Exposed Modbus ICS Devices Heighten Risks to Critical Infrastructure

Exposed Modbus ICS Devices Heighten Risks to Critical Infrastructure

First seen 9 Apr 2026, 22:00 UTC Securityaffairs.CoScworldIndustrialcyber.Cowww.catonetworks.com 81% similarity 68.0

Article Content

Browse articles
ThreatCluster

A report reveals that 179 internet-exposed industrial control systems (ICS) using the Modbus protocol are vulnerable across 20 countries, with the majority located in the U.S., Sweden, and Turkey. The Modbus protocol lacks encryption and authentication, making these devices susceptible to unauthorized access and manipulation. Notably, one device is part of a national railway network, while others are linked to power grid infrastructures in both Asia and Europe. Researchers from Comparitech warn that attackers can exploit these vulnerabilities to read and write to holding registers without authentication. The presence of malware targeting ICS, such as Stuxnet and Industroyer, further exacerbates the risk of disruption and sabotage. The findings indicate a significant threat to critical infrastructure entities, necessitating immediate attention from security professionals.

Key Points: • 179 Modbus ICS devices exposed across 20 countries, primarily in the U.S. • Modbus protocol lacks encryption and authentication, increasing vulnerability. • Malware like Stuxnet and Industroyer poses additional risks to critical infrastructure.

ThreatCluster AI

Timeline

2026-04-09
Report on exposed Modbus ICS devices published
Date unknown
Discovery of devices linked to national railway and power grids
Date unknown
Research findings released by Comparitech

Community

Browse all →