Industrial and building-automation environments continue to expose operational technology (OT) services directly to the public internet, increasing the likelihood of unauthorized access and disruption. An Intelligence-Driven Active Defense Report 2026 cited by Palo Alto Networks/Siemens/Idaho National Laboratory data indicates internet exposure is growing sharply, with Cortex Xpanse reporting 110M+ observations of exposed OT devices in 2024 and fingerprinting 19.6M unique OT devices/services across 1.77M IPv4 addresses; the highest concentrations were observed in the US, China, and Germany. Frequently observed exposed products included Tridium Niagara, Linear eMerge, and Saia PCD Web Server, and common exposure points included standard web ports TCP/443 and TCP/80 alongside OT/building-automation-associated ports such as TCP/502, UDP/47808, and Niagara-related ports like TCP/4911 and TCP/5011.
Similar internet-exposure risk was observed in healthcare, where Rapid7 Labs reported 30+ UK-based systems responding to DICOM requests over TCP/104 (the default medical imaging port) from the public internet. Rapid7 stated it used Project Sonar to validate service responsiveness only and did not attempt to access records, but warned that externally reachable DICOM services—especially without VPN restriction or encryption—are readily discoverable via routine scanning and were not designed for hostile networks. Prior research cited in the report indicates misconfigured or poorly controlled PACS/DICOM deployments can leak sensitive metadata (including patient identifiers) and may be susceptible to data reconstruction or modification, creating both cybersecurity and patient safety risk.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
A global scan found 311 Modbus responses on port 502, which researchers filtered down to 179 likely real internet-exposed ICS devices across multiple countries, with the United States hosting the most. Some exposed systems appeared linked to sensitive environments including a national railway network and national power grids in Europe and Asia, highlighting risks from Modbus's lack of authentication and encryption.
A report cited by Palo Alto Networks, Siemens, and Idaho National Laboratory said internet exposure of OT systems continues to grow, with remote access portals, building automation servers, and other OT services reachable on public IP space. The report also highlighted long precursor phases before attacks and promoted earlier detection and OT-SOC maturity improvements.
Rapid7 Labs reported that, at the time of observation, more than 30 UK-based systems were responding to DICOM requests over Port 104 from the public internet. It also observed additional externally reachable PACS-related systems over web ports such as 80 and 443, confirming service responsiveness without attempting to access records or exploit the systems.
Trend Micro's TrendAI analysis, based on Shodan data from November to December 2025, identified 3,627 publicly accessible DICOM servers across more than 100 countries, with about one-third located in the United States. The report said most lacked basic protections, with minimal TLS use, widespread acceptance of connections without AE Title validation, and exposure to several known vulnerabilities.
According to Palo Alto Networks, Cortex Xpanse observed more than 110 million instances of exposed OT devices in 2024, identifying 19.6 million unique OT devices and services across 1.77 million IPv4 addresses. The highest concentrations were reported in the United States, China, and Germany.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
5 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcehelpnetsecurity.com
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.