TL;DR

what: Forescout's August 3 scan found 4,407 internet-facing Rockwell PLCs worldwide, including 22 in US cities where water utilities reported attacks since July 27.

Forescout scanned the internet on August 3 and counted 4,407 exposed Rockwell Automation programmable logic controllers. 2,844 of them are in the United States. Twenty-two sit in cities where water utilities have reported cyberattacks since July 27, and 19 of those 22 ride the same mobile carrier network. Forescout could not confirm that any of the 4,407 were compromised, and the number counts controllers, not utilities or victims.

The part that should change your Monday: the effects described publicly in those water incidents did not require a vulnerability exploit. Attackers changed IP addresses and set passwords on controllers that were already reachable from the internet. Operators lost visibility, and in some cases control, of connected equipment. No CVE, no memory corruption, no zero-day. Just a device answering unauthenticated requests on a routable address.

What the exposure actually looks like