Cyber Warfare on Tap: Water Utility Hacks, Nation-State APTs and Secure Browsers
What happens when nation-state hackers target the water coming out of your tap? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem break down the recent wave of attacks on water utilities across Minnesota and 27 other states, where threat actors got their hands on administrative passwords to programmable logic controllers. The crew is joined for the first time by Kelly Venzke, Director of Business Operations at IT Audit Labs, who brings a business leadership perspective to a conversation that quickly turns technical. From there, Eric and Nick trace how these attacks echo the Stuxnet playbook used against Iran's nuclear program, explain how threat actors are impersonating help desk staff over Microsoft Teams to gain remote access, and dig into a blockchain-based command and control technique that hides inside paid search ads. The conversation wraps with practical advice on browser security, including why isolating AI browser extensions and ditching saved passwords in the browser matters more than most people realize. In this episode: Nation-state hackers breach US water utilities across 27 states. How Iranian threat actors obtained administrative access to programmable logic controllers and why Minnesota may have been ground zero. The Stuxnet connection. Eric breaks down how the historic attack on Iran's nuclear centrifuges bridged an air-gapped network, and why today's "air-gapped" systems often aren't as isolated as they seem. Help desk impersonation over Microsoft Teams. Why blocking external Teams-to-Teams calls has become a critical defense against social engineering attacks targeting employees. EtherHiding: blockchain-backed command and control. How attackers use paid search ads and blockchain infrastructure to maintain persistent, hard-to-detect access to compromised environments. Practical browser security tips. Kelly, Eric, and Nick talk through password managers, isolating LLM browser extensions, and why saving passwords in your browser is a bad habit worth breaking. Don't wait until your organization is the next headline. Like, share, and subscribe for more conversations on the threats shaping cybersecurity and IT today. #Cybersecurity #InfoSec #NationStateThreat #CriticalInfrastructure #WaterSecurity #APT #EtherHiding #BrowserSecurity #ITAudit #Stuxnet



