Mouz

Forget poisoned water, a cyberattack’s real threat to SA is empty reservoirs

· Citizen

Cybersecurity experts said this week that the greatest danger posed by a cyberattack on a utility like Rand Water is not contaminated drinking water, but the loss of pressure and control across a gravity-fed network serving millions of people.

Visit turconews.click for more information.

Their comments came after Rand Water confirmed a cybersecurity incident that hit its payments and GIS systems. The water utility insisted that water treatment and quality control had continued without interruption.

Worst-case scenario if Rand Water had a deeper cyberattack

Anna Collard, SVP, content strategist, and CISO advisor at KnowBe4, said the scenario most people imagine when they think of a water utility being hacked is actually the hardest for attackers to pull off.

“The dramatic scenario people imagine, like attackers poisoning the water by manipulating chemical dosing, is the hardest to pull off,” she said.

She explained that multiple independent safeguards are in place, including physical dosing limits, redundant sensors, and continuous laboratory testing.

The more realistic danger, Collard said, is attackers locking operators out of control systems, disabling alarms, or shutting down pumping stations.

“Reservoirs draw down in hours, not days,” she said, describing how quickly a gravity-and-pressure-dependent network serving more than 11 million people across Gauteng could be affected.

She added that higher-lying areas would go dry first, and that lost pressure carries a back-siphoning risk that can trigger precautionary boil-water notices.

Bongani Majola, head of DFIR at ScaryByte, offered a starker warning about what a deeper breach of operational technology could mean.

He said attackers with write-access to programmable logic controllers could, in theory, interfere with dosing or induce dangerous pressure surges.

“These physical disruptions can unfold within minutes,” he said, adding that restoring a compromised system could take weeks and leave communities without potable water in the meantime.

The Citizen reached out to the Department of Communications for comment on government’s cybersecurity systems. This article will be updated once comment is received.

Are South Africa’s state entities being targeted, or just exposed?

Both experts pointed to a mix of opportunism and heightened risk.

This comes after questions on whether the country’s state-owned entities are being deliberately targeted by attackers, following Transnet’s 2021 ransomware attack and a wave of attacks on water utilities in the United States this year.

Collard said most attacks on South African organisations are financially motivated and not aimed at targets of national significance.

“They aren’t picking targets off a map of national importance, they’re picking off a list of whoever left the door open,” she said.

She added that state-owned entities are disproportionately represented among victims because they tend to run large, ageing, and technically complex systems.

However, Collard did not entirely rule out a geopolitical dimension.

Referring to attacks on US water systems this year claimed by the group CyberAv3ngers, she said state-aligned actors find water utilities attractive because they are softer targets than the power grid and carry outsized psychological impact.

“South Africa is a BRICS member with an active, visible foreign policy posture, and we should not assume we’re invisible to that kind of actor. But in most cases it’s more likely financially motivated, and I’d caution against jumping to ‘we’re under state attack’ on the current evidence,” she said, adding that the far more common story is that criminals simply found an unlocked door.

Majola described a similar pattern, which he believed operated in two phases.

He said attackers typically started with automated, large-scale scans for unpatched systems or the harvesting of credentials before shifting to a more targeted operation once they realised they had compromised a major public utility.

Citing Transnet’s 2021 attack and past municipal billing shutdowns, he said state-owned entities become primary extortion targets “due to the critical nature of their services” once a breach is confirmed.

What Rand Water says happened, and what experts make of it

Rand Water’s own account of the incident focused on reassurance.

The utility said its treatment processes and quality control systems had continued to operate normally throughout the disruption, and that regular monitoring remained in place to ensure compliance with SANS 241 drinking water standards.

“Our core water delivery mandate continues uninterrupted, and we are committed to restoring full system functionality as quickly as possible,” the utility said.

A thin disclosure, but the right first priority

Collard said Rand Water’s disclosure of the situation was somewhat adequate.

“Rand Water’s statement gets the most important thing right: it addressed the question the public actually cares about, which is whether the water is safe,” she said.

She added that what remains thin is the detail on exactly what was affected, for how long, and whether any personal or vendor data was involved.

Majola said South Africa’s broader track record on technical disclosure after cyberattacks has been poor, with entities often defaulting to minimal statements.

He linked this partly to the absence of a legal mandate forcing more detailed reporting.

“Without a statutory mandate requiring detailed technical reporting, entities weaponise confidentiality to manage brand reputation and public panic,” he argued.

