View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

More Than 4,400 Rockwell PLCs Exposed Online, 22 in Attack-Hit Cities

๐Ÿšจ ACTIVE EXPLOITATION

  • UNC6671 vishing attacks target hedge funds and private-equity firms UNC6671 has targeted financial firms in voice-phishing attacks.
    • Point72, Millennium, Two Sigma, Citadel, private-equity firms, and other financial organizations were targeted.
    • Microsoft 365 and Okta accounts, cloud services, credentials, session cookies, and data were targeted.
    • Attackers spoofed corporate help desks and called employees on personal mobile phones.
    • Victims were directed to adversary-in-the-middle phishing sites to steal credentials and session cookies in real time.
    • Automated tools accessed linked cloud platforms, stole data, and deleted security notifications and password-reset emails. ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • UPDATE: More Than 4,400 Rockwell PLCs Exposed Online, Including 22 in Attack-Hit Cities More than 4,400 Rockwell PLCs remain exposed online.

    • U.S. water utilities use the exposed Rockwell Automation/Allen-Bradley PLCs.
    • Forescout identified 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States.
    • Twenty-two exposed PLCs were located in cities hit by recent water-system attacks, with 19 using firmware susceptible to CVE-2017-16740.
    • Attackers remotely accessed internet-facing devices and changed IP addresses and passwords, disrupting monitoring and control.
    • Exposed EtherNet/IP on TCP port 44818 can provide unauthenticated access to identify controllers or write settings, depending on configuration. ๐Ÿ“„ Source: censys.com ยท ๐Ÿ“Ž Coverage: cyberscoop.com ยท ๐Ÿ‘ via CyberScoop
  • Researcher Claims Proof-of-Concept Control of ChatGPT Secure Sandbox A researcher demonstrated a proof-of-concept attack against ChatGPT's isolated sandbox.

    • The claim applies to ChatGPT's isolated sandbox during an OpenAI agent session.
    • The attack provided C2-style influence over the sandbox.
    • The proof of concept used an attack chain demonstrated at Black Hat USA 2026. ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading
  • Attackers increasingly target exposed OT systems for destructive disruption Attackers targeted exposed OT systems at U.S. water utilities.

    • U.S. water and wastewater utilities were targeted, including more than 30 Minnesota systems.
    • Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs were specifically targeted.
    • Attackers changed PLC passwords to lock out operators.
    • Attackers changed PLC IP addresses, disrupting remote access and forcing manual operations. ๐Ÿ“„ Source: cisa.gov ยท ๐Ÿ“Ž Coverage: cybersecuritydive.com ยท ๐Ÿ‘ via Cybersecurity Dive

๐Ÿ“‹ ADVISORIES

  • UPDATE: Zbtlink routers ship with an embedded backdoor enabling remote root shells VulnCheck found an embedded backdoor in at least 20 Zbtlink router models.
    • Zbtlink and Wiflyer routers, including white-label models sold worldwide, are affected; VulnCheck estimates more than 100,000 deployed.
    • The Endlessdoors implant appears in all 21 firmware images available from Zbtlink and affects models including CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602-DSIM, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and Z8102AX-2DSIM.
    • The implant starts at boot as a root userland process disguised as a Linux kworker thread and phones home every 35 seconds over unauthenticated cleartext TCP.
    • The rctl-based implant can execute server commands and open an interactive root shell through ports 7000 and 7001.
    • Reported endpoints include 47.107.224[.]89, rbdg4nzqadui[.]wikaba[.]com, zbtctl.epplink[.]net, 47.100.190[.]96, online-string[.]com, 45.32.81[.]152, and 43.248.136[.]125. ๐Ÿ“Ž Coverage: mastodon.social ยท ๐Ÿ‘ via @campuscodi@mastodon.social

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check