Looking for a security contact at American Water

Pretty rough bug. Let me know if you have any contacts there!

1 Like

Without going into detail, when you say “pretty rough” are you talking about exploitability, triviality, or impact?

Given we’re talking about water here (i.e. designated Critical Infrastructure in most countries) any safety criticality caused by what you’re talking about should probably be directed to the local CERT, along with a nudge to some of the folks who are wired into this type of thing in the group.

Also, which country are you referring to? I’m assuming the USA, but it’s good to confirm.

USA and I dmd you on slack

2 Likes

@caseyjohnellis was able to get me a contact and I’m working on disclosure. Thanks for the contact and for this fantastic effort with disclose.io

1 Like