DFIR Radar[verified]@DFIR_RadarActive Exploitation
Iranian State Group CyberAv3ngers actively exploited the unpatched Rockwell CVE-2021-22681, causing operational disruptions in critical infrastructure, and the advisory calls for immediate mitigations.
Ahmed Nawaz Khalid[verified]@hushed_ahmieActive Exploitation
CISA has classified two critical CVEs (CVE‑2017‑7921 and CVE‑2021‑22681) as known exploited vulnerabilities with active wild attacks, urging immediate patching.
EdgeDetectOps[verified]@EdgeDetectOpsActive Exploitation
The tweet reports that attackers have discovered how to exploit the master key flaw in Rockwell factory controllers and are actively using it against thousands of devices worldwide.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The post reports active exploitation of CVE‑2021‑22681 in Rockwell PLCs by Iranian‑affiliated actors, notes no patch and recommends compensating controls like network isolation.
piyokango[verified]@piyokangoActive Exploitation
CISA confirms that five CVEs are being actively exploited in the wild, and vendor links indicate patches or workarounds are available. No PoC or exploit code is shared.
EdgeDetectOps[verified]@EdgeDetectOpsDisclosure
The tweet announces CVE-2021-22681, describing how hardcoded authentication keys in Rockwell Studio 5000 Logix Designer can be extracted to impersonate legitimate design software and target industrial controllers, with no mention of PoC, exploit code, or patches.
ShiftSix Security[verified]@Shift6SecurityGeneral
The text offers scanning guidance for water‑infrastructure OT systems and lists CVE-2021-22681, but provides no PoC, exploit tool, active exploitation claim, patch details, or technical vulnerability specifics.
ShiftSix Security[verified]@Shift6SecurityPatch
Rockwell declares CVE-2021-22681 is unpatchable and the sole mitigation is to remove exposure from the network.