惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
H
Hackread – Cybersecurity News, Data Breaches, AI and More
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
有赞技术团队
有赞技术团队
大猫的无限游戏
大猫的无限游戏
Security Latest
Security Latest
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
博客园 - Franky
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Simon Willison's Weblog
Simon Willison's Weblog
S
Securelist
T
Threatpost
Last Week in AI
Last Week in AI
P
Privacy International News Feed
S
SegmentFault 最新的问题
aimingoo的专栏
aimingoo的专栏
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
MyScale Blog
MyScale Blog
P
Palo Alto Networks Blog
Cisco Talos Blog
Cisco Talos Blog
T
Tailwind CSS Blog
Blog — PlanetScale
Blog — PlanetScale
G
GRAHAM CLULEY
GbyAI
GbyAI
G
Google Developers Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
B
Blog RSS Feed
A
About on SuperTechFans
H
Help Net Security
T
Threat Research - Cisco Blogs
C
Check Point Blog
S
Schneier on Security
Google DeepMind News
Google DeepMind News
T
The Exploit Database - CXSecurity.com
博客园 - 叶小钗
Scott Helme
Scott Helme
博客园 - 司徒正美
美团技术团队
W
WeLiveSecurity
O
OpenAI News
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
AWS News Blog
AWS News Blog
I
InfoQ

