Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'exposed'

View all threats tagged with 'exposed'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: exposed

Threats Tagged 'exposed'

Click on any threat for detailed analysis and mitigation recommendations

Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
0

A recent scan identified over 4,000 Rockwell Automation and Allen-Bradley industrial controllers used in U.S. water and wastewater systems exposed directly to the internet. Despite federal warnings, many of these devices remain accessible, including 22 in cities recently targeted by cyberattacks. The exposed devices use the EtherNet/IP protocol, which can allow remote identification and potential configuration changes if improperly secured. Some devices appear vulnerable to a known remote code execution flaw disclosed in 2017 (CVE-2017-16740). The FBI and EPA have confirmed cyberattacks on water utilities in multiple states, with some attacks causing operational disruptions such as pressure loss and flooding. The exposure is attributed to mass scanning and opportunistic exploitation rather than targeted zero-day attacks. Manufacturers and federal agencies have long advised against placing such controllers on the public internet.

Join the discussion
tl;dv (AI meeting assistant) left 181,874 meetings exposed via misconfigured Firestore, including live calls you could join. Researcher disclosed in January, still unpatched 6 months later.
0

The AI meeting assistant tl;dv exposed 181,874 meetings due to a misconfigured Firestore database. This exposure included live calls that unauthorized users could join. The vulnerability was disclosed by a researcher in January but remains unpatched six months later.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: exposed
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses