Water ICS Exposures Highlight Vulnerabilities in Critical Infrastructure Security
ID: 4e960845-97b0-5e66-9123-fc2985394860
STIX ID: report--4e960845-97b0-5e66-9123-fc2985394860
Feed Name: Censys Blog
Date Published: 2024-02-08
Date Updated: 2026-04-27
Author: Brenda Mendoza; The Censys Research Team
Censys describes a confirmed compromise of a Unitronics PLC at a municipal water pumping station attributed to an IRGC‑affiliated group (CyberAv3ngers) and reports discovery of 149 internet‑exposed Unitronics devices in the U.S. with exposed PCOM, API endpoints, web admin panels using default "1111" passwords, and VNC (three instances without authentication); the report warns these exposures enable trivial access and potential disruption to critical infrastructure, notes many observed PCOM instances are likely honeypots, and recommends disconnecting vulnerable PLCs from the internet or protecting them with VPNs/firewalls and stronger authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
