Back Scworld Report: Operational tech remains primary target for hackers
Trellix reports that manufacturing continues to face the highest volume of operational technology attacks, representing 42% of OT-related detections across its critical-infrastructure customers, with transportation and shipping, utilities, energy companies, and aerospace firms making up the remaining top targeted sectors, according to Cybersecurity Dive .
Based on activity between April and September, the report notes that OT incidents have shifted from unintended spillover from IT breaches to deliberate operations carried out by criminal groups and state- actors. Trellix says intrusions frequently exploit weaknesses in the connection between IT and OT networks, with attackers using Cobalt Strike, PowerShell, stolen credentials, and scans for industrial control system protocols to move within environments. Instead of directly attacking low-level industrial controllers, threat actors increasingly compromise devices that bridge the two network layers, which often contain more common vulnerabilities but still enable interference with industrial equipment.
Some attacks have attempted to corrupt or shut down safety-related systems. Trellix also warns vulnerabilities in legacy protocols such as Modbus, proprietary Supervisory Control and Data Acquisition device-makers' protocols, DNP3, as well as increased targeting of programmable logic controllers, citing past Triton malware activity. The report urges segmentation, zero-trust controls, threat-intelligence sharing, and strong vendor requirements.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
