discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, …

By Swati Khandelwal·Aug 6·thehackernews.com·2 min read

Intelligence analysis by Llama

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Image: thehackernews.com

Forescout's analysis found that attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment. The FBI and EPA recommend strong authentication, updates and logging for cellular modems, with remote access isolated through a private APN, VPN or similar architecture.

Why it matters

The exposed Rockwell PLCs pose a significant risk to critical infrastructure, including water utilities. Defenders can act now by taking the controllers off the public internet.

Imagine you're in charge of a big water treatment plant. You have special computers called PLCs that help control the water flow and make sure everything runs smoothly. But what if someone found a way to hack into those computers and change their settings? That's what happened with some Rockwell PLCs. They were left exposed online, making it easy for hackers to find and exploit them. This is a big deal because it could affect the water supply and other critical infrastructure.

Analysis

Exposed Rockwell PLCs: A Growing Concern for Critical Infrastructure

Forescout's analysis has revealed a significant number of Rockwell Automation programmable logic controllers (PLCs) exposed online, with 22 found in cities hit by recent cyberattacks on US water utilities. This is a growing concern for critical infrastructure, as these PLCs play a crucial role in controlling and monitoring industrial processes. The fact that 19 of these exposed PLCs used the same mobile carrier network raises questions about the potential for coordinated attacks.

The Role of Mobile Carrier Networks

Forescout's analysis found that more than 70% of the US-based exposed controllers were on large mobile carrier networks. This highlights the importance of securing these networks to prevent attackers from using them as a vector for their attacks. The FBI and EPA recommend strong authentication, updates and logging for cellular modems, with remote access isolated through a private APN, VPN or similar architecture.

Firmware Updates and Security

Forescout's analysis also found that 19 of the 22 controllers in affected cities ran firmware susceptible to CVE-2017-16740 (Rockwell CVSS score: 8.6). This vulnerability is a Modbus TCP buffer overflow affecting MicroLogix 1400 Series B and C running firmware 21.002 and earlier. Rockwell fixed this issue in revision 21.003. However, firmware updates address specific bugs but do not make direct public exposure of PLCs acceptable.

The Importance of Securing PLCs

The exposed Rockwell PLCs pose a significant risk to critical infrastructure, including water utilities. Defenders can act now by taking the controllers off the public internet. This requires a comprehensive approach to security, including strong authentication, updates and logging for cellular modems, with remote access isolated through a private APN, VPN or similar architecture. Additionally, operators should ensure that their PLCs are running the latest firmware and that they have a robust security plan in place to prevent and respond to potential attacks.

Key points

  • Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities.
  • Nineteen of the exposed PLCs used the same mobile carrier network.
  • Forescout's analysis found that attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment.
  • The FBI and EPA recommend strong authentication, updates and logging for cellular modems, with remote access isolated through a private APN, VPN or similar architecture.
The Upside

If the exposed Rockwell PLCs are taken offline and secured, the risk of a successful cyberattack on critical infrastructure decreases. Additionally, the implementation of strong authentication, updates and logging for cellular modems, with remote access isolated through a private APN, VPN or similar architecture, can help prevent similar attacks in the future.

The Downside

If the exposed Rockwell PLCs are not secured, hackers could potentially exploit them to disrupt critical infrastructure, including water utilities. This could lead to significant consequences, including loss of life and economic disruption.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscyberattackfirmware-securityindustrial-securityinternet-exposuremobile-network-securitynetwork-securityoperational-technologyvulnerabilitywater-security

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Aug 6, 2026

Source

thehackernews.com

Share

Topics

cyberattackfirmware-securityindustrial-securityinternet-exposuremobile-network-securitynetwork-securityoperational-technologyvulnerabilitywater-security

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.