Comparitech

How to watch McGregor vs Holloway 2 (UFC 329) from anywhere Medical billing firm MCBS warns 300,000+ patients of data breach - Comparitech Ransomware Roundup: H1 2026 stats on attacks, ransoms, and active gangs - Comparitech Colorado Health Network warns 68,000+ people of data breach that leaked SSNs, credit cards, and medical records - Comparitech Middletown, OH warns 123,000+ people of data breach that leaked SSNs, financial and medical info - Comparitech DeGoogling your life: What is it and how do you do it? How to opt out of Meta AI data collection - Comparitech Is CurseForge safe? Common risks and how to mod safely - Comparitech Cybercriminals say they hacked New South Wales Rural Fire Service - Comparitech Grandview School District warns 9,000+ people of data breach 21 months later - Comparitech Which industry & country has the worst email security? An analysis of 5,800+ domains for SPF, DMARC, DKIM & MTA-STS protocols - Comparitech Kootenai County, ID warns residents of government data breach that leaked personal info - Comparitech What is Kik? Is it safe for kids? - Comparitech Cybercriminals say they hacked Reynella East College - Comparitech Are UK council websites adhering to government security guidelines? - Comparitech Bellflower Unified Schools warns students of data breach that leaked SSNs - Comparitech What are location services and how do they work? - Comparitech How to bypass Xbox age verification - Comparitech What is a Minecraft dedicated IP? Do you need one? The best Discord alternatives in 2026 - Comparitech How to watch UFC Freedom 250: Stream UFC White House online Taos Mountain Casino warns of data breach that leaked SSNs Cybercriminals give Delano Public Schools two weeks to pay ransom How to fix ‘Your connection is not private’ in Chrome Plaza Home Mortgage warns 138,000 people of data breach that leaked SSNs How to watch the NBA Finals live online from anywhere Cybercriminals take credit for Singing River Health System data breach How Spammers Are Hiding Behind Google and the New York Times Ransomware roundup: May 2026 Iowa hospital warns 24,000+ people of data breach that leaked SSNs, medical and financial info 80K+ people notified of data breach at Louisiana university that leaked SSNs & bank info Finance firm IMA warns 525,000+ people of data breach Auto lender IAC warns 79,000+ people of data breach that leaked SSNs Sandstone, MN says SSNs and financial info compromised in ransomware data breach Las mejores herramientas de gestión de Active Directory Die besten Active-Directory-Management-Tools I Migliori Strumenti di Gestione di Active Directory Las mejores herramientas de gestión de logs Die besten Log-Management-Tools I migliori strumenti di log management Watching You, Funded by You: Number of CCTV Cameras by UK Council & Police Force Las mejores herramientas SIEM para alertas de seguridad automatizadas Die besten SIEM-Tools für automatisierte Sicherheitswarnungen I migliori strumenti SIEM per gli avvisi di sicurezza automatizzati Software maker warns 200,000 Frost Bank customers in Texas of data breach Oregon employment firm notifies 142,000+ people of two data breaches claimed by ransomware gangs Cybercriminals say they hacked Harrison County, WV commission, demand ransom Cybercriminals say they breached AdvancedHealth, Tennessee clinic confirms Fluke Corp notifies 18,000+ people of data breach that leaked SSNs What is Token-Based Authentication? Tokens Explained Western Orthopaedics warns 113,000+ people of data breach that leaked SSNs, credit cards, and medical info What is ARP? ARP protocol explained What is symmetric encryption? Crunchyroll VPN not working? Fix buffering, errors & region blocks American Lending Center notifies 123,000+ people of data breach that leaked SSNs How to watch Oleksandr Usyk vs Rico Verhoeven online Cybercriminals say they hacked CarePoint Health, stole data Ransomware gang claims attack and data theft from UK city school Horizon Media reports data breach of SSNs, cybercriminals take credit Claude VPNs (and how to use Claude safely) What is GhostPairing on WhatsApp? What is a prompt injection attack? Where do leaked passwords end up? A statistical analysis of the dark web’s credential pipeline Ransomware roundup: April 2026 Suffolk, VA warns 157,000+ people of data breach that leaked SSNs, finances How to watch UFC 328 (Chimaev vs Strickland) from anywhere Cybercriminals say they hacked Winona County, MN (again) Keeper vs 1Password: Which password manager is best in 2026? What is F-Droid? Is it safe? Proton VPN Secure Core: What is it, and should you use it? What is an agentic browser? Features and how to use them safely Sandhills Medical Foundation warns patients of data breach Cybercriminals say they hacked Massachusetts Development Finance Agency, its second breach in 2 years STELIA Aerospace confirms cyber attack on North American systems. $2.07 million ransom issued Debt collector Rodenburg Law Firm warns 81,307 people of data breach Healthcare ransomware roundup: Q1 2026 stats on attacks, ransoms, and data breaches How to block ads on Paramount Plus A complete guide to smart speaker privacy What is the Great Firewall of China Cybercriminals say they hacked Rusk County, WI What is a decentralized VPN? Do you need a dVPN? Southern Illinois Dermatology warns patients of data breach that leaked SSNs 92,000 people notified of data breach following cyber attack at Puerto Rican hospital Cybercriminals say they hacked Minidoka Memorial Hospital, demand ransom What is sensitive data? Types and how to protect yourself Inside RAMP: What a leaked database reveals about Russia’s ransomware marketplace What is a passphrase? Are they safer than passwords? Phoenix Art Museum warns of data breach that leaked SSNs Mozilla VPN vs NordVPN – VPN Comparison Guide Cookeville Regional Medical Center warns 338,000 people of data breach Antimalware vs Antivirus: What’s the difference? What is URL phishing? Examples and how to stay safe How to use a VPN in Bhutan (and the best options) Cybercriminals give Brockton, MA hospital one week to pay ransom after hack Is Truth Social safe? Everything you need to know What is cyberwarfare? Medical implant maker TriMed warns 80,000+ people of data breach Ransomware roundup: Q1 2026 Heart South Cardiovascular Group warns 46,000+ people of data breach Cybercriminals say they hacked Community College of Beaver County
Critical Infrastructure at Risk: 179 ICS Devices Exposed Online
2026-04-06 · via Comparitech

Critical Infrastructure at Risk_ 179 ICS Devices Exposed Online

Malware affecting industrial control systems (ICS) has the potential to disrupt the key industries that underpin modern society. Variants such as Industroyer, Stuxnet, Havex, Triton, and BlackEnergy have demonstrated the ability to interfere with industrial processes, disrupt power supplies, and, in some cases, cause physical damage to critical infrastructure.

According to Cyble Research & Intelligence Labs’ most recent report, ICS vulnerability disclosures almost doubled between 2024 and 2025. This increase, says Digital Watch Observatory, is linked in part to “greater exploitation by threat actors” seeking to compromise energy, manufacturing, and utilities infrastructure.

