<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #ICS Security</title><description>Cybersecurity articles tagged #ICS Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Enhancing OT Security with Cyber Deception Strategies</title><link>https://runtimerebel.com/blog/enhancing-ot-security-with-cyber-deception-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/enhancing-ot-security-with-cyber-deception-strategies</guid><description>Implement cyber deception in OT to detect, deter, and understand threats targeting critical infrastructure. Gain vital intelligence from attacker interactions.</description><pubDate>Tue, 08 Sep 2026 12:26:26 GMT</pubDate><category>OT Security</category><category>ICS Security</category><category>Cyber Deception</category><category>Threat Detection</category><category>Critical Infrastructure</category></item><item><title>OT Security Startup Frenos Secures $1.52 Million for AI R&amp;D</title><link>https://runtimerebel.com/blog/ot-security-startup-frenos-secures-1-52-million-for-ai-r-d</link><guid isPermaLink="true">https://runtimerebel.com/blog/ot-security-startup-frenos-secures-1-52-million-for-ai-r-d</guid><description>Frenos raises $1.52 million in seed funding to expand AI research and development focused on securing industrial control systems and operational technology.</description><pubDate>Tue, 28 Jul 2026 14:10:52 GMT</pubDate><category>Frenos</category><category>OT Security</category><category>ICS Security</category><category>AI Security</category><category>Critical Infrastructure</category></item><item><title>Rockwell Arena Simulation RCE: CVE-2024-37367 and CVE-2024-37368 Patch</title><link>https://runtimerebel.com/blog/rockwell-arena-simulation-rce-cve-2024-37367-and-cve-2024-37368-patch</link><guid isPermaLink="true">https://runtimerebel.com/blog/rockwell-arena-simulation-rce-cve-2024-37367-and-cve-2024-37368-patch</guid><description>Rockwell Automation addresses high-severity memory corruption flaws in Arena simulation software that enable remote code execution via malicious .doe files.</description><pubDate>Sat, 25 Jul 2026 09:49:59 GMT</pubDate><category>Rockwell Automation</category><category>Arena Simulation</category><category>CVE-2024-37367</category><category>CVE-2024-37368</category><category>ICS Security</category><category>RCE</category></item><item><title>PLC Exploits and AI Prompt Injection: Analysis of Emerging Threats</title><link>https://runtimerebel.com/blog/plc-exploits-and-ai-prompt-injection-analysis-of-emerging-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/plc-exploits-and-ai-prompt-injection-analysis-of-emerging-threats</guid><description>Analysis of recent threats including PLC attacks, AI image prompt injection, and Android spyware disguised as utility applications in the latest bulletin.</description><pubDate>Thu, 23 Jul 2026 17:26:37 GMT</pubDate><category>PLC Security</category><category>AI Security</category><category>Android Spyware</category><category>Prompt Injection</category><category>ICS Security</category></item><item><title>AI Models Fail at Nuclear Sabotage Malware Analysis Benchmark</title><link>https://runtimerebel.com/blog/ai-models-fail-at-nuclear-sabotage-malware-analysis-benchmark</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-models-fail-at-nuclear-sabotage-malware-analysis-benchmark</guid><description>New SentinelOne research reveals frontier AI models struggle with complex malware investigations, particularly those involving nuclear sabotage and industrial systems.</description><pubDate>Thu, 23 Jul 2026 14:13:02 GMT</pubDate><category>AI Security</category><category>Fast16</category><category>SentinelOne</category><category>Malware Analysis</category><category>ICS Security</category></item><item><title>Iranian Hackers Target Siemens, Schneider, Rockwell ICS PLCs</title><link>https://runtimerebel.com/blog/iranian-hackers-target-siemens-schneider-rockwell-ics-plcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-hackers-target-siemens-schneider-rockwell-ics-plcs</guid><description>US federal agencies warn of Iranian hackers actively targeting Siemens, Schneider Electric, and Rockwell Automation ICS PLCs. Defenders must secure OT environments.</description><pubDate>Thu, 23 Jul 2026 06:32:12 GMT</pubDate><category>Iranian Hackers</category><category>ICS Security</category><category>OT Security</category><category>Siemens</category><category>Schneider Electric</category><category>Rockwell Automation</category><category>PLCs</category></item><item><title>Recognizing Excellence: The Critical Impact Awards in Industrial Cybersecurity</title><link>https://runtimerebel.com/blog/recognizing-excellence-the-critical-impact-awards-in-industrial-cybersecurity</link><guid isPermaLink="true">https://runtimerebel.com/blog/recognizing-excellence-the-critical-impact-awards-in-industrial-cybersecurity</guid><description>SecurityWeek launches Critical Impact Awards to honor innovations and proven impact in industrial cybersecurity, highlighting the importance of OT security.