Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
AI Generated Image

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

The Hacker News nation

Key Points:

  • Forescout identified 22 internet-facing Rockwell Automation PLCs in cities affected by recent cyberattacks on US water utilities, with 19 using the same mobile carrier network; globally, 4,407 exposed Rockwell controllers were found, including 2,844 in the US, though no confirmed compromises were reported.
  • Attackers reportedly gained control by changing IP addresses and setting passwords on already reachable controllers without exploiting vulnerabilities, causing operators to lose visibility and control; the initial access methods remain unclear.
  • Water utilities in at least seven states have reported incidents since late July, with FBI and EPA advisories recommending strong authentication, updates, logging for cellular modems, and isolating remote access via private APNs or VPNs.
  • Over 70% of exposed US-based controllers operate on large mobile carrier networks, with many devices vulnerable to a known Modbus TCP buffer overflow (CVE-2017-16740) affecting MicroLogix 1400 Series firmware versions 21.002 and earlier; however, firmware updates alone do not justify public internet exposure.
  • Recovery guidance involves resetting affected controllers to factory defaults and restoring offline project files, but the FBI warns that attackers may exploit similar network setups to repeat compromises across multiple sites sharing vulnerable configurations.

Trending Business

Trending Technology

Trending Health