The UK National Cyber Security Centre (NCSC) warned that multiple state and non-state actors are increasingly targeting operational-technology (OT) environments worldwide, including in the United Kingdom. The activity has caused limited real-world disruption and is concentrated on systems exposed to the public internet, including OT assets accessible through misconfiguration, legacy management connections, and unmanaged edge devices.
The NCSC identified unsupported or end-of-life equipment, insecure industrial and management protocols, and unchanged default credentials as key exposure factors. It urged organisations to identify and remove public access to OT assets, segment OT from business and management networks, enforce strong authentication, maintain supported edge devices, protect controller logic from remote modification, continuously monitor connectivity, and test ransomware-resilient backup and recovery processes.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The UK NCSC issued an advisory warning that multiple state and non-state actors had increasingly targeted operational-technology systems globally, including in the UK, causing limited real-world disruption. It highlighted internet-exposed OT assets, edge devices, legacy protocols, unmanaged equipment, and default credentials as key risks and urged organisations to strengthen OT security.
The NCSC published information with international partners on activity targeting poorly configured routers, which it later cited as related disruptive activity affecting internet-exposed systems.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcencsc.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.