Over 161,000 Assets Exposed on Port 102 Linked to Industrial PLC Advisory
A joint cybersecurity advisory (AA26-231A), issued on August 19, 2026, by the NSA, CISA, FBI, DOE, and EPA, warned that threat actors were using internet scanning services to locate exposed Siemens S7 programmable logic controllers running outdated software. The attackers reportedly used AI-generated scripts built on open-source libraries to read and write PLC memory and configuration data via the S7comm protocol on TCP port 102. A subsequent ZoomEye query conducted on September 16, 2026, found 161,764 assets with port 102 reachable, while more specific fingerprints returned far smaller counts — 10,160 for Siemens SIMATIC and just 173 for Siemens S7. Analysts caution that these figures reflect indexed exposure levels, not counts of vulnerable or compromised devices, as different query types measure different things. Asset owners are advised to audit their own network address space against documentation to identify any unintended internet-facing controllers.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in