Censys finds 5,219 devices exposed to attacks by Iranian APTs, majority in U.S.
ID: 01e0564d-a183-51ae-92e4-9cb25960f7fe
STIX ID: report--01e0564d-a183-51ae-92e4-9cb25960f7fe
Feed Name: Security Affairs
Threat Score
Censys and U.S. agencies warn that Iran-linked APTs (e.g., CyberAv3ngers) are actively exploiting internet-exposed Rockwell Automation PLCs—Censys found 5,219 EtherNet/IP-responsive devices (74.6% in the U.S.), many on cellular links and running outdated firmware—attackers can fingerprint, access, and manipulate project files and HMI/SCADA outputs, risking disruption to critical infrastructure; the report includes technical IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
