logo

Turning Off the (Information) Flow: Working With the EPA to Secure Hundreds of Exposed Water HMIs

ID: f1cc101c-73d5-50dc-b2d0-d671b563b4eb

STIX ID: report--f1cc101c-73d5-50dc-b2d0-d671b563b4eb

Feed Name: Censys Blog

Threat Score
65/100

Date Published: 2025-06-05

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

In October 2024 Censys discovered almost 400 web-accessible browser-based HMIs for U.S. water treatment facilities—identified via TLS certificate analysis and screenshot extraction—including 40 fully unauthenticated systems and 264 read-only instances; Censys reported the findings to the EPA and the vendor, prompting coordinated remediation that reduced exposed systems to under 6% by May 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.