logo

Thousands Of Rockwell PLCs Exposed Online As Iranian APT Threats Intensify

ID: 82c7b887-9f10-535b-9d42-0ffcba3d4b86

STIX ID: report--82c7b887-9f10-535b-9d42-0ffcba3d4b86

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-04-13

Date Updated: 2026-04-13

Author: Varshini

...
...

U.S. agencies warn that Iranian-linked hackers are actively targeting Rockwell Automation PLCs; Censys found >5,200 internet-exposed devices (mostly in the U.S.), many using cellular modems and running outdated MicroLogix/CompactLogix/Micro850 firmware. Researchers traced attacker infrastructure to a single Windows engineering workstation (identified by an RDP certificate) plus additional burner servers, and observed exposed insecure remote services (VNC, Telnet). Immediate mitigation recommended: remove PLCs from direct internet exposure, use secure gateways and MFA for remote access, set physical key switches to RUN, block known/more fully enumerated attacker IPs, and hunt for suspicious industrial-port connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.