Thousands of Rockwell PLCs Exposed Online Amid Water-Utility Attacks

Forescout counted 4,407 exposed Rockwell/Allen‑Bradley PLCs worldwide (2,844 in the U.S.) as of Aug. 3, with 22 internet-facing in cities affected by recent water-utility cyberattacks. Attackers could disrupt operations by changing IPs or passwords on already-accessible controllers, even without exploiting a vulnerability; 19 of the 22 exposed units ran firmware susceptible to CVE-2017-16740. Many exposed devices are on large mobile carrier networks (about 70% of U.S. exposed controllers). Authorities advise removing public Internet exposure, enforcing strong authentication, and using VPNs/private networks. A separate recovery advisory exists for resetting affected MicroLogix 1400/1100 PLCs to default and restoring known-good projects, but it requires offline backups. No agency has publicly attributed the campaign yet, and researchers caution that similar configurations could enable broader compromises.
- Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities The Hacker News
- NJ water utilities hit by cyberattacks with suspected link to Iran 6abc Philadelphia
- America's water systems are getting hacked amid security gaps: "No one guarding these systems" CBS News
- Hackers just broke into America’s tap water. How scared should you be? vox.com
- New Jersey water systems targeted in cyberattack affecting 7 states nbcphiladelphia.com
Reading Insights
0
6
2 min
vs 3 min read
78%
544 → 121 words
Want the full story? Read the original article
Read on The Hacker News