Skip to content

1.8 Million Exposed RDP and VNC Access Points Endanger OT Infrastructures

In Brief: 1.8 million unprotected RDP and 1.6 million VNC servers worldwide provide direct attack vectors to Operational Technology.

Globally, over 1.8 million RDP and 1.6 million VNC servers without protective measures are directly accessible from the Internet and in some cases enable access to industrial and energy supply facilities. Active attackers and botnets are already exploiting this exposure.

Extensive measurements show: Over 1.8 million RDP (Remote Desktop Protocol) servers and at least 1.6 million VNC servers are directly accessible worldwide from the Internet without protective measures. A significant portion of these insecurely configured systems connect to machines and control systems in industry and energy supply, thereby exposing critical infrastructures directly to attack.

Hacktivists and established botnets—notably including REDHEBERG—are already actively exploiting these configuration errors. The reason lies in the fact that conventional VPN and jump host architectures provide only insufficient control over established sessions and their activities. This eliminates classical control mechanisms for access to critical systems.

As a countermeasure, Secure Remote Access is deployed, an approach that enables granular control over remote access, user actions and session parameters. For CISOs, this means a necessity to inventory exposed remote access services and to implement access control and monitoring mechanisms beyond mere network isolation.


Source: www.security-insider.de · Published July 13, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: