logo

Water ICS Exposures Highlight Vulnerabilities in Critical Infrastructure Security

ID: 4e960845-97b0-5e66-9123-fc2985394860

STIX ID: report--4e960845-97b0-5e66-9123-fc2985394860

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2024-02-08

Date Updated: 2026-04-27

Author: Brenda Mendoza; The Censys Research Team

...
...

Censys describes a confirmed compromise of a Unitronics PLC at a municipal water pumping station attributed to an IRGC‑affiliated group (CyberAv3ngers) and reports discovery of 149 internet‑exposed Unitronics devices in the U.S. with exposed PCOM, API endpoints, web admin panels using default "1111" passwords, and VNC (three instances without authentication); the report warns these exposures enable trivial access and potential disruption to critical infrastructure, notes many observed PCOM instances are likely honeypots, and recommends disconnecting vulnerable PLCs from the internet or protecting them with VPNs/firewalls and stronger authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.