Separation of systems

Experts said that outcome, water quality unaffected while payments and GIS systems were hit, was a reasonable sign that separation between the utility’s IT and OT networks had functioned as intended.

According to Majola, the result suggested a working barrier between the corporate network and the SCADA control loops that manage pumps and valves.

However, he warned that the growing use of IoT sensors and remote monitoring in “smart utilities” is gradually narrowing that gap.

“An attacker who compromises the corporate IT network can move laterally across into the physical OT domain,” he said, if cross-domain connections are not properly secured.

Collard was more cautious about drawing firm conclusions from a single incident.

“There’s a big difference between having a firewall between IT and OT and being able to prove, with testing, that nothing crosses it,” she said.

She said the fact that treatment kept running was “what segmentation looks like when it holds,” but stressed that this does not confirm the boundary would survive a more determined attack.

Both experts pointed to chronic underinvestment as a structural weakness across South African public utilities.

Collard said cybersecurity spending routinely loses out to competing priorities such as pipe replacement and load shedding mitigation, because the risk involved “is invisible until it isn’t.”

She said governance was the cheapest problem to fix, arguing that cyber risk should sit on utility boards alongside water quality and infrastructure failure.

“If cyber isn’t on the board’s risk register next to water quality and infrastructure failure, it will never get the attention or the funding,” she said.

Meanwhile, Majola raised a related concern about the skills required to defend both IT and OT environments.

He said public entities cannot compete with private sector salaries for specialists, and argued that partnerships with outside digital forensics firms can help close the gap.

“These entities provide the military-grade incident response, continuous threat hunting, and prosecution-ready evidence preservation necessary to protect critical infrastructure,” he said.

On regulation, both experts agreed that South Africa lacks a law compelling utilities to disclose operational incidents that do not involve personal data.

Collard said oversight of the sector is fragmented across bodies with little enforcement power, and pointed to the European Union’s NIS2 directive, which requires reporting within 24 hours, as a possible model.

Majola noted that mandatory reporting provisions under the Cybercrimes Act remain suspended for general utilities, leaving obligations inconsistent across the sector.

What experts say should happen next

Collard urged utilities to identify and immediately close any internet-exposed control systems.

She cited this year’s US water attacks as evidence that initial access is often gained through poorly secured equipment accessible via the public internet.

She also called for regular rehearsal of manual plant operations.

“Get your control systems off the public internet, prove you can run without them, and make sure your people know what an attack looks like before it arrives”.

Majola called for stricter audits of IT-OT segmentation and the use of immutable, offline backups for critical data and blueprints.

He said such measures, combined with specialist forensic support, would allow utilities “to rebuild encrypted servers swiftly, eliminating the need to negotiate with criminal syndicates.”

Read full story at source

Former Trump Cabinet official had 'inappropriately close' relationship with bodyguard, IG finds

· Fox News

Former Labor Secretary Lori Chavez-DeRemer allegedly had an inappropriate relationship with her bodyguard and created a hostile work environment for her subordinates, according to a Thursday report from the Department of Labor's (DOL's) Office of the Inspector General (OIG).

The report cites one incident in which Chavez-DeRemer allegedly ordered a member of her security detail to throw cash at a stripper.

Visit newsbetting.club for more information.

Chavez-DeRemer, who resigned her position in April, had been under investigation after the OIG received an anonymous complaint in January. That complaint alleged Chavez-DeRemer's inappropriate relationship with the assistant special agent-in-charge (ASAIC) of her department's Division of Protective Operations (DPO), who the report did not name.

TRUMP TAPS ACTING LABOR SECRETARY KEITH SONDERLING FOR PERMANENT ROLE PENDING SENATE CONFIRMATION

The complaint also alleged that Chavez-DeRemer, her chief of staff, Jihun Han, and deputy chief of staff, Rebecca Wright, created a hostile work environment and regularly drank alcohol on DOL property and during work hours.

The OIG interviewed 38 witnesses who described the DOL work environment as "toxic, intimidating and humiliating." The witnesses reported that Chavez-DeRemer, Han and Wright "openly discussed employee performance matters in the presence of other staff, including details of performance-related meetings and whether those employees had cried during the meetings."

HIGH-RANKING DHS OFFICIAL SIDELINED OVER ALLEGATIONS OF 'SUGAR DADDY' RELATIONSHIP, LUXE GIFTS AND DRUG USE

Witnesses also told the OIG that Chavez-DeRemer's alleged relationship with the ASAIC also contributed to the hostile work environment.

