Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Over 4,400 Rockwell Controllers Vulnerable Online

Over 4,400 Rockwell Controllers Vulnerable Online

Posted on August 6, 2026 By CWS

Recent research by Forescout has revealed that 22 Rockwell Automation programmable logic controllers (PLCs) are exposed online in cities that have recently experienced cyberattacks on water utilities. A total of 19 of these controllers are linked via the same mobile carrier network, raising security concerns.

Widespread Vulnerability of Rockwell PLCs

Forescout’s scan on August 3 identified 4,407 Rockwell controllers exposed globally, with 2,844 located in the United States. While these devices are exposed, there is no confirmation of any being compromised. The focus remains on exposed controllers rather than specific water utilities or confirmed victims.

The identified vulnerabilities allow attackers to manipulate these controllers without exploiting specific vulnerabilities. Changes to IP addresses and password settings can disrupt operator control, leading to potential loss of visibility and control over connected systems. However, the exact methods attackers used to identify and target these controllers remain unclear.

Impact on Water Utilities and Suggested Measures

Since July 27, several water utilities across at least seven states have reported incidents, prompting warnings from the FBI and EPA. Conflicting reports from The Hacker News and Forescout suggest the attacks may have affected up to 12 states. Despite this, no official attribution has been made regarding the source of these cyberattacks.

To mitigate risks, experts suggest removing controllers from public internet access. Exposing EtherNet/IP on port 44818 can create an unauthenticated access route, potentially allowing attackers to identify and manipulate controllers. Strong authentication and isolated remote access are recommended by the FBI and EPA to bolster security.

Statistics and Device Vulnerabilities

A snapshot from Censys on July 30 identified 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with major mobile carriers accounting for a significant portion of these connections. The different data collection methods between Censys and Forescout make direct comparisons challenging. Historical data shows a significant decline from March 2020 figures, with a June 2026 low of 4,169.

MicroLogix 1400 devices represent a significant portion of the exposed controllers, with 19 of the 22 controllers in affected cities running firmware vulnerable to CVE-2017-16740. Although Rockwell has addressed this buffer overflow flaw in newer firmware versions, public exposure of PLCs remains a critical concern. Recovery paths exist for locked devices, but they rely on having a current offline logic copy.

As these vulnerabilities continue to expose critical infrastructure to potential cyber threats, it is imperative for organizations to enhance their security measures and prevent unauthorized access.

The Hacker News Tags:Cyberattack, Cybersecurity, EPA, FBI, Forescout, Modbus TCP, network security, Rockwell PLC, Vulnerability, water utilities

Post navigation

Previous Post: Linux Kernel Bridge Vulnerability Exposes Security Risks
Next Post: AI Browser Vulnerabilities: Risks of Claude and ChatGPT Atlas

Related Posts

VMware Security Flaws: Auth Bypass and Code Execution Risks VMware Security Flaws: Auth Bypass and Code Execution Risks The Hacker News
Amazon Q Developer Flaw Exposes Cloud Credentials Amazon Q Developer Flaw Exposes Cloud Credentials The Hacker News
3 SOC Challenges You Need to Solve Before 2026 3 SOC Challenges You Need to Solve Before 2026 The Hacker News
DevMan RaaS Centralizes Cyber Operations and Affiliations DevMan RaaS Centralizes Cyber Operations and Affiliations The Hacker News
Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control The Hacker News
Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Jenkins Flaw Enables Malicious Code Execution
  • AI Browser Vulnerabilities: Risks of Claude and ChatGPT Atlas
  • Over 4,400 Rockwell Controllers Vulnerable Online
  • Linux Kernel Bridge Vulnerability Exposes Security Risks
  • Future Cyber Risks: Insights from Edna Conway

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Jenkins Flaw Enables Malicious Code Execution
  • AI Browser Vulnerabilities: Risks of Claude and ChatGPT Atlas
  • Over 4,400 Rockwell Controllers Vulnerable Online
  • Linux Kernel Bridge Vulnerability Exposes Security Risks
  • Future Cyber Risks: Insights from Edna Conway

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark