ICS and Iran: Exposure of Previously Targeted Devices
ID: 46391576-655f-5198-9f0b-7588940b86ed
STIX ID: report--46391576-655f-5198-9f0b-7588940b86ed
Feed Name: Censys Blog
Executive Summary: The report examines Internet exposure trends from January to June 2025 for four ICS/building-automation systems (Unitronics Vision PLC/HMIs, Orpak SiteOmat, Red Lion devices, and Tridium Niagara), finding overall exposure increases of 4.5%–9.2% for most systems (Tridium having the largest absolute counts) while Orpak decreased. It highlights prior compromises or claimed attacks by Iranian-aligned actors (e.g., CyberAv3ngers) and known malware (IOCONTROL), emphasizes the continued prevalence of default credentials and consumer/mobile ISP hosting for ICS devices, and urges operators and manufacturers to remove Internet-facing interfaces and eliminate default passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