During an April trip to Oregon, the ASAIC complied with Chavez-DeRemer's request to make an unplanned, off-the-record stop at "an establishment that was determined upon entry to feature partially nude dancers," according to the report.

The ASAIC assigned Chavez-DeRemer's driver to enter the establishment with her, and, according to the report, she handed the driver a stack of cash and instructed him to give it to one of the dancers. When the driver refused, the ASAIC instructed him to comply.

"Chavez-DeRemer then took additional money from her purse and asked the agent to drop the bills one by one onto the partially nude woman. The agent again hesitated and sought intervention from ASAIC 1, who told him to follow Chavez-DeRemer's instructions," according to the report.

The complaint and subsequent investigation also determined that the ASAIC's alleged inappropriate relationship with the former labor secretary, who is married, affected his job performance.

"ASAIC 1 allegedly focused on his interactions with Chavez-DeRemer, monitored her interactions with other agents, and reduced the presence of other DPO personnel to create opportunities to be alone with her, resulting in reduced protective coverage for the Secretary," the report read.

COURT FILINGS REVEAL KYRSTEN SINEMA HAD SEX MULTIPLE TIMES WITH MARRIED BODYGUARD WHILE SERVING AS SENATOR

The pair reportedly grew immediately close upon Chavez-DeRemer's arrival at the department in March 2025, communicating often through the encrypted messaging app Signal in off-duty hours and about non-operational subjects.

Another witness described observing Chavez-DeRemer massaging the ASAIC's shoulders in a car after he had finished a driving shift. When she asked if he was tired, he allegedly responded that he was "solid as a rock," and the pair both laughed.

"The witness interpreted the comment as sexual innuendo," the report read.

MARRIED FEDERAL JUDGE REPEATEDLY HAD COURTHOUSE SEX WITH LAW ENFORCEMENT OFFICER, COMPLAINT ALLEGES

Other witnesses described the pair walking arm in arm after leaving an event at Secretary of Agriculture Brooke Rollins' home. After opening the investigation, the OIG surveilled Chavez-Deremer's Washington, D.C., home and found the ASAIC entering her residence through a back door on repeated occasions.

FEDERAL JUDGE WHO HAD SEX IN CHAMBERS APOLOGIZES TO FORMER CLERK AS IMPEACHMENT PUSH RAMPS UP

After reports that the ASAIC was breaking chain-of-command protocol by attending meetings with Chavez-DeRemer's chief of staff and deputy chief of staff without his Special Agent in Charge's (SAIC) knowledge, the SAIC recommended he take a leave of absence. However, the SAIC did not escalate beyond this recommendation for fear she herself would be terminated.

"ASAIC 1 declined the suggestion to take leave and agreed that the SAIC taking action to limit his travel with Chavez-DeRemer could result in the SAIC’s removal," the report read.

TWO TAMPA POLICE OFFICERS RESIGN AFTER INVESTIGATION INTO ALLEGATIONS THEY SLEPT WITH A 911 DISPATCHER ON DUTY

When the SAIC told ASAIC in a text message that she would reassign him to another team he replied, "lol. Don't do that."

The ASAIC was put on paid administrative leave in January and then on unpaid investigative leave in February. He resigned in March, according to the report.

Fox News Digital contacted the Department of Labor, the department's OIG and the White House for additional comment.

Read full story at source

Rooney and Kate Mara Are Brilliant in Werner Herzog's Fractured Fairytale Bucking Fastard

· Time

Rooney Mara and Kate Mara as Joan and Jean Holbrooke —Courtesy of Gateway to Orkney LLC

Almost nothing in Werner Herzog’s fractured fairytale Bucking Fastards, playing in competition here at the Venice Film Festival, makes literal sense. But it all makes a kind of sideways sense, especially if, before watching, you can will yourself into a Herzogian brainspace, a place where possibly nonexistent elephants roam the Earth, where ancient cave drawings bear witness to the enduring creativity and wonder of humankind, where mad dreamers insist it’s possible to haul a multi-ton ship over a mountain. In that context, two inseparable sisters who speak only in unison, who are crazily lovesick over the man who has spurned them, and who believe they can dig a literal tunnel into a land of freedom, acceptance, and love: in a world where our deepest desires are so seldom met, how nuts does that really sound?

Visit bettingx.club for more information.

