Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Thousands of Rockwell PLCs Put Water Systems at Risk

Thousands of Rockwell PLCs Put Water Systems at Risk

Posted on August 6, 2026 By CWS

Recent cyber threats targeting U.S. water and wastewater facilities have highlighted the widespread exposure of industrial controllers accessible via the internet. A Forescout study has revealed that 4,407 Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) are openly reachable online, using port 44818, the EtherNet/IP protocol. A significant 65% of these devices are found in the United States, with Canada hosting 12% and Spain 3%.

Current Exposure and Historical Trends

The current number of exposed devices represents a decline of 47% from a previous high of 7,814 in March 2020, reaching a low of 4,169 by June 2026. Despite the reduction, the level of exposure continues to pose a serious risk to essential infrastructure, making them susceptible to cyber intrusions.

On July 28, a coordinated cyberattack affected more than 30 water systems throughout Minnesota. Although water quality remained unaffected, operational disruptions were reported in cities such as Plymouth, South St. Paul, Maple Plain, and Braham. Braham experienced control shutdowns due to malware, while Plymouth’s equipment issues stemmed from connections through cellular routers.

Scope of Cyber Threats and Affected Devices

By July 30, the FBI and EPA issued a joint warning about similar attacks across 12 states since July 27, including Michigan, South Dakota, and Georgia. The attackers specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, causing issues like pressure drops and potential flooding, which could lead to groundwater contamination in drinking supplies.

MicroLogix 1400 PLCs make up about 50% of these exposed devices, followed by CompactLogix 1769 at 22%, with MicroLogix 1100 and ControlLogix 5590 each at 8%. Notably, over 70% of the U.S.-based controllers are linked to large mobile networks via cellular routers, mirroring the access points mentioned in the advisory.

Recommendations for Mitigating Risks

Security experts recommend disconnecting PLCs from the internet, disabling unused services like SNMP, and enforcing strict allowlists for Modbus TCP and port 44818. Cellular gateways should transition to private carrier APNs or VPNs, with public administration disabled, and remote access should be secured with individual accounts and multi-factor authentication.

Organizations are advised to upgrade MicroLogix 1400 firmware and prioritize replacing the discontinued MicroLogix 1100 models. Secure remote access (SRA) gateways, which isolate user sessions from direct protocol access, can offer additional protection while facilitating necessary remote operations.

Ensuring robust cybersecurity measures is crucial for safeguarding water systems, and organizations must act swiftly to address existing vulnerabilities and protect these critical infrastructures from escalating cyber threats.

Cyber Security News Tags:critical infrastructure, cyber threats, Cyberattacks, Cybersecurity, Forescout research, industrial control systems, PLCs, Rockwell PLCs, security measures, water systems

Post navigation

Previous Post: New Linux Zapscape Vulnerability Threatens KVM Hosts
Next Post: Cisco Fixes Critical SD-WAN and IOS XE Vulnerabilities

Related Posts

Hugging Face Thwarts AI-Powered Cyber Attack Hugging Face Thwarts AI-Powered Cyber Attack Cyber Security News
Fake AI Chrome Extensions Compromise Over 260,000 Users Fake AI Chrome Extensions Compromise Over 260,000 Users Cyber Security News
AI-Powered Cyber Attacks Accelerate Threat Landscape AI-Powered Cyber Attacks Accelerate Threat Landscape Cyber Security News
GPT-5.6 Codex: File Deletion Issue Sparks Security Concerns GPT-5.6 Codex: File Deletion Issue Sparks Security Concerns Cyber Security News
Keenadu Malware Threatens Android Devices via Firmware Keenadu Malware Threatens Android Devices via Firmware Cyber Security News
Chrome’s Gemini Flaw Risks User Privacy with Remote Access Chrome’s Gemini Flaw Risks User Privacy with Remote Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Fixes Critical SD-WAN and IOS XE Vulnerabilities
  • Thousands of Rockwell PLCs Put Water Systems at Risk
  • New Linux Zapscape Vulnerability Threatens KVM Hosts
  • Canadian Hacker Admits Guilt in U.S. Cloud Breach Case
  • AI Memory Poisoning: The Threat of Hidden Prompts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Fixes Critical SD-WAN and IOS XE Vulnerabilities
  • Thousands of Rockwell PLCs Put Water Systems at Risk
  • New Linux Zapscape Vulnerability Threatens KVM Hosts
  • Canadian Hacker Admits Guilt in U.S. Cloud Breach Case
  • AI Memory Poisoning: The Threat of Hidden Prompts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark