Thousands Of Rockwell PLCs Exposed Online As Iranian APT Threats Intensify
ID: 82c7b887-9f10-535b-9d42-0ffcba3d4b86
STIX ID: report--82c7b887-9f10-535b-9d42-0ffcba3d4b86
Feed Name: Cyber Press
U.S. agencies warn that Iranian-linked hackers are actively targeting Rockwell Automation PLCs; Censys found >5,200 internet-exposed devices (mostly in the U.S.), many using cellular modems and running outdated MicroLogix/CompactLogix/Micro850 firmware. Researchers traced attacker infrastructure to a single Windows engineering workstation (identified by an RDP certificate) plus additional burner servers, and observed exposed insecure remote services (VNC, Telnet). Immediate mitigation recommended: remove PLCs from direct internet exposure, use secure gateways and MFA for remote access, set physical key switches to RUN, block known/more fully enumerated attacker IPs, and hunt for suspicious industrial-port connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