Real-life sisters Rooney Mara and Kate Mara play Joan and Jean Holbrooke, sisters living in Ireland—they are not, they adamantly insist, twins—who share every emotion, every thought, every waking moment as if they were a single entity. They dress exactly alike, in droopy trenchcoats and modest granny-style skirts; they both wear their long, silky hair parted neatly in the middle and tied partially back, like identical waterfalls. They don’t finish each other’s sentences; instead, they form their thoughts and words in unison and speak as one. It’s an eerie effect the first time you hear it. Even more unsettling, it comes to sound completely normal as the movie wears on.

Joan and Jean have fallen for a single man, their handsome rapscallion neighbor Gareth Mulroney (a saucy, salacious Orlando Bloom). It’s love at first sight—or is that sights?—when he bursts into their local church, a tankard of beer in hand, stirring up nothing but trouble. Afterward, they breathlessly wait for him to emerge through the church doors. Their eyes gleaming like double constellations, they proposition him: “I’d love to show you my inner cowgirl!” they tell him, the words tumbling out more like a song than a sentence. He’s charmed, intrigued; he’s horny. The trio land in bed, with Gareth in the middle flanked by his semi-nude cutie cowgirls, who ooh and ahh over him adoringly. They’re Goldilocks and he’s their just-right. This is how a sex scene, as imagined by Herzog, plays out.

But their bliss is short-lived. That meet-cute and its aftermath are relayed in flashback as the sisters huddle together in a courtroom, essentially defending themselves against charges of stalking. Gareth, after dallying with Joan and Jean for a time, has thrown them over and taken a wife. They can’t believe it—in their futile rage, they set the interior of his car on fire. (Their procurement of the gasoline they use to do so is a cracked mini-adventure by itself.) They also set the postbox outside his house aflame. Before the bewigged judge, Gareth’s lawyer tries to argue that the relationship was purely sexual. Joan and Jean justify their actions plaintively. “It was love!” they cry in unison, and later, “I am never going to stop loving him!”

Joan and Jean, forever in sync —Courtesy of Courtesy of Gateway to Orkney LLC

But there’s no hope. Their linked hearts are broken, and the court case has brought them both fame and embarrassment. A kind villager (John Kavanagh) takes pity on them, knowing that the best thing for them is to get away. He offers them the use of a flat he doesn’t need, located in another town. He urges them not to open the door to strangers, people who want only to take advantage of them. From there, Bucking Fastard becomes a set of wriggly vignettes more than a linear story. There’s a sleazy neighbor (Malcolm Adams) who attempts to take, and post on the Internet, pictures of them undressing. (They put their heads together and cook up a giggly-devious plan to outwit him.) A kind social worker, played by Domhnall Gleeson, tries to show them how to collaborate in the task of opening a tin of sardines. But soon even their cozy flat comes to feel like a prison: they strike out on an adventure, going to live with an aunt who loves them (Marion O’Dwyer) and who encourages them to explore a mysterious cave near her country property, one whose twists and turns ignite their two-for-one imaginations. A fox named Cupid, with a perpetually alarmed-looking face, becomes their mascot. Through it all, they continue to mourn their lost love. But perhaps they can find a new one?

What does any of this mean? Though the story was inspired by real-life twins from York, England, Freda and Greta Chaplin—who spoke in unison and, like Jean and Joan, did everything together—the meandering storyline is pure, sweet, gaga Herzog. The picture’s most radiant sequences take place in the girls' beloved cave, where they toil for years to dig their way, admittedly nonsensically, to a better life. Herzog and his frequent cinematographer Peter Zeitlinger film the two of them, within a halo of light as they dutifully chip through a rocky passageway—their twin images are as luminous as a delicately carved shell cameo.

The Mara sisters are brilliant here, their eyes as hungry and haunted as those of an orphan in a Keane painting. You laugh with them, not at them, when they take revenge on that peeping tom. But there’s also something deeply touching about their refusal to give up on love. There’s a metaphorical idea shimmering beneath the surface of Bucking Fastard: it’s as if, through this strange and somewhat simple story, Herzog were trying to explore the things women want but don’t dare demand. Here, those longings are voiced in stereo. And yes, men can sometimes drive you crazy. What can you do?

The ending of Bucking Fastard might be considered a flaw; it’s hard to know exactly what has happened, or what it means. But then, an ambiguous ending is one we’re free to write ourselves. How can you not want the best for these dreamy, heartbroken girls, who at one point race through their cave in matching gauzy white gowns, like freedom-loving butterflies? You’ll want to believe that their hearts have at last found a home—a cave not of forgotten dreams, but of remembered ones, made sweeter with every recounting.

Read full story at source