logo

Exposed and vulnerable: Recent attacks highlight critical need to protect internet-exposed OT devices

ID: 593fd1cd-bb6b-55a3-96bc-1c6f06a64d89

STIX ID: report--593fd1cd-bb6b-55a3-96bc-1c6f06a64d89

Feed Name: Microsoft Security

Threat Score
85/100

Date Published: 2024-05-30

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft reports an increase in attacks since late 2023 against internet-exposed, poorly secured OT devices—including a November 2023 incident at the Aliquippa water plant attributed to IRGC-affiliated "CyberAv3ngers"—where exposed Unitronics PLC/HMI systems with default or weak credentials and open control ports were scanned, accessed, defaced, and used to disrupt a pressure regulation pump. The report details the common attacker methodology, cites CVE-2023-6448 for default credentials, documents wider campaign activity, and provides mitigation and detection recommendations such as eliminating direct internet exposure, patching, segmentation, and using Defender for IoT detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.