Censys Warns 5,219 Rockwell/Allen-Bradley PLCs Are Exposed Amid Iranian APT Activity
ID: 9f3bf475-d027-50c3-993e-868f8275bfc7
STIX ID: report--9f3bf475-d027-50c3-993e-868f8275bfc7
Feed Name: cybersecurityNews.com
**Executive Summary:** U.S. government agencies warn that Iranian-affiliated APT actors (IRGC-CEC) are actively targeting internet‑exposed Rockwell Automation/Allen‑Bradley PLCs—using legitimate Studio 5000 engineering software to access, read/modify projects, and manipulate HMI/SCADA displays; Censys enumerations found 5,219 exposed hosts (3,891 in the U.S.), widespread co‑exposed services (VNC, Telnet, Modbus), and related IOCs, with recommended mitigations including removing PLCs from direct internet exposure, disabling remote services, enforcing MFA, and auditing firmware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
