The images in this article were generated with artificial intelligence. How we publish
A new alert coordinated by U.S. federal agencies pointed to a tangible and urgent risk: More than 900 Automatic Tank Gauge (ATG) systems exposed on the Internet in the USA. United States.- and more than 1,000 at the global level according to public monitoring - are accessible and, according to the warning, are already target of attacks that allow to execute remote commands and modify their behavior. The joint warning can be found in the official document issued by the agencies: https: / / www.ic3.gov / CSA / 2026 / 260602.pdf.
TGAs are equipment that measure fuel and chemical levels in tanks, and combine inventory, leakage detection and environmental compliance functions. For their presence in service stations, industrial plants and other critical facilities, its alteration has a direct effect on operational safety and environmental integrity. The public monitoring of Shadowserver shows the magnitude of the phenomenon and allows you to visualize the exposed directions: https: / / dashboard.Shadowserver.org /... / atg.

The observed operating vectors are the ones that are unfortunately repeated in industrial equipment: default or hardcoded passwords, authentication omission, SQL injections, operating system command execution and privilege scaling failures. With these tracks, an attacker can disable alarms, manipulate readings, or force adjustments that damage sensors and bombs. A change in the configuration can turn a safety function into an environmental time pump or a fraud vector.
While some journalistic reports have linked previous incidents with Iranian actors, federal agencies that issued the alert emphasize that authorship is not conclusively attributed in all cases; the operational priority is immediate mitigation. Recent history shows that attackers do not need high sophistication to cause damage: unsafe configurations and direct Internet access are enough. A general context on risks in industrial control systems can be found in the resources of CISA: https: / / www.cisa.gov / industrial-control-systems.
For organizations operating ATG and similar equipment, immediate action should be clear and priority: identify and isolate the exposed devices, remove direct access from the Internet and place them behind accepted border controls (firewalls, VPNs or access control lists), and change credentials by default. The temporary disconnection of public access is a preventive measure of low risk and high impact while the condition of the equipment is validated.
Beyond that initial reaction, it is essential to apply patches and manufacturer updates, enable records and alerts to detect unauthorized changes, and deploy strong authentication (ideally multifactor when feasible). Sensor integrity tests - to verify that physical readings match system log - must be part of post-incident verification to rule out manipulations that hide leaks or mechanical failures.
Not everything is up to operators: ATG manufacturers and suppliers have a direct responsibility to remove firmware-embedded credentials, provide firm updates and document secure settings by default. From a regulatory and risk management perspective, require accurate asset inventories and continuity in the disclosure of vulnerabilities help reduce the number of unsafe devices accidentally connected to the Internet.

Visibility is a critical factor. Internet monitoring tools and reports such as Shadowserver help locate exposed devices, but companies must integrate regular internal scans, attack simulations and response exercises that include coordination with authorities (CISA / FBI) and suppliers. Reporting intrusions and anomalies to the authorities facilitates the collective response and traceability of malicious campaigns.
In practical terms for security equipment: identify public PIs with ATG service, audit configurations, restore unique and secure passwords, put strict network access rules and validate the integrity of physical security functions. For plant managers, check manually that the leak detectors and valves do not depend exclusively on vulnerable remote signals and that there is physical redundancy in the alarms.
This episode is a reminder that the digitization of industrial control increases the attack surface and that unnoticed exposure to the Internet translates administrative weaknesses into specific risks. The urgency is not only technological: it is operational and environmental and requires collaboration between operators, suppliers and authorities to close the opportunity window of the attackers before further damage occurs.
Related
More news on the same subject.

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...

SharePoint in CVE alert 2026 55040 JWT failures allow for identity supplanting and data exfiltration
In recent weeks malicious activity has been detected taking advantage of a critical vulnerability in Microsoft SharePoint registered as CVE-2026-55040(CVSS 9.1), which Microsoft...

Lazarus Group returns with a campaign aimed at defense and aerospace that combines kernel rootkit and social recruitment
The North Korean group known as Lazarus Group has again shown that it continues to improve intrusion techniques for the defence and aerospace industry. According to the research...