Over 900 automatic tank gauge (ATG) systems at US gas stations are exposed online and vulnerable to attacks. These systems monitor fuel and chemical storage tanks across critical infrastructure.
Automatic tank gauge systems are essential infrastructure components that track inventory levels in storage tanks at gas stations and other facilities. Security researchers discovered that a significant number of these systems lack adequate protection against unauthorized access.
The exposed ATG systems can be reached directly over the internet, creating potential entry points for attackers. Compromised systems could allow bad actors to monitor tank levels, manipulate readings, or disrupt fuel distribution operations.
The vulnerability affects multiple sectors beyond retail gas stations, including chemical storage facilities and other critical infrastructure that relies on ATG technology for operational monitoring.
Gas station operators and facility managers are advised to review their network security configurations, implement access controls, and isolate ATG systems from public internet access. Security patches and firmware updates should be applied where available.
The extent of any active exploitation remains unclear, but the widespread exposure indicates a significant security gap in US energy infrastructure.
A new remote access trojan called Dolphin X leverages AI to profile and score infected users, enabling cybercriminals to prioritize high-value victims for exploitation.
A race condition vulnerability in the Linux kernel's XFS filesystem allows local attackers to overwrite protected files and gain root privileges. The flaw, tracked as CVE-2026-64600, has remained unpatched for nine years.
Intensified enforcement against online scam operations in Cambodia is displacing criminal networks to Sri Lanka, where authorities have arrested over 1,000 people in 2026.
Offensive cybersecurity researchers report that safety guardrails from OpenAI and Anthropic are restricting their ability to find vulnerabilities and develop security tools. The limitations are creating friction for legitimate security work.