Cybersecurity authorities issued an emergency directive after researchers demonstrated remote exploitation of a critical vulnerability in industrial control systems deployed at water utilities, energy facilities and manufacturing plants.

The flaw resides in a widely used programmable logic controller line and allows attackers to bypass authentication and issue commands that manipulate physical processes, from valve positions to motor speeds.

While no destructive attacks have been confirmed, scanning activity targeting the vulnerable devices spiked sharply following public disclosure. Several internet-exposed controllers have already been defaced with warning messages by vigilante researchers.

Operators are instructed to isolate control networks from the internet immediately, apply vendor firmware updates and audit systems for unauthorized logic changes.