CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New Report Reveals Hidden Risks: How Internet-Exposed Systems Threaten Critical Infrastructure

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1927

As cited

Copy frozen at (site build).

ot ics

New Report Reveals Hidden Risks: How Internet-Exposed Systems Threaten Critical Infrastructure

A Censys report identified approximately 145,000 internet-exposed industrial control systems (ICS) and thousands of insecure human-machine interfaces (HMI), creating readily exploitable entry points for attackers. Real-world incidents demonstrate active threats, including state-backed actors from Iran and Russia targeting HMI systems to compromise water infrastructure in Pennsylvania and Texas. GreyNoise research confirms attackers are actively scanning for HMI vulnerabilities and prioritizing remote access services as lower-friction attack vectors compared to direct ICS protocol exploitation.

Why it matters: Critical infrastructure operators managing water systems, utilities, and industrial facilities need immediate visibility into externally exposed HMI and RAS endpoints, as documented state-sponsored activity shows these systems are being actively targeted and weaponized.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary