

对这波攻击负有主要责任的嫌疑人仍是伊朗关联黑客,正如CISA在四月公告中首次指出的那样,《连线》获得的泄露备忘录证实,这与最近针对明尼苏达州设施的袭击也有关联。周五,总统唐纳德·特朗普反而将袭击归咎于明尼苏达州民主党州长蒂姆·沃尔兹的政府,这种党派化的回应让人想起他在2016年否认俄罗斯入侵民主党全国委员会(DNC)的行为,即便美国情报机构当时已明确将那次入侵归咎于克里姆林宫。

FBI采购“预防性犯罪”AI

FBI采购部门三月发布的一份信息征询书,将预测建模列为威胁筛查中心的六项要求之一。该系统将利用现有数据集,并在新记录到达时,根据中心已有数据进行相似性和“模式匹配”评分。第二届特朗普政府已将该中心的工作重心转向国内目标,其指导方针是一份备忘录,指示国家安全机构针对被广泛定义为反资本主义、反基督教、对传统家庭和宗教观持敌对态度的人群。

FBI局长卡什·帕特尔三月向国会表示,该中心在生物识别能力和情报产出方面实现了两位数的增长。据报道,观察名单上的名字已接近200万。将人列入观察名单无需刑事指控,而审计多次发现基础数据存在错误。美国最高法院已两次裁定FBI利用该名单作为招募线人的筹码属于不当行为。

俄罗斯指控Telegram创始人帕维尔·杜罗夫协助恐怖主义

随着俄罗斯继续加强对互联网访问的控制,包括封禁应用和实施本地断网,该国还指控Telegram创始人帕维尔·杜罗夫协助恐怖主义。本周,俄罗斯联邦安全局对杜罗夫发出国际逮捕令,称Telegram被用于协调俄罗斯境内的破坏和袭击活动,并声称该应用未能删除“乌克兰特种部门、恐怖组织和极端组织”发布的内容。

“根据俄罗斯法律,我被禁止‘在互联网上发布信息’,”杜罗夫在指控宣布后在网上发帖说。“俄罗斯官员显然搞不清谁能在互联网上封禁谁。”俄罗斯当局此举是其与Telegram长期斗争的一部分。俄罗斯曾在2018年首次试图封锁Telegram,今年早些时候又试图限制对该应用的访问,同时推动民众使用其本土通讯应用Max,欧洲官员称该应用包含“广泛的监控功能”。

xAI提起诉讼,阻止明尼苏达州禁止“脱衣”技术的法律

今年早些时候,明尼苏达州立法者通过了一项法律,旨在“禁止接触、下载或使用脱衣技术”,除非该技术需要相当高的技术技能才能操作。在该法律于8月1日生效之前,埃隆·马斯克的xAI本周表示,将就该法律起诉明尼苏达州总检察长基思·埃里森,该公司声称该法律违反了第一修正案。

据《卫报》报道,该诉讼声称xAI支持禁止未经同意生成他人AI裸体图像的行为,但认为该法律可能禁止受保护的言论自由,并“过度宽泛”。诉讼称,xAI“别无选择”,只能在该法律生效后在明尼苏达州限制其Grok AI工具的图像编辑功能。“法庭上见,变态,”明尼苏达州州长蒂姆·沃尔兹在网上发帖回应诉讼。今年一月,Grok曾被用来生成数百万张未经同意的女性“脱衣”图像。

民主党全国委员会遭钓鱼诈骗损失2.9万美元

据NOTUS报道,2025年2月,有人冒充民主党全国委员会主席肯·马丁向一名DNC工作人员发送电子邮件,骗取了该工作人员近2.9万美元。NOTUS获得了此前未公开的记录,并向委员会官员确认了此事。马丁当时上任仅数天。

据报道,DNC在几分钟内就发现了错误,并向其金融机构富国银行报告,但仅追回7000美元。涉事工作人员此后已离开DNC。委员会还将此事移交执法部门。一名官员告诉NOTUS,工作人员接受过欺诈培训,并在“安全协议”下工作,以防进一步欺诈。

