
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, and data engineering — plus mindset essays on confidence, routines, health, and sport psychology.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Sun, 09 Aug 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/plc/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/security/2026-08-09-the-ot-exposure-you-cannot-inventory.en</guid>
    <title>What Is Not in the Asset Inventory Never Gets Scanned — OT Exposure Management, From the Water Utility PLC Case</title>
    <link>https://www.youngju.dev/blog/security/2026-08-09-the-ot-exposure-you-cannot-inventory.en</link>
    <description>On 30 July 2026 CISA warned of a sharp rise in activity targeting PLCs in the water and wastewater sector and urged operators to remove internet-exposed OT immediately. The behavior the advisory observed was not compromise in the usual sense but changing passwords to lock operators out and changing IP addresses to cut the devices off, and the result was boil water notices and prolonged manual operation. Reading that advisory straight through, this post covers the cellular modem problem that a routine attack surface scan cannot catch, why the mitigations are in the order they are in, and the recovery precondition nobody prepares: a verified clean PLC image backup. Attribution claims and technical recommendations are handled separately.</description>
    <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>ot</category><category>ics</category><category>plc</category><category>cisa</category><category>critical-infrastructure</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/security/2026-08-09-the-ot-exposure-you-cannot-inventory.ja</guid>
    <title>資産台帳にないものはスキャンされない — 上水道PLC事件が教えるOT露出管理</title>
    <link>https://www.youngju.dev/blog/security/2026-08-09-the-ot-exposure-you-cannot-inventory.ja</link>
    <description>CISAが2026年7月30日、上下水道部門のPLCを狙う活動が大きく増えているとして、インターネットに露出したOTを直ちに切り離すよう勧告しました。勧告文が観察した行為は侵害というより、パスワードを変えて運用者を締め出し、IPアドレスを変えて機器を切り離すことであり、その結果が煮沸勧告と長期間の手動運転でした。この勧告文をそのまま読みながら、定期的な攻撃表面スキャンに掛からないセルラーモデムの問題、緩和策がなぜその順序なのか、そして誰も用意していない復旧の前提条件であるクリーンなPLCイメージのバックアップを整理します。帰属の主張と技術的勧告は分けて扱います。</description>
    <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>ot</category><category>ics</category><category>plc</category><category>cisa</category><category>critical-infrastructure</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/security/2026-08-09-the-ot-exposure-you-cannot-inventory</guid>
    <title>자산 목록에 없는 것은 스캔되지 않는다 — 상수도 PLC 사건이 알려 주는 OT 노출 관리</title>
    <link>https://www.youngju.dev/blog/security/2026-08-09-the-ot-exposure-you-cannot-inventory</link>
    <description>CISA가 2026년 7월 30일 상하수도 부문 PLC를 겨냥한 활동이 크게 늘었다며 인터넷에 노출된 OT를 즉시 분리하라고 권고했습니다. 권고문이 관찰한 행위는 침해가 아니라 비밀번호 변경으로 운영자를 잠그고 IP 주소를 바꿔 장비를 끊어 놓는 것이었고, 그 결과가 끓임 안내와 장기간의 수동 운전이었습니다. 이 권고문을 그대로 읽으면서, 정기 공격 표면 스캔에 잡히지 않는 셀룰러 모뎀 문제, 완화 조치가 왜 그 순서인지, 그리고 아무도 준비해 두지 않는 복구 전제 조건인 깨끗한 PLC 이미지 백업을 정리합니다. 귀속 주장과 기술 권고를 분리해서 다룹니다.</description>
    <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>ot</category><category>ics</category><category>plc</category><category>cisa</category><category>critical-infrastructure</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/security/2026-08-09-the-ot-exposure-you-cannot-inventory.zh</guid>
    <title>不在资产清单里的东西不会被扫描 —— 自来水 PLC 事件带来的 OT 暴露面管理</title>
    <link>https://www.youngju.dev/blog/security/2026-08-09-the-ot-exposure-you-cannot-inventory.zh</link>
    <description>CISA 于 2026 年 7 月 30 日发出警告，称针对供排水行业 PLC 的活动大幅增加，并建议立即把暴露在互联网上的 OT 断开。通告所观察到的行为并不是通常意义上的攻陷，而是改掉密码把运维人员锁在门外、改掉 IP 地址让设备失联，其结果是煮沸饮水通告和长时间的手动运行。本文照着这份通告逐条读下去，梳理常规攻击面扫描抓不到的蜂窝调制解调器问题、缓解措施为什么是那个顺序，以及那个没人预先准备的恢复前提条件 —— 一份经确认干净的 PLC 镜像备份。归因主张与技术建议分开处理。</description>
    <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>ot</category><category>ics</category><category>plc</category><category>cisa</category><category>critical-infrastructure</category>
  </item>

    </channel>
  </rss>
