Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
ID: 7f14484e-4d22-5e45-8539-fb85576c39f5
STIX ID: report--7f14484e-4d22-5e45-8539-fb85576c39f5
Feed Name: CyberScoop
Forescout’s Vedere Labs scanned the internet and found over 4,000 Rockwell/Allen‑Bradley controllers exposed online—including 22 in cities recently impacted by confirmed attacks on U.S. water/wastewater utilities—while the FBI and EPA have issued advisories describing incidents across at least 12 states. Researchers identified many MicroLogix 1400 devices potentially vulnerable to CVE-2017-16740, observed stale/expired infrastructure that increases attack surface, and concluded the activity aligns with large-scale opportunistic scanning and exploitation of internet-exposed industrial controllers rather than a bespoke APT operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
