logo

The Global Surge in Modbus/TCP Probes Targeting Our Physical World

ID: 9695667e-4f04-5e22-9445-40c8f7c76702

STIX ID: report--9695667e-4f04-5e22-9445-40c8f7c76702

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Ddos

...
...

Between September and November 2025, Cato Networks observed a widespread campaign probing and interacting with internet-facing PLCs via Modbus/TCP across 70 countries and over 14,000 targets; actors used a scripted two-step sequence (fingerprinting via function 0x2B/0x0E and targeted register reads) and conducted significant read and write activity—one source issued 3,240 write requests—demonstrating a realistic risk of remote manipulation of physical processes and prompting recommendations to isolate Modbus from the public internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.