CISA Alert: Water Sector PLC Targeting
- Security
- Infrastructure
- Public Policy
- Hardware
The linked post is a vendor writeup on a CISA alert covering attempts to access PLCs used in water infrastructure, with Censys adding internet scan data showing more than four thousand hosts answering on EtherNet/IP and identifying as Rockwell Automation or Allen-Bradley. That gave people a concrete number to react to, but the bigger point was familiar: critical control systems are still exposed to the public internet in 2026, and nobody in the space sounds surprised anymore.
If you operate industrial systems, stop treating this as a niche OT problem and assume exposed control equipment will be found and probed. For leaders, the practical issue is governance and funding: inventory internet exposure, remove direct access, and make someone accountable for legacy system risk instead of waiting for federal warnings to do the work.
-
censys.com
- Discuss on HN