logo

Support Forums Reveal Soft Underbelly of Critical Infrastructure

ID: d444dcd6-efb6-5c8a-bafd-0b6e4f8048b7

STIX ID: report--d444dcd6-efb6-5c8a-bafd-0b6e4f8048b7

Feed Name: Security Ledger

Threat Score
50/100

Date Published: 2012-11-11

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

This article describes research showing that forum data dumps and diagnostics reveal malware-infected laptops and systems used to manage SCADA/ICS devices, notes internet-exposed ICS instances discoverable via search engines like Shodan/ERIPP, lists specific ICS software observed (e.g., GE EnerVista, SEL AcSELerator, Siemens Digsi), and warns that infected technician endpoints and serial connections could enable manipulation of protection relays or compromise of critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.