Security03:15 · 1h ago

Former NSA Chief Warns Iranian Cyberattacks on US Water Systems Highlight Growing AI Threats

Calcalist
Translated & summarized from Calcalist by baba
The story · English

Mike Rogers, retired US Navy admiral and former head of the NSA and US Cyber Command, discussed recent Iranian cyberattacks targeting US water infrastructure. He explained that while such attacks are not new, with Iran previously targeting water systems in the US, Israel, and the Persian Gulf, the decentralized nature of US water management creates many vulnerable points, especially in smaller towns with limited cybersecurity resources. Rogers noted that the attacks mainly affected smaller communities rather than large cities like New York or Los Angeles, aiming to demonstrate Iran's ability to cause geographically widespread impact and sow psychological fear.

Rogers expressed relative confidence in the cybersecurity of large urban water systems but emphasized the inherent vulnerabilities in smaller segments. He highlighted that the Iranian attacks are intended to send a message about their capabilities rather than to cripple the US economy, which remains largely unaffected. The admiral also addressed the emerging threat posed by AI in cyber warfare, explaining that AI accelerates and scales attack capabilities by autonomously identifying and exploiting software vulnerabilities, as seen in recent incidents involving AI agents breaching networks like Hugging Face.

He warned that AI lowers the barrier for cyberattacks, enabling not only state actors but also individuals with limited expertise to launch impactful operations. This broadens the range of potential attackers from nation-states to frustrated individuals or ideologically motivated actors worldwide. Rogers stressed the importance of cyber resilience, urging infrastructure operators to assume breaches will occur and focus on limiting lateral movement within networks and maintaining situational awareness.

Regarding government response, Rogers acknowledged no country is fully prepared for cybersecurity challenges and questioned the current US federal approach that places primary responsibility on network owners. He argued that critical infrastructure, which affects national security and public welfare, requires a different, more coordinated strategy involving government support and resource allocation. He also cautioned against focusing solely on specific AI models, advocating for viewing cybersecurity threats as an ecosystem of diverse tools and actors.

In summary, Rogers highlighted the evolving cyber threat landscape shaped by AI advancements and stressed the need for enhanced resilience and strategic collaboration to protect critical infrastructure from increasingly sophisticated and widespread attacks.

Read the original at Calcalist
Open the live terminal