# Over 100 US Water Systems Targeted, CISA Calls for Better Exposure Management

*Published August 31, 2026*
*Source: [https://www.sans.org/newsletters/newsbites/xxviii-64](https://www.sans.org/newsletters/newsbites/xxviii-64)*

## Executive Summary

Over 100 US water systems have been attacked, revealing persistent cybersecurity weaknesses. CISA emphasizes the need for better exposure management and the establishment of shared capabilities to protect these utilities.

## Article

Recent reports have unveiled that more than 100 water systems in the United States have been attacked, underscoring vulnerabilities in the sector's cybersecurity defenses. The Cybersecurity and Infrastructure Security Agency, known as CISA, has emphasized the need for improved exposure management to prevent similar incidents in the future. Despite CISA's sound guidance, the repeated occurrence of similar weaknesses across numerous water systems points to a systemic issue that requires a more coordinated approach.

The attacks on these utilities highlight the necessity for a shared capability that can continuously identify exposed assets within the water sector and assist in their remediation. Such a capability could be operated through a trusted organization like WaterISAC, MS-ISAC, a state program, or a consortium of utilities. This would ensure that even smaller utilities, which may lack extensive cybersecurity resources, can benefit from a centralized system that identifies threats and vulnerabilities in real time.

Additionally, the OWASP GenAI LLM Top 10 for 2026 has been introduced, providing a framework to address the most critical security risks associated with artificial intelligence and machine learning models. The inclusion of ten new Common Vulnerabilities and Exposures, or CVEs, in the CISA Known Exploited Vulnerabilities catalog further underscores the need for vigilance among security professionals.

The water sector's exposure to cyber threats is a stark reminder of the importance of proactive cybersecurity measures. By leveraging shared capabilities and following CISA's guidance, utilities can better protect themselves against future threats and ensure the safety and reliability of essential water services.
