Advertisement
Enhancing OT Security with Cyber Deception Strategies
Implement cyber deception in OT to detect, deter, and understand threats targeting critical infrastructure. Gain vital intelligence from attacker interactions.
OT Security Startup Frenos Secures $1.52 Million for AI R&D
Frenos raises $1.52 million in seed funding to expand AI research and development focused on securing industrial control systems and operational technology.
Rockwell Arena Simulation RCE: CVE-2024-37367 and CVE-2024-37368 Patch
Rockwell Automation addresses high-severity memory corruption flaws in Arena simulation software that enable remote code execution via malicious .doe files.
PLC Exploits and AI Prompt Injection: Analysis of Emerging Threats
Analysis of recent threats including PLC attacks, AI image prompt injection, and Android spyware disguised as utility applications in the latest bulletin.
AI Models Fail at Nuclear Sabotage Malware Analysis Benchmark
New SentinelOne research reveals frontier AI models struggle with complex malware investigations, particularly those involving nuclear sabotage and industrial systems.
Iranian Hackers Target Siemens, Schneider, Rockwell ICS PLCs
US federal agencies warn of Iranian hackers actively targeting Siemens, Schneider Electric, and Rockwell Automation ICS PLCs. Defenders must secure OT environments.
Advertisement
Recognizing Excellence: The Critical Impact Awards in Industrial Cybersecurity
SecurityWeek launches Critical Impact Awards to honor innovations and proven impact in industrial cybersecurity, highlighting the importance of OT security.
OT Security: Legacy System Vulnerabilities in Critical Infrastructure
Addressing the complex challenges of securing legacy OT systems in critical infrastructure, balancing vulnerability disclosure with operational continuity and safety.
Siemens and Schneider Patch Critical ICS Flaws — October 2024
Siemens, Schneider Electric, and Rockwell Automation release critical updates for ICS products including SCALANCE, SINEC, and EcoStruxure platforms.
Jesse McGraw (GhostExodus): Examining the First ICS Hacking Conviction
A technical analysis of Jesse McGraw (GhostExodus), his compromise of hospital HVAC systems, and the evolution of industrial control system security threats.
Exposed Fuel Tank Gauges: US Gas Stations Face Active Cyberattacks
Threat actors are actively exploiting Internet-exposed fuel tank gauges at US gas stations, risking significant disruption to fuel supply and operations.
CISA Warns: Critical Infrastructure ATG Systems Under Attack
CISA, FBI, and NSA warn of active cyberattacks targeting internet-exposed Automatic Tank Gauge (ATG) systems in critical infrastructure. Learn to defend.
Hardening Automatic Tank Gauge Systems Against Cyber Threats
CISA and partners warn of active cyber threats targeting Automatic Tank Gauge (ATG) systems. Learn to secure critical infrastructure assets now.
CVE-2023-47359 & More: Critical Vulnerabilities in ABB Ability Camera Connect
Multiple critical and high-severity vulnerabilities in ABB Ability Camera Connect (VLC component <=1.5.0.14) could lead to RCE or DoS. Update to 1.5.0.15 now.
CVE-2026-41551: Siemens ROS# Path Traversal Remediation Guide
Critical path traversal vulnerability (CVE-2026-41551) in Siemens ROS# file_server allows arbitrary file access. Immediate update to v2.2.2+ is crucial.
CVE-2025-15467: ABB AC500 V3 Stack Buffer Overflow to RCE
Critical vulnerability [CVE-2025-15467](https://nvd.nist.gov/vuln/detail/CVE-2025-15467) in ABB AC500 V3 PM5xxx firmware could lead to unauthenticated remote code…
Polish Water ICS Breaches: Attackers Alter Operational Parameters
Poland's ABW reports unauthorized access to five water treatment plants where attackers gained control over operational parameters, risking public safety.
AI-Driven Cyberattack Fails to Breach OT Systems via SCADA Login
Analysis of the first AI-driven cyberattack targeting OT. Despite advanced automation, the campaign failed to bypass standard SCADA login interfaces.
Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks
Analysis of Microsoft Edge plaintext password storage risks, newly disclosed ICS zero-day vulnerabilities, and Telegram-based data exfiltration TTPs.
Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion
Threat actors utilized Anthropic’s Claude AI to navigate OT environments during a water utility breach, highlighting the rising risk of AI-assisted ICS attacks.
CVE-2026-3893: Unauthenticated Access in Carlson VASCO-B GNSS Receiver
Critical CVE-2026-3893 in Carlson VASCO-B GNSS Receivers <1.4.0 allows unauthenticated remote alteration of critical system functions. Update to v1.4.0+.
ZionSiphon Malware Targets Israeli Water Treatment ICS
Security analysis of ZionSiphon, a backdoor malware targeting Israeli desalination and water treatment facilities via ICS vulnerabilities.
Analyzing ZionSiphon: Malware Targeting Water Treatment OT Systems
Investigate ZionSiphon malware, an OT-specific threat designed to sabotage water treatment and desalination facilities.
OT Cryptographic Readiness: Addressing the PQC Attestation Gap
OT asset owners struggle to meet regulatory PQC attestation requirements due to a lack of visibility tools, creating a false sense of security in ICS environments.