</description><pubDate>Tue, 21 Jul 2026 13:56:33 GMT</pubDate><category>Industrial Cybersecurity</category><category>ICS Security</category><category>OT Security</category><category>SecurityWeek</category><category>Critical Impact Awards</category><category>Cybersecurity Awards</category><category>Industry Recognition</category></item><item><title>OT Security: Legacy System Vulnerabilities in Critical Infrastructure</title><link>https://runtimerebel.com/blog/ot-security-legacy-system-vulnerabilities-in-critical-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/ot-security-legacy-system-vulnerabilities-in-critical-infrastructure</guid><description>Addressing the complex challenges of securing legacy OT systems in critical infrastructure, balancing vulnerability disclosure with operational continuity and safety.</description><pubDate>Thu, 16 Jul 2026 17:24:03 GMT</pubDate><category>OT Security</category><category>Legacy Systems</category><category>Critical Infrastructure</category><category>Vulnerability Management</category><category>ICS Security</category></item><item><title>Siemens and Schneider Patch Critical ICS Flaws — October 2024</title><link>https://runtimerebel.com/blog/siemens-and-schneider-patch-critical-ics-flaws-october-2024</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-and-schneider-patch-critical-ics-flaws-october-2024</guid><description>Siemens, Schneider Electric, and Rockwell Automation release critical updates for ICS products including SCALANCE, SINEC, and EcoStruxure platforms.</description><pubDate>Wed, 15 Jul 2026 10:07:48 GMT</pubDate><category>Siemens</category><category>Schneider Electric</category><category>Rockwell Automation</category><category>ICS Security</category><category>SCADA</category><category>CVE-2024-42359</category><category>CVE-2024-38311</category></item><item><title>Jesse McGraw (GhostExodus): Examining the First ICS Hacking Conviction</title><link>https://runtimerebel.com/blog/jesse-mcgraw-ghostexodus-examining-the-first-ics-hacking-conviction</link><guid isPermaLink="true">https://runtimerebel.com/blog/jesse-mcgraw-ghostexodus-examining-the-first-ics-hacking-conviction</guid><description>A technical analysis of Jesse McGraw (GhostExodus), his compromise of hospital HVAC systems, and the evolution of industrial control system security threats.</description><pubDate>Mon, 13 Jul 2026 14:43:16 GMT</pubDate><category>GhostExodus</category><category>Jesse McGraw</category><category>ICS Security</category><category>SCADA</category><category>Insider Threat</category></item><item><title>Exposed Fuel Tank Gauges: US Gas Stations Face Active Cyberattacks</title><link>https://runtimerebel.com/blog/exposed-fuel-tank-gauges-us-gas-stations-face-active-cyberattacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/exposed-fuel-tank-gauges-us-gas-stations-face-active-cyberattacks</guid><description>Threat actors are actively exploiting Internet-exposed fuel tank gauges at US gas stations, risking significant disruption to fuel supply and operations.</description><pubDate>Fri, 05 Jun 2026 20:42:04 GMT</pubDate><category>Fuel Tank Gauges</category><category>Gas Stations</category><category>Critical Infrastructure</category><category>OT Security</category><category>Exposed Devices</category><category>US</category><category>ICS Security</category></item><item><title>CISA Warns: Critical Infrastructure ATG Systems Under Attack</title><link>https://runtimerebel.com/blog/cisa-warns-critical-infrastructure-atg-systems-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-warns-critical-infrastructure-atg-systems-under-attack</guid><description>CISA, FBI, and NSA warn of active cyberattacks targeting internet-exposed Automatic Tank Gauge (ATG) systems in critical infrastructure. Learn to defend.</description><pubDate>Wed, 03 Jun 2026 21:11:09 GMT</pubDate><category>CISA</category><category>FBI</category><category>NSA</category><category>Automatic Tank Gauge</category><category>ATG</category><category>Critical Infrastructure</category><category>OT Security</category><category>ICS Security</category></item><item><title>Hardening Automatic Tank Gauge Systems Against Cyber Threats</title><link>https://runtimerebel.com/blog/hardening-automatic-tank-gauge-systems-against-cyber-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/hardening-automatic-tank-gauge-systems-against-cyber-threats</guid><description>CISA and partners warn of active cyber threats targeting Automatic Tank Gauge (ATG) systems. Learn to secure critical infrastructure assets now.</description><pubDate>Tue, 02 Jun 2026 21:12:50 GMT</pubDate><category>ATG Systems</category><category>Operational Technology</category><category>ICS Security</category><category>Critical Infrastructure</category><category>CISA Advisory</category><category>Cyber Threat Actors</category><category>Authentication Bypass</category><category>Privilege Escalation</category><category>SQL Injection</category></item><item><title>CVE-2023-47359 &amp; More: Critical Vulnerabilities in ABB Ability Camera Connect</title><link>https://runtimerebel.com/blog/cve-2023-47359-more-critical-vulnerabilities-in-abb-ability-camera-connect</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-47359-more-critical-vulnerabilities-in-abb-ability-camera-connect</guid><description>Multiple critical and high-severity vulnerabilities in ABB Ability Camera Connect (VLC component &lt;=1.5.0.14) could lead to RCE or DoS. Update to 1.5.0.15 now.