LIVE · cybersecurity feed
Live wire
breach

Thousands of wind and solar park systems sit exposed on the internet across Europe

A recent report by Modat and the Dutch government's cybersecurity center, NCSC-NL, has revealed that 8,547 industrial control systems at wind and solar energy facilities across 35 countries in and around the European Union are directly accessible from the internet. These systems, which should be isolated from public networks, range from basic login portals to turbine control interfaces…

ZeroDay News ·

Source: Help Net Security

A recent report by Modat and the Dutch government's cybersecurity center, NCSC-NL, has revealed that 8,547 industrial control systems at wind and solar energy facilities across 35 countries in and around the European Union are directly accessible from the internet. These systems, which should be isolated from public networks, range from basic login portals to turbine control interfaces featuring "Stop" buttons.

The researchers identified these exposed systems using machine-learning clustering, which automatically groups similar devices and can uncover previously unrecognized system types. While the physical decentralization of renewable energy assets offers some protection against kinetic attacks, the report highlights a significant cybersecurity vulnerability, noting that "in cyberspace, there is no there there."

The exposed systems include web dashboards displaying live operational data such as power output, wind speed, and rotor information. Some control panels offer "Start," "Stop," and "Reset" functionalities. The report specifically mentions one wind turbine whose web server exposes a Siemens ET 200SP PLC, an industrial controller. Furthermore, some interfaces include map pages that reveal the precise geographical location of turbines, complete with aerial imagery of surrounding infrastructure.

While individual exposed systems can control a single turbine, others operate at a higher level, managing multiple turbines or entire energy farms, meaning a single compromised system could impact substantial generating capacity. The report also noted instances where login pages for wind parks explicitly named the sites and indicated that "root" is the default username in newer releases.

Of the 8,547 identified systems, 7,942 are associated with solar parks across 34 countries. Spain accounts for the largest share with 2,766 systems, representing 35% of the solar total. Greece (1,860), Italy (753), and Germany (672) collectively hold 76% of the exposed solar systems. For wind farms, 605 systems were found across 23 countries, with Germany (212) and Italy (192) making up 67% of this category. Despite the lower number, the exposed wind systems are significant, as some control multiple turbines at farms ranging from 10 megawatts to over 4,500 megawatts.

The report emphasizes that the actual number of exposed systems is likely higher, as systems were only included if they could be definitively linked to a specific solar or wind site.

The findings raise concerns about the security of remote access to critical infrastructure. While some countries, like Lithuania, restrict remote control by vendors from nations deemed national security threats, cybersecurity experts suggest that such measures address only one aspect of the problem. Most of the identified exposures are independent of the vendor's origin.

Experts recommend that organizations operating these facilities obtain a comprehensive list of all remote connections, including who connects, from where, to which assets, and their access permissions (read-only or operational control). They also advise requiring individual vendor accounts with strong authentication, limiting access to specific assets and actions, and separating permissions for sending commands from those for monitoring. Operators should maintain independent records of all commands and configuration changes, verify data and commands without relying solely on vendor systems, and ensure timely incident notification in compliance with directives like the EU's NIS2.

The immediate recommendation for operators is to remove administrative interfaces from the internet, plan and monitor systems with the assumption of an ongoing attack, and maintain the capability for manual site operation. The NIS2 directive holds management bodies of essential and important entities accountable for cybersecurity measures, whether systems are managed internally or outsourced.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Co-creator of Empire Market dark web marketplace given 40-year sentence

Raheim Hamilton, a co-creator of the dark web marketplace Empire Market, has been sentenced to 40 years in federal prison for his role in operating the platform. The 30-year-old Virginia native pleaded guilty earlier this year to a drug conspiracy charge and was ordered by U.S. District Judge Steven Seeger to forfeit over $100 million in Bitcoin and several properties in Virginia, in addition…

vulnerability

Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

The Pwn2Own Ireland 2026 hacking competition concluded with security researchers earning a total of $1,262,000 for demonstrating 98 unique zero-day vulnerabilities across various products. The three-day event, organized by Trend Micro's Zero Day Initiative (ZDI), saw 29 research teams targeting devices in seven categories, including mobile phones, AI infrastructure, and smart home devices.

ai

PCI SSC calls for human approval of AI agent actions involving cardholder data

The PCI Security Standards Council (PCI SSC) has released new guidance, "Security Considerations for AI Systems," aimed at securing artificial intelligence deployments within payment environments and defending against AI-assisted attacks. The advisory document, developed in collaboration with industry stakeholders, covers governance, deployment, access controls, testing, and the application of…

security

ICE Agent at NYC Shooting Has History of Alleged Violence and Illegal Arrests

An Immigration and Customs Enforcement (ICE) supervisor, Brenden Cuni, has been identified as an agent present at a shooting in New York City's Marble Hill neighborhood, near the Bronx, on Thursday. Cuni, who was seen brandishing a modified AR-15-style rifle at the scene, has a history of allegations of unlawful arrests and excessive force in federal court cases across New York and Minneapolis.

ai

Companies want autonomous IT operations but hesitate to let AI act alone

Ninety percent of companies anticipate a shift toward autonomous IT operations within the next two years, envisioning agentic AI systems that independently plan and execute multi-step tasks. However, a significant majority, 77 percent, express hesitation in allowing AI to make operational decisions without human approval. This suggests that most organizations currently aim for a model where a…

vulnerability

'AgentCorruption' Puts AWS Environments At Risk With Single Prompt

A recently disclosed vulnerability, dubbed 'AgentCorruption,' reportedly allowed attackers to compromise AWS environments through a single prompt directed at an AI chatbot. The flaw, now patched, was identified within AWS Bedrock AgentCore and could have enabled an attacker to gain control over an organization's entire fleet of AI agents.