9 hours ago
- CISA warned on July 30, 2026 that threat actors increasingly target internet-exposed PLCs in water and wastewater systems, locking out operators by changing passwords and IP addresses.
- CISA named Rockwell Automation/Allen-Bradley, Siemens, and Schneider Electric as affected vendors, and flagged cellular modems as a common blind spot in attack-surface scans.
- Censys found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts (71% in the US), 4,117 Siemens SIMATIC S7-1200 hosts (86% in southern/central Europe), and 2,072 Schneider Electric hosts (55.5% in Turkey and Australia).
- CISA recommends disconnecting PLCs from the internet, enabling password protection, changing default passwords, and using allowlists for remote access.