Thousands of Industrial Control Devices Found Exposed on Public Internet
A ZoomEye scan conducted on September 20, 2026, detected over 10,500 records responding to industrial protocol fingerprints across three queries. Modbus accounted for the largest share with 9,820 records, followed by EtherNet/IP with 585 and Siemens S7 with 173, each showing distinct geographic distributions. These protocols were originally designed for isolated, air-gapped networks and lack native authentication or encryption in their base forms. Researchers cautioned that a reachable device does not automatically indicate a vulnerability or confirm it controls critical infrastructure, as test rigs and simulators can appear identical in such scans. The findings nonetheless highlight that internet exposure of legacy industrial protocols is a widespread, multi-regional concern requiring careful network architecture controls.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in