Internet-exposed ICS devices are a primary target, particularly those running legacy protocols such as Modbus. Modbus enables the sensors and controllers used in power grids, factories, and other industrial systems to communicate with each other. The decades-old protocol lacks encryption and doesn’t require authentication. As such, devices running Modbus should be placed behind a firewall or VPN.

To assess the extent of this risk, we conducted a scan for internet-facing Modbus devices. We identified 179 suspected industrial control devices responding on port 502, the default port used by the Modbus protocol.

One ICS device we identified as being part of a national railway network. Railways use ICS devices to help with everything from train routing to signalling. The exposure of such devices could present a serious operational and safety risk.

Two other devices (one in Asia and one in Europe) formed part of their respective country’s national power grid infrastructure. In the energy supply sector, ICS devices can be used to monitor consumption and control electrical distribution.

Which country had the most exposed ICS devices?

The United States had the most (57) exposed industrial control devices, followed by Sweden (22) and Turkey (19).

Which ICS manufacturers had the most exposed devices?

The majority of devices (128) only exposed their firmware versions and/or internal IDs without including a vendor string. This is to be expected from custom controllers or embedded modules.

A total of 54 devices did advertise their manufacturer (though not always their model information). Schneider devices were most prevalent (22 instances), followed by Data Electronics (14 instances) and ABB Stotz-Kontakt (6 instances).

Exposed devices included:

  • Schneider TM221CE40T logic controller: used to automate industrial processes by monitoring inputs (like sensors) and controlling outputs (such as motors, relays, and actuators).
  • Fastwel CPM713 logic controller: manages distributed input/output modules across large-scale industrial networks.
  • eGauge Core EG4015 energy meter and data logger: measures electrical energy usage across multiple circuits and logs detailed data, while also acting as a built-in web server so users can view real-time and historical power data locally or remotely.
  • Schneider BMXP342020 processor module: used in industrial automation systems. It forms the “brain” of a control system that can read inputs, execute logic, and drive outputs to control equipment.
  • A.Eberle PQI-DA-SMART voltage and power logger: enables continuous monitoring and analysis of grid performance, helping detect disturbances early and maintain stable, reliable power in industrial systems and energy networks.

The danger of revealing the make and model of a device is that it allows attackers to find any associated register lists provided by the manufacturer. The register list maps the values found in each of the device’s holding registers to sensor readings. These readings can include temperature, pressure, voltage, current, flow; control states for switches, motors or pumps, target values for controllers; and error or status codes.

For example, using the register list for the PowerLogic EM4880, we were able to chart the energy consumption of a live installation.

PowerLogic EM4880 energy consumption of a live installation.

Even if a device isn’t obviously linked to a particular manufacturer, attackers may make an educated guess as to what its registers relate to, particularly if they monitor how they change over time.

Because Modbus doesn’t require authentication, an attacker could potentially write to, as well as read from, the holding registers. Even minor unauthorized changes could disrupt the system that depends on the device’s readings.

Where next?

Given that the global industrial automation and control systems (ICS) market is currently valued at USD 226.76 billion and is projected to grow to USD 504.38 billion by 2033, the number of connected industrial devices is rapidly increasing. This expansion presents a significant cybersecurity challenge: every newly networked device introduces potential attack surfaces that must be protected. Without proper safeguards such as firewalls, VPNs, network segmentation, and secure authentication, internet-exposed ICS devices make easy targets.

From an attacker’s perspective, devices running protocols like Modbus (as well as DNP3, or BACnet) are particularly vulnerable because they were designed for closed networks and often lack built-in authentication or encryption. These devices could be exploited by attackers with limited technical expertise if exposed directly to the internet. This is particularly concerning given some ICS devices’ critical role in economic activity and essential infrastructure.

Methodology

We used the Masscan tool to perform an internet-wide scan for anything listening on port 502, which is commonly used by the Modbus protocol. We received 311 responses in total.

To ensure we didn’t include any honeypots – decoy systems used by security researchers to attract attackers – we erred on the side of caution and dismissed any responses from emulation software and cloud-based devices. Where device holding registers were visible and interpretable, we dismissed any with wildly fluctuating readings that were unlikely to mirror real-world outputs. This left us with 179 responses with a high likelihood of coming from real ICS devices.

Researcher: Mantas Sasnauskas