Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Can Manipulate Internet-Based Solar Panel Systems to Execute Attacks in Minutes

Recent findings indicate that internet-based attacks are increasingly targeting solar power infrastructure, posing significant risks to energy production. Attackers can exploit these systems within minutes using open ports and readily available tools.

Recent findings indicate that internet-based attacks are increasingly targeting solar power infrastructure, posing significant risks to energy production. Attackers can exploit these systems within minutes using open ports and readily available tools.

Modern solar farms utilize networked operational technology, including SCADA controllers and string monitoring boxes, many of which employ the legacy Modbus protocol that lacks inherent security features.

When these devices are exposed online, attackers can remotely send control commands, potentially disrupting power generation on clear, sunny days with minimal effort.

Cato Networks analysts have observed extensive reconnaissance and exploitation attempts on Modbus-enabled string-monitoring boxes, which directly control solar panel outputs.

By exploiting Modbus over TCP, typically accessible on port 502, attackers can read device status and manipulate control bits to turn strings on or off.

Recent findings indicate that internet-based attacks are increasingly targeting solar power infrastructure, posing significant risks to energy production.
Peter Collins · Thehackingpost

This approach does not require zero-day exploits or complex payloads. The primary risk arises from default-open services and insecure protocols. Once attackers identify a vulnerable device, the time from initial probe to significant power disruption can be reduced from days to mere minutes.

Command-Level Manipulation over Modbus

The core of this threat involves direct register manipulation over Modbus/TCP. Attackers typically start with discovery using tools like Nmap's Modbus NSE scripts to verify a host's Modbus service on port 502 and enumerate device IDs.

For instance, a malicious operator could switch off a PV string by writing a specific value to a control register:

mbpoll -m tcp -t 0 -r 0xAC00 -0 1 <target-ip>

Advertisement

0xAC00 mapped as SWITCH OFF

Registers such as 0xAC00 and 0xAC01 are often mapped to "SWITCH OFF" and "SWITCH ON," respectively. By looping these commands, attackers could rapidly toggle strings, stress inverters, or silently reduce production while keeping the plant online.

AI-driven tools can automate the scanning, fingerprinting, and command injection processes against OT assets, enhancing attack scalability.

These findings underscore the vulnerabilities present in internet-exposed Modbus services on solar assets, highlighting the potential for rapid grid disruption.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories