Support Forums Reveal Soft Underbelly of Critical Infrastructure
ID: d444dcd6-efb6-5c8a-bafd-0b6e4f8048b7
STIX ID: report--d444dcd6-efb6-5c8a-bafd-0b6e4f8048b7
Feed Name: Security Ledger
This article describes research showing that forum data dumps and diagnostics reveal malware-infected laptops and systems used to manage SCADA/ICS devices, notes internet-exposed ICS instances discoverable via search engines like Shodan/ERIPP, lists specific ICS software observed (e.g., GE EnerVista, SEL AcSELerator, Siemens Digsi), and warns that infected technician endpoints and serial connections could enable manipulation of protection relays or compromise of critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
