CISA 警报:针对水务行业可编程逻辑控制器(PLC)的攻击
CISA Alert: Water Sector PLC Targeting

原始链接: https://censys.com/blog/cisa-alert-water-tower-plc-targeting/

2026年7月30日,美国网络安全和基础设施安全局(CISA)发布紧急警报,指出针对水利和污水处理系统(WWS)领域暴露在互联网上的可编程逻辑控制器(PLC)的威胁活动有所增加。攻击者通过修改密码将操作员锁定,并通过更改IP地址使设备失效,从而导致严重的运营中断,包括发布沸水警报。 CISA强调,蜂窝调制解调器是一个关键且常被忽视的安全盲点。他们强烈建议运营方将PLC与公共互联网断开连接,使用VPN或安全网关进行远程访问,并强制执行严格的密码管理和IP白名单策略。 Censys对受影响供应商当前面向互联网的设备占用情况进行了分析: * **罗克韦尔自动化(Rockwell Automation)/ Allen-Bradley:** 4,148台主机(主要在美国;59%通过蜂窝运营商连接)。 * **西门子(Siemens)SIMATIC S7-1200:** 4,117台主机(高度集中在南欧和中欧,多通过移动运营商连接)。 * **施耐德电气(Schneider Electric):** 2,072台主机(供应商范围;集中在土耳其和澳大利亚)。 虽然这些暴露数据描述了当前的概况,但并不证实存在主动攻击。敦促业主立即审计其基础设施,特别是未记录的蜂窝连接,以降低这些风险。

此次 Hacker News 的讨论聚焦于美国网络安全与基础设施安全局(CISA)近期发出的一项警报,该警报指出美国水务领域有超过 4,000 台罗克韦尔自动化(Rockwell Automation)的 PLC(可编程逻辑控制器)直接暴露在互联网上。由于技术陈旧、使用默认密码以及直接暴露于公网,这些关键系统正面临严重的安全威胁。 讨论反映出各方在如何应对这些系统性风险上存在巨大分歧: * **技术鸿沟:** 专家指出,运营技术(OT)面临独特挑战,例如许多遗留设备无法轻易修补或更换,否则可能导致基础设施瘫痪。 * **系统性疏忽:** 参与者认为,公用事业运营商往往依赖“价低者得”的承包商,这些承包商通常更看重短期项目而非长期安全。此外,网络安全专业知识的匮乏和责任落实不到位也加剧了这一问题。 * **监管辩论:** 关于责任归属存在强烈争议。一些人认为,鉴于水务系统属于国家关键基础设施,联邦政府必须强制执行安全标准并加强监管。另一些人则认为,由于美国拥有超过 15 万家资源匮乏的小型公用事业机构,集中化的联邦管控并不切实际,他们认为地方问责制和组织文化才是保障现代公用事业安全的真正瓶颈。
相关文章

原文

Download the full brief → 


Introduction

CISA issued an alert on July 30, 2026 warning that threat actors are increasingly targeting internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) sector, in some cases modifying passwords to lock out operators and disconnecting devices by changing their IP addresses, resulting in boil-water notices and sustained manual operations. CISA named Rockwell Automation/Allen-Bradley, Siemens, and Schneider Electric equipment and flagged cellular modems as a common blind spot in routine attack-surface scans. This report characterizes current Censys-observed internet exposure for each named vendor: 4,148 Rockwell/Allen-Bradley EtherNet/IP hosts, 4,117 Siemens SIMATIC S7-1200 hosts, and 2,072 Schneider Electric hosts (vendor-wide, not PLC-scoped), all as of the 2026-07-30 snapshot. This is an exposure characterization only: it does not confirm that any specific host is a victim of the activity CISA describes.


Advisory Context

The following paraphrases the CISA alert as supplied by the user for this report; it was not independently re-fetched from cisa.gov in this session.

CISA is observing a significant increase in threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Observed actor behavior includes modifying PLC passwords to lock out operators and disconnecting PLCs by changing their IP addresses, producing boil-water notices and sustained manual operations at affected utilities.

Targeting affects water entities of all sizes, including organizations with mature cybersecurity processes. CISA specifically flags cellular modems installed by operators, vendors, or system integrators as a common blind spot: these connections may be undocumented and excluded from routine attack-surface scans. Owners of Rockwell Automation MicroLogix 1400 controllers are directed to Rockwell’s guidance for restoring access when a controller password is unknown.

  • Disconnect the PLC from the internet; route remote access through a VPN or gateway device, not directly to the PLC.
  • Enable password protection and change default passwords.
  • Allowlist IPs to permit remote access only from known engineering laptops or other critical OT assets.

This report addresses the exposure-characterization question only — current internet-facing host counts, geography, and network concentration for the three named vendors — and does not assess the mitigations above, IOC infrastructure, or attribution.


Rockwell/Allen-Bradley Ethernet/IP

Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts).

Geographic Distribution


Rockwell/Allen-Bradley EtherNet/IP exposure by country (Censys, 2026-07-30)

Network/ASN Distribution


Rockwell/Allen-Bradley EtherNet/IP exposure by network/ASN (Censys, 2026-07-30).


Combined cellular carriers (Verizon Business, AT&T Mobility, T-Mobile USA) account for 59.0% of all exposed hosts.


Siemens Simatic S7-1200

Censys ARC identified 4,117 Internet-exposed hosts that fingerprint as Siemens SIMATIC S7-1200. Exposure concentrates heavily in southern and central Europe: Greece, Spain, Italy, and Austria together account for 86.0% of the total, each dominated by that country’s leading mobile carrier rather than fixed-line or hosting providers.

Geographic Distribution


Siemens SIMATIC S7-1200 exposure by country (Censys, 2026-07-30).


Network / ASN Distribution


Siemens SIMATIC S7-1200 exposure by country (Censys, 2026-07-30).

Schneider Electric (Vendor-Wide)

2,072 internet-exposed hosts fingerprint as Schneider Electric hardware (snapshot 2026-07-30). This query has no PLC-model or protocol filter. This total should not be read as Schneider Electric PLC exposure specifically. Turkey and Australia account for 55.5% of the total combined.

Geographic Distribution


Schneider Electric (Vendor-Wide) exposure by country (Censys, 2026-07-30).

Network/ASN Distribution


Schneider Electric (Vendor-Wide) exposure by network/ASN (Censys, 2026-07-30).

Censys Queries

Rockwell/Allen-Bradley:

(host.services.protocol=EIP) and host.services.eip.identity.vendor_name="Rockwell Automation/Allen-Bradley"

Siemens SIMATIC S7-1200:

host.hardware.vendor: "siemens" and host.hardware.product: "simatic_s7-1200"

Schneider Electric:

host.hardware.vendor = "schneider-electric"

联系我们 contact @ memedata.com