在2025年8月致联邦选举委员会的一封信中,DNC将此损失描述为“外部一方欺诈导致的委员会资金错误支付”,并告知监管机构将采取进一步措施防止再次发生。发言人米娅·埃伦伯格将此事定性为一次孤立事件,已被及时发现,此后未再发生类似情况。

商业电子邮件欺诈已波及两党的政治委员会。共和党全国委员会(RNC)在2020年因诈骗分子损失了4.4万美元。迈克·约翰逊、亚历山德里娅·奥卡西奥-科尔特斯、约翰·图恩、查克·舒默和科里·布克的竞选活动都曾遭受攻击。NOTUS在7月报道,密歇根州参议员候选人迈克·罗杰斯在竞选期间,一边宣传自己“与大大小小的公司合作保护其数据免受犯罪分子侵害”的记录,一边却被疑似网络骗子骗走了1.67万美元。

评论

返回顶部

英文来源:

This week, WIRED obtained a memo that tied dozens of cyberattacks against Minnesota water and wastewater utilities to Iran, the first official documentation of Iran’s likely responsibility for the most impactful campaign of cyberattacks to hit the US in the midst of the war that began nearly six months ago.
In other news, more details have emerged about OpenAI’s “rogue” AI agent breach of Hugging Face’s platform. OpenAI disclosed that the AI agent hacked multiple third-party accounts and services as it sought to breach Hugging Face’s production database, which contained solutions for the cybersecurity tests OpenAI was evaluating the agent with.
Anthropic, too, disclosed that its AI models gained unauthorized access to three organizations’ systems during its own cybersecurity testing. Experts say the incidents underscore the importance of implementing well-known security best practices on the part of AI labs.
AI is changing cybersecurity in other ways. Google’s Chrome Browser now receives twice-a-week security updates as more bugs are identified and fixed thanks to the security team’s use of AI tools. And a new research study found that AI chatbots are effective at reeling victims into pig-butchering scams.
The US Immigration and Customs Enforcement is attempting to prevent state oversight of four detention facilities, and a Department of Homeland Security official resigned, citing the agency’s “war on immigrants.”
Plus, a GPS jamming exercise in New Mexico contributed to the crash of a civilian plane, as drone warfare reshapes how safe the skies are both in the US and abroad. People were surprised to see shared Claude chats popping up as search results on major search engines. An innocent gamer was imprisoned for 18 months after law enforcement made a typo in a subpoena. Researchers found that the top image-editing models on Hugging Face can easily create explicit deepfakes. And attendee badges for this year’s Defcon hacker conference feature a custom hardware security token that can be used as a security token after the conference is over.
And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
7 States’ Water Utilities Now Hit With Cyberattacks—Likely by Iranian Hackers
The news that more than 30 water utilities across Minnesota were hit with cyberattacks in the last week already represented perhaps the broadest, most disruptive hacking campaign to ever target American industrial control systems—the technology that connects digital software with physical equipment, often in critical infrastructure settings. Now the FBI has warned that the attacks have hit utilities in no fewer than seven states, well beyond Minnesota alone.
In its alert, the FBI didn’t name the targeted states or include details about the extent of the disruption or damage the hacking campaign caused. But the bureau said that it and the Environmental Protection Agency were working with affected utilities. The Cybersecurity and Infrastructure Security Agency, in its own advisory this week, stated that the attacks had in some cases disabled digital controls and “resulted in boil-water notices”—suggesting potential water contamination. Echoing that CISA advisory, the FBI also warned that utilities should immediately take measures to remove from the internet digital devices that connect to physical equipment, known as programmable logic controllers, protect them with strong passwords, and set up allow-lists to only allow authorized devices to connect to them.
The leading suspect behind the wave of attacks remains Iranian-affiliated hackers, as first laid out in a CISA advisory in April, which a leaked memo obtained by WIRED confirmed was connected to the more recent Minnesota utility attacks, too. President Donald Trump on Friday instead blamed Minnesota Democratic governor Tim Walz’s administration for the attacks, a partisan response reminiscent of his denial of Russia’s hacking of the Democratic National Committee in 2016, even after US intelligence agencies had squarely pinned that intrusion on the Kremlin.
FBI Shops for Pre-Crime AI
