WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) Forescout’s 2025 Threat Roundup Report
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Forescout’s 2025 Threat Roundup Report

TLP:CLEAR

Author: Chase Snow

Created: Thursday, February 12, 2026 - 15:00

Categories: Cybersecurity, Security Preparedness

Summary: Forescout Research – Vedere Labs recently released its “2025 Threat Roundup report,” which analyzed threat actor intelligence collected throughout the year, including over 900 million attacks. The report highlights an increase in the volume, sophistication, and global distribution of cyber attacks, with increasing abuse of cloud infrastructure and expanding exploitation across IT, IoT, and OT environments. Notably, while the number of threat actors and state-sponsored groups remained relatively similar, threat actors conducted nearly six times more incidents compared to the previous report.

Additionally, the report notes an 84% surge in attacks leveraging OT protocols, with Modbus accounting for 57% of observed OT exploitation, followed by Ethernet/IP (22%) and BACnet (8%). IoT exploitation rose 19% frequently targeting IP cameras and network video recorders.  

Analyst Note: Members are encouraged to review the report, which includes key findings related to OT/ICS infrastructure and offers strategic recommendations for improved defense in 2026 in the recommended mitigations section. The report indicates the importance of comprehensive visibility across all asset types, including legacy OT, IoT devices such as cameras and environmental sensors, and externally facing web applications. Members can validate unnecessary services are disabled, default credentials are removed, and multifactor authentication is enforced for remote access and administrative interfaces. Network segmentation between IT and OT environments, combined with strict access control lists limiting exposure to sensitive protocols, can significantly reduce lateral movement risk.

Original Source: https://www.forescout.com/research-labs/2025-threat-roundup/

Additional Reading:

  • 2025 Threat Report: Exploitation Grows Across IT, IoT, and OT

Related WaterISAC PIRs: 6 -12

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 11, 2026)

Jun 11, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – June 11, 2026

Jun 11, 2026 in Cybersecurity
Members Only

(TLP:GREEN) FBI Report – Elevated Cyber Risk to Utility Providers Supporting FIFA World Cup 2026 Tournament Events

Jun 11, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar