Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

US agencies warn of hackers targeting fuel tank monitoring systems

A joint advisory from CISA, FBI, NSA, and DOE warns of ongoing attacks targeting internet-exposed Automatic Tank Gauge (ATG) systems, which monitor fuel and liquid storage in critical infrastructure. Threat actors are exploiting vulnerabilities including authentication bypass, hardcoded credentials, OS command injection, and SQL injection to gain access, allowing them to modify system settings, disable alarms, and manipulate tank controls. To mitigate these risks, organizations should immediately block ATG systems from the internet, enforce strong authentication, apply available security updates, and monitor for unauthorized configuration changes.
Read Full Article →

OT Security US agencies warn of hackers targeting fuel tank monitoring systems June 4, 2026 Share By SC Staff (Adobe Stock) Internet-exposed automatic tank gauge (ATG) systems, used to monitor fuel and liquid storage tanks across critical infrastructure sectors, are being targeted by hackers, according to a joint warning from CISA, the FBI, the NSA, and the Department of Energy. These systems are crucial for remote monitoring of tank levels, temperatures, and potential leaks in sectors like energy, chemical, food and agriculture, and transportation. The advisory highlights ongoing malicious cyber activity, with further coverage provided by Bleeping Computer. Threat actors are exploiting vulnerabilities such as authentication bypass, hardcoded credentials, OS command execution flaws, SQL injection, and privilege escalation to gain access to these internet-exposed ATG systems. Once compromised, attackers can modify system settings, including network configurations, product identifiers, tank volumes, and pump controls. They can also disable alerts, potentially leading to undetected leaks or equipment failures. While the advisory does not attribute the attacks to a specific group, recent reporting has linked similar activity targeting ATG systems to Iranian hackers. Agencies are urging organizations to block ATG systems from the internet, restrict remote access, enforce strong authentication, apply security updates, and monitor for unauthorized changes to mitigate these risks. Source: Bleeping Computer SC Staff Related IoT Dragos acquires Phosphorus to enhance industrial cybersecurity SC Staff June 1, 2026 The acquisition aims to integrate Phosphorus' platform, which identifies connected devices, assesses exposures, and automates remediation, into Dragos' offerings. OT Security Iran suspected in breaching automatic tank gauges at US gas stations Laura French May 19, 2026 The automatic tank gauge systems were reportedly exposed online without passwords. IoT Thousands of Yarbo robotic lawnmowers exposed with identical default passwords SC Staff May 18, 2026 Security researcher Andreas Makris discovered that Yarbo robotic lawnmowers, which operate in over 30 countries and are equipped with cameras, GPS, and AI mapping, used the same default passwords. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article