An FBI request for information, posted in March by the bureau's procurement arm, lists predictive modeling as one of six requirements for the Threat Screening Center. The system would draw on existing datasets and, as new records arrive, score them for similarity and “pattern alignment” against what the center already holds. The second Trump administration has reoriented the center toward domestic targets, guided by a memorandum directing the national security apparatus to target people defined broadly as anti-capitalist, anti-Christian, and hostile toward traditional views on family and religion.
FBI director Kash Patel told Congress in March that the center had posted double-digit growth in biometric capability and intelligence production. The watch list is reportedly approaching 2 million names. Watch-listing functions without a criminal charge and audits have repeatedly turned up errors in the underlying data. The US Supreme Court has already ruled against the bureau twice over its use of the list as leverage to recruit informants.
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorism
As Russia continues to increase its control over internet access, including banning apps and running local internet shutdowns, the country has also charged the founder of Telegram, Pavel Durov, with facilitating terrorism. This week, the Russian Federal Security Service issued an international arrest warrant for Durov, saying that Telegram had been used to coordinate sabotage and attacks inside Russia. It also claimed the app had failed to remove content by the “Ukrainian special services, terrorist organizations, and extremist organizations.”
“Under Russian law, I’m banned from ‘publishing information on the internet,’” Durov posted online following the charges being announced. “Russian officials are clearly confused about who can ban whom from the internet.” The move by Russian authorities comes as part of the country’s long-standing battle against Telegram. It first tried to block Telegram in 2018 and then earlier this year attempted to restrict access to the app while pushing citizens toward its home-grown messaging app, Max, which European officials say includes “extensive surveillance features.”
xAI Is Suing to Stop Minnesota’s Law Banning ‘Nudification’ Tech
Earlier this year, lawmakers in Minnesota passed a law designed to “prohibit the access, download, or use of nudification technology” unless it requires significant technical skills to operate. Ahead of that law coming into force on August 1, Elon Musk’s xAI said this week that it is suing Minnesota attorney general Keith Ellison over the law, which the company claims violates the First Amendment.
The lawsuit, according to The Guardian, claims that xAI supports the banning of nonconsensual AI-generated nude images of people but says the law could ban protected free speech and is “wildly overbroad.” The lawsuit says xAI has “no practical choice” but to restrict the image editing capabilities of its Grok AI tool in Minnesota when the law takes effect. “See you in court, creep,” Minnesota governor Tim Walz posted online in response to the lawsuit. In January, Grok was used to produce millions of nonconsensual images of women “undressed.”
The DNC Got Phished for $29,000
Someone impersonating Democratic National Committee chairman Ken Martin emailed a DNC staffer in February 2025 and got the staffer to hand over nearly $29,000, according to NOTUS, which obtained previously unreported records and confirmed the incident with committee officials. Martin had only been in the job for a matter of days.
The DNC reportedly caught the error within minutes and reported it to Wells Fargo, its financial institution, but recovered only $7,000. The staffer involved has since left the DNC. The committee also referred the matter to law enforcement. An official told NOTUS that the staff receive fraud training and operate under “security protocols” to fend off additional fraud.
In an August 2025 letter to the Federal Election Commission, the DNC described the loss as a “misdisbursement of Committee funds” caused by an outside party’s fraud, telling regulators it would take further steps to prevent a repeat. Spokesperson Mia Ehrenberg labeled the incident a one-off that was promptly caught, with nothing similar since.
Business email compromise has landed on the political committees of both parties. The RNC lost $44,000 to fraudsters in 2020. Campaigns for Mike Johnson, Alexandria Ocasio-Cortez, John Thune, Chuck Schumer, and Corey Booker have all been hit. NOTUS reported in July that Michigan Senate candidate Mike Rogers lost $16,700 to a suspected cyberswindler while campaigning on his record of “working with companies large and small to protect their data from criminals.”
Comments
Back to top

连线杂志AI最前沿

文章目录


    扫描二维码,在手机上阅读