Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cyber Security
  • Positive Technologies: “73 percent of industrial organizations’ networks are vulnerable to hackers”
  • Cyber Security

Positive Technologies: “73 percent of industrial organizations’ networks are vulnerable to hackers”

Do Son May 8, 2018 5 minutes read
Add Daily CyberSecurity as a preferred source on Google

After the security company Positive Technologies analyzed the data of more than a dozen companies in the global oil and gas, metallurgy and energy industries, a research report released on May 3, 2018, pointed out that hackers may penetrate the corporate network and Use this as a springboard to access the industrial environment.

Positive Technologies researchers have successfully infiltrated up to 73% of industrial organizations. In 82% of successful penetration cases, researchers can use this as a springboard to further access the extensive industrial network of Industrial Control System (ICS) equipment.

The proportion of ICS vulnerable to malicious hacking is really worrying. ICS is a technical term that covers a wide range of systems including SCADA for use in controlling manufacturing, power, power and wastewater treatment, the oil and gas industry, and many other industrial automation sectors.

 

Although most of the previous ICS systems were physically isolated from non-safety networks such as the public Internet, this practice has now been phased out. At present, many ICSs have begun to use traditional and modern technologies to introduce super-connection capabilities, including dial-up networking, Bluetooth, and physical serial connections. He said, “Even mobile applications have even emerged to help manage and monitor ICS devices.”

The analysis and testing companies of the company are exposed by SSH, Telnet, RDP, and other management interfaces:

  • 91% of companies are still providing password dictionaries for privileged users.
  • In 82% of cases, other types of security flaws at the network boundary expose the DBMS interface;
  • In 64% of cases, use vulnerable software;
  • In 64% of cases, use of insecure protocols;
  • 45% of cases have any file upload vulnerability;
  • In 36% of cases, there were remote command execution vulnerabilities and excessive software and user privilege authorization.
  • In about 80% of cases, the degree of difficulty of using these loopholes is “low” or “very low.”

Researchers have discovered a large number of vulnerabilities in the corporate network that allow malicious attackers to raise power and move laterally. The most common problems are weak passwords, vulnerable software and operating systems, and loopholes in network segmentation and traffic filtering.

In about two-thirds of companies, hackers may have used special control channels that bypass the demilitarized zone (DMZ) to access industrial networks.

In 45% of the cases, the researchers found that the traffic filtering between the networks was poor, while some companies did not have a quarantine zone (18%) or no network segmentation (18%) between the networks.

Positive Technologies pointed out in the report that these loopholes are very serious, and once the attack is successful, critical servers will be threatened. The risk of remotely controlling the gateway server through a dedicated channel seems to be less because the attacker needs to access a specific workstation in the enterprise information system. In most cases, this method of infiltrating industrial networks proved to be successful. Security vulnerabilities that have already been fixed on common systems have long existed in industrial control systems. This is because companies are afraid to perform any adjustments and operations that may lead to business downtime. More importantly, the method used to protect ICS in the industrial sector – for example, isolating the device from the Internet connection system – often fails to prevent attacks.

Research shows that even if a network segment is properly deployed, attackers can still access industrial systems. Access includes access to the firewall through administrator privileges and reconfiguration allows connections from malicious or infected devices.

Researchers said that the most successful attack vectors currently originate from the use of security vulnerabilities in Web applications, including SQL injection, arbitrary file upload, and remote command execution. The report stated that “almost every enterprise is using a dictionary password to protect the Web server management system or to protect the remote access mechanism through a management protocol, which means that in as many as one-third of the attack cases, malicious people need only one successful intrusion. You can gain access to the LAN.”

The U.S. Federal Bureau of Investigation (FBI) and the U.S. Department of Homeland Security (DHS) issued a joint warning last month alleging that the Russian state supports hacking organizations to take the process mentioned by Positive Technologies to launch an attack on U.S. grid infrastructure – that is, first in the site. Get a foothold and move to a critical system.

The warning states that “DHS and the FBI categorized this as a multi-stage intrusion campaign initiated by cyber attackers supported by the Russian government. This activity is aimed at small commercial facility networks where they run the malicious software and implement spear networks. A phishing attack and access to remote access to the energy sector network. After gaining access, the Russian government supports cyber attackers to further perform network reconnaissance, lateral movement, and collect information related to the Industrial Control System (ICS).”

On May 3, 2018, Tenable, a network security vendor from Maryland, released security flaws that existed in two applications widely used by manufacturers and power plants. The company said that this may allow hackers to further increase their access to the ICS device network.

 

Researchers have found that in many cases, due to weak or inadequate protection, attackers can easily obtain the necessary credentials. An attacker can obtain credentials of the enterprise IT system (usually stored in clear text) by attacking the firewall directly or by obtaining an encrypted password.

Source: ptsecurity

Related coverage

  • Cybersecurity Alert: MUT-8694 Supply Chain Attack Targets npm and PyPI Ecosystems
  • RansomHub Adopts New Tactics in Latest Attack, Bypasses EDR and Harvests Credentials
  • New China-Linked Threat Actor Earth Krahang Targets Government Entities Worldwide
  • Beyond VPNs and Botnets: Understanding the Danger of ORB Networks
  • Fake DocuSign Emails: Don’t Get Hooked by Phishing Scams
  • HoneyMyte Evolved: Spies Use Pixeldrain & CoolClient for Real-Time Surveillance
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: industrial organizations

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-95339CVSS 9.6
    Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary...
    📅 Updated: Sep 29, 2026
  • CVE-2026-95350CVSS 9.6
    Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to...
    📅 Updated: Sep 29, 2026
  • CVE-2026-95357CVSS 9.6
    Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote...
    📅 Updated: Sep 29, 2026
  • CVE-2026-69865CVSS 10.0
    Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a...
    📅 Updated: Sep 29, 2026
  • CVE-2026-87701CVSS 9.6
    Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows...
    📅 Updated: Sep 29, 2026
  • CVE-2026-102829CVSS 9.2
    simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from...
    📅 Updated: Sep 29, 2026
  • CVE-2026-102828CVSS 9.2
    simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from...
    📅 Updated: Sep 29, 2026
  • CVE-2026-65113CVSS 9.8
    NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A...
    📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.