CISA, the FBI, NSA, and other US agencies have issued a joint advisory warning that threat actors are actively targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage in critical infrastructure sectors including energy, chemical, food and agriculture, and transportation. Attackers are exploiting authentication bypass vulnerabilities, hardcoded credentials, OS command-execution flaws, SQL injection, and privilege escalation to gain access, then modifying network settings, tank volumes, pump controls, and disabling alerts. The advisory follows CNN reporting that Iranian hackers were suspected in similar ATG breaches at gas stations across multiple US states. Recommended mitigations include blocking ATG systems from the internet, enforcing strong credentials and MFA, applying security patches, and actively monitoring for unauthorized changes.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Iranian hackers previously linked to similar activityThe Validation Gap: Automated Pentesting Answers One Question. You Need Six.
231 Impressions