home.social

#industrialcontrolsystems — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #industrialcontrolsystems, aggregated by home.social.

fetched live
  1. Ongoing PLC Exploitation Against Critical U.S. Infrastructure

    Multiple federal agencies have updated a joint advisory warning of active exploitation targeting programmable logic controllers (PLCs) in U.S. critical infrastructure. Attackers scan for internet-exposed industrial control systems and connect using legitimate engineering software with valid credentials, appearing as authorized technicians. Once inside, they alter controller logic and manipulate operator displays to hide anomalies. The campaign has expanded beyond Rockwell Automation to include Schneider Electric and Siemens equipment. Unlike a similar 2023 campaign that caused minimal disruption, this ongoing activity has resulted in confirmed operational disruption and financial losses. Targeted sectors include government facilities, water systems, and energy infrastructure. The exploitation leverages architectural weaknesses rather than software vulnerabilities, with attackers accessing systems through ports 22, 102, 502, 2222, and 44818.

    Pulse ID: 6a635bdde06bc9c9945e6c19
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Government #IndustrialControlSystems #InfoSec #Nim #OTX #OpenThreatExchange #RAT #Troll #bot #AlienVault

  2. US Warns of Iranian Hackers Targeting Exposed Industrial Controls

    When devices that connect our physical and digital worlds are left exposed to the public internet, they become an open invitation for hackers - and Iranian-linked cybercriminals are now actively targeting Internet-exposed industrial control systems, specifically Rockwell/Allen-Bradley…

    osintsights.com/us-warns-of-ir

    #IndustrialControlSystems #ProgrammableLogicControllers #Rockwellallenbradley #Iran #UsCriticalInfrastructure

  3. Could your next software update hide a ticking time bomb? Malicious NuGet packages are now creeping into trusted code—targeting databases and industrial systems with stealthy triggers that only go off on a specific date. How safe is your code, really?

    thedefendopsdiaries.com/malici

    #nugetsecurity
    #softwaresupplychain
    #malwareanalysis
    #industrialcontrolsystems
    #csharpextensionmethods

  4. 🌐Securing Critical Infrastructure 🌐

    Dive into the world of industrial control systems with @hacks4pancakes from @dragosinc. In this episode of the Breaking Badness Cybersecurity Podcast, discover the unique challenges and essential practices for securing our critical infrastructure. 🚧🔒

    #CyberSecurity #IndustrialControlSystems #OTSecurity #Dragos

    Listen wherever you get podcasts

    Apple: podcasts.apple.com/us/podcast/

    Spotify: open.spotify.com/episode/5S8UI

    YouTube: youtube.com/watch?v=S2f4MSQL7g

  5. New ICS Malware 'FrostyGoop' Targeting Critical Infrastructure

    Date: July 23, 2024

    CVE: N/A

    Vulnerability Type: Exploitation of Modbus TCP communication

    CWE: [[CWE-668]], [[CWE-20]], [[CWE-74]]

    Sources: The Hacker News, Yahoo News, Dragos

    Synopsis

    FrostyGoop is a newly identified malware designed to target Industrial Control Systems (ICS) by exploiting Modbus TCP communication protocols. This malware caused significant disruption to critical infrastructure in Lviv, Ukraine, earlier this year.

    Issue Summary

    In January 2024, FrostyGoop malware targeted an energy company in Lviv, resulting in a 48-hour loss of heating services to over 600 apartment buildings. This malware interacts directly with ICS devices using Modbus TCP over port 502, making it a serious threat to critical infrastructure.

    Technical Key Findings

    FrostyGoop, written in Golang, can read and write to ICS device registers and uses JSON-formatted configuration files to target specific IP addresses and Modbus commands. Initial access was likely gained through a vulnerability in Mikrotik routers.

    Vulnerable Products

    ENCO controllers with TCP port 502 exposed and ICS devices using Modbus TCP are particularly vulnerable to this malware.

    Impact Assessment

    The malware's ability to manipulate ICS devices can lead to significant operational disruptions, inaccurate system measurements, and potential safety hazards, affecting public safety and industrial operations.

    Patches or Workarounds

    Currently, there are no specific patches available for FrostyGoop.

    #FrostyGoop #ICS #ModbusTCP #CriticalInfrastructure #CyberAttack #EnergySector #Ukraine #Dragos #IndustrialControlSystems #Golang #MikrotikVulnerability

  6. Promising tool
    github.com/cisagov/parsnip

    Parsnip is a program developed to assist in the parsing of protocols using the open source network security monitoring tool Zeek. Parsnip is specifically designed to be applied towards developing Industrial Control Systems (ICS) protocol parsers but can be applied to any protocol.
    #Parsnip #ProtocolParser #Zeek #ICS #IndustrialControlSystems #OT #OperationalTechnology #SCADA