Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May, and June, all three months sit below the previous year’s floor, and the decline holds up against checks for address churn and port hopping. Exposure figures rarely move this way, and almost never t

The number of internet-exposed automatic tank gauges (ATGs) in the United States, which monitor fuel levels and other critical parameters, decreased by more than half over a three-month period, following advisories about suspected nation-state attacks. Between March and June, the count of unique IPv4 addresses responding to ATG protocol queries on the internet fell by 56 percent, from a peak of approximately 5,300 to 2,354.
This significant reduction, which began in April, is highly unusual for internet exposure figures of industrial control systems, which rarely change so rapidly. The decline was most pronounced in the U.S., contrasting with a gentler 26 percent reduction observed outside the country during the same timeframe.
ATGs are critical components at gas stations, airports, hospitals, power plants, data centers, and military bases, where they track fuel levels, temperature, moisture, and leaks, and can control alarms and fume extractors. Unauthorized access to these devices could allow an attacker to manipulate readings, disable alarms, or cause physical damage to the hardware.
The precipitous drop in exposure coincided with a series of warnings issued by industry and government bodies. On April 14, the Energy Marketers of America (EMA) released an urgent advisory, reporting that attackers were targeting tank gauges in Tennessee and other parts of the country, with unprotected consoles being the primary target. Many suspected Iran-linked activity. EMA and the Tennessee Fuel Convenience Store Association were already collaborating with the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Energy’s CESER office. News reports of suspected Iran-linked intrusions followed in mid-May.
Prior to April, the U.S. count of exposed ATGs had remained relatively stable, averaging 4,815 per month in 2025 and fluctuating between 4,300 and 5,300 from June 2025 through March 2026. In April, the number dropped by 27.6 percent to 3,850. May saw a further 31.8 percent decrease to 2,624, culminating in June's figure of 2,354.
The primary port affected by this reduction was port 10001, which is often a factory default for Lantronix adapters used to bridge older Veeder-Root serial lines to TCP/IP networks. Data shows that U.S. addresses on port 10001 decreased by 65 percent, from 4,214 in January to 1,466 in June. In contrast, port 8001, which serves a smaller population of similar networks, saw only a 4 percent decrease over the same period, from 885 to 849. This disparity suggests that the reduction was not merely due to IP address churn or changes in scanning coverage, but rather active remediation efforts targeting specific configurations.
Researchers estimate that approximately 2,260 addresses on port 10001 were genuinely removed from public internet exposure between January and June, after accounting for typical address churn. This indicates that a substantial number of operators took action to secure their systems.
Despite the significant reduction on port 10001, the relative stability of port 8001 suggests that the outreach and advisories may not have uniformly addressed all exposed configurations. Operators running consoles on other ports might mistakenly believe they are secure, but the recommended fix is to remove ATGs from direct internet exposure entirely, regardless of the port or protocol used.
A joint fact sheet published by CISA and seven other federal agencies on June 2 provided guidance on hardening these systems, including setting strong passwords and taking devices off the internet. However, most of the observed decline in exposure had already occurred by the time this fact sheet was released, indicating that earlier industry-specific advisories played a critical role.
While removing ATGs from direct internet exposure is a crucial step, it does not eliminate all risks. Devices behind VPNs, network address translation gateways, or carrier firewalls are no longer publicly visible but remain vulnerable if they are among affected models. Attackers can still reach industrial control systems by moving laterally once inside a network, a route that remains unaffected by external exposure reduction. Additionally, newer gauges often run their consoles on web servers, where default credentials are a common vulnerability.
Prior research identified ten zero-day flaws in six gauges from five vendors in 2024, and five more in 2025. The current analysis focused on hosts where at least one of these confirmed vulnerabilities was present, meaning all addresses in the monitored set were not merely visible but confirmed to be vulnerable.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets