Story perspectives
Pro-Russian Hackers Exploit Critical Vulnerability in OpenPLC
12/1/2025
49 6
1 of 1
Story summary
- U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2021-26829 to Known Exploited Vulnerabilities catalog for OpenPLC ScadaBR running on Windows and Linux.
- The flaw allows remote attackers to execute cross-site scripting attacks.
- TwoNet, a pro-Russian hacktivist group, exploited the vulnerability and targeted a honeypot instead of a water treatment facility.
- The attack unfolded over 26 hours and defaced the honeypot login page.
- Federal agencies must apply fixes by December 19, 2025.
