Ad

Over 145,000 Industrial Control Systems in 175 Countries Discovered Exposed Online



New research showed that over 145,000 industrial control systems (ICS) are totally open to the internet and anyone can see them, which is super sketchy. The company that found this, Censys, says that the U.S. has the most of these with over 48,000. These systems are all over the place, but the most are in North America and Europe, and they use old protocols that aren't as secure as the stuff we have now.

They looked at a bunch of these systems and found that different regions have different types of ICS protocols that are more popular. For example, Modbus, S7, and IEC 60870-5-104 are big in Europe, while Fox, BACnet, ATG, and C-more are more common in North America. Some protocols like EIP, FINS, and WDBRPC are used in both places.

One of the guys who helped with the research, Zakir Durumeric, said that even though these protocols are old school from the '70s, they're still a big part of how things work in factories and stuff, but they don't have the same security upgrades that our phones and computers do.

There haven't been a ton of hacks on these ICS systems, but they're starting to happen more often, especially with the whole Ukraine and Russia situation going on. There's this one nasty malware called FrostyGoop that messes with these systems and can make them stop working.

HMIs are like the screens you use to control these industrial systems, and they're popping up online a lot, mostly in the U.S. and some European countries. The researchers said that even though these HMIs might not say who they belong to, they can still figure out a lot about them, like what company they're from or what they do.

To stay safe, companies need to be really careful with these devices, change the default passwords, and keep an eye on their networks for any weird activity. And it turns out, some of the most at-risk stuff in healthcare are these old medical devices that are part of the IoMT, like X-ray machines and stuff. Forescout, another company, said that these devices have been found to be super vulnerable because they're still using old tech.

So basically, we need to make sure we're protecting all this important stuff because if someone gets into them, it could cause a big mess. It's kind of like leaving your diary open on the internet, but way, way more serious.

Tags