</description><pubDate>Tue, 26 May 2026 20:49:50 GMT</pubDate><category>CVE-2023-47359</category><category>CVE-2019-13962</category><category>CVE-2017-10699</category><category>ABB Ability Camera Connect</category><category>VLC Media Player</category><category>Buffer Overflow</category><category>Integer Underflow</category><category>ICS Security</category></item><item><title>CVE-2026-41551: Siemens ROS# Path Traversal Remediation Guide</title><link>https://runtimerebel.com/blog/cve-2026-41551-siemens-ros-path-traversal-remediation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-41551-siemens-ros-path-traversal-remediation-guide</guid><description>Critical path traversal vulnerability (CVE-2026-41551) in Siemens ROS# file_server allows arbitrary file access. Immediate update to v2.2.2+ is crucial.</description><pubDate>Thu, 14 May 2026 20:40:37 GMT</pubDate><category>CVE-2026-41551</category><category>Siemens ROS</category><category>Path Traversal</category><category>Critical Manufacturing</category><category>ICS Security</category></item><item><title>CVE-2025-15467: ABB AC500 V3 Stack Buffer Overflow to RCE</title><link>https://runtimerebel.com/blog/cve-2025-15467-abb-ac500-v3-stack-buffer-overflow-to-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-15467-abb-ac500-v3-stack-buffer-overflow-to-rce</guid><description>Critical vulnerability [CVE-2025-15467](https://nvd.nist.gov/vuln/detail/CVE-2025-15467) in ABB AC500 V3 PM5xxx firmware could lead to unauthenticated remote code…</description><pubDate>Tue, 12 May 2026 20:40:45 GMT</pubDate><category>CVE-2025-15467</category><category>ABB AC500 V3</category><category>Stack Buffer Overflow</category><category>ICS Security</category><category>PLC Security</category><category>Out of Bounds Write</category><category>Critical Manufacturing</category><category>Energy</category></item><item><title>Polish Water ICS Breaches: Attackers Alter Operational Parameters</title><link>https://runtimerebel.com/blog/polish-water-ics-breaches-attackers-alter-operational-parameters</link><guid isPermaLink="true">https://runtimerebel.com/blog/polish-water-ics-breaches-attackers-alter-operational-parameters</guid><description>Poland&apos;s ABW reports unauthorized access to five water treatment plants where attackers gained control over operational parameters, risking public safety.</description><pubDate>Fri, 08 May 2026 12:39:04 GMT</pubDate><category>ICS Security</category><category>Poland</category><category>Critical Infrastructure</category><category>OT Security</category><category>SCADA</category></item><item><title>AI-Driven Cyberattack Fails to Breach OT Systems via SCADA Login</title><link>https://runtimerebel.com/blog/ai-driven-cyberattack-fails-to-breach-ot-systems-via-scada-login</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-cyberattack-fails-to-breach-ot-systems-via-scada-login</guid><description>Analysis of the first AI-driven cyberattack targeting OT. Despite advanced automation, the campaign failed to bypass standard SCADA login interfaces.</description><pubDate>Thu, 07 May 2026 16:43:36 GMT</pubDate><category>AI Driven Attack</category><category>ICS Security</category><category>SCADA</category><category>OT Defense</category><category>Automation</category></item><item><title>Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks</title><link>https://runtimerebel.com/blog/microsoft-edge-plaintext-password-exposure-and-ics-zero-day-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-edge-plaintext-password-exposure-and-ics-zero-day-risks</guid><description>Analysis of Microsoft Edge plaintext password storage risks, newly disclosed ICS zero-day vulnerabilities, and Telegram-based data exfiltration TTPs.</description><pubDate>Thu, 07 May 2026 12:46:01 GMT</pubDate><category>Microsoft Edge</category><category>ICS Security</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>Zero-Day</category></item><item><title>Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion</title><link>https://runtimerebel.com/blog/claude-ai-guided-hackers-toward-ot-assets-during-water-utility-intrusion</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-ai-guided-hackers-toward-ot-assets-during-water-utility-intrusion</guid><description>Threat actors utilized Anthropic’s Claude AI to navigate OT environments during a water utility breach, highlighting the rising risk of AI-assisted ICS attacks.</description><pubDate>Thu, 07 May 2026 08:59:57 GMT</pubDate><category>Claude AI</category><category>OT Security</category><category>Water Utility Breach</category><category>ICS Security</category><category>Dragos</category></item><item><title>CVE-2026-3893: Unauthenticated Access in Carlson VASCO-B GNSS Receiver</title><link>https://runtimerebel.com/blog/cve-2026-3893-unauthenticated-access-in-carlson-vasco-b-gnss-receiver</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3893-unauthenticated-access-in-carlson-vasco-b-gnss-receiver</guid><description>Critical CVE-2026-3893 in Carlson VASCO-B GNSS Receivers &lt;1.4.0 allows unauthenticated remote alteration of critical system functions. Update to v1.4.0+.</description><pubDate>Thu, 23 Apr 2026 20:26:34 GMT</pubDate><category>CVE-2026-3893</category><category>Carlson Software</category><category>VASCO B GNSS Receiver</category><category>Critical Manufacturing</category><category>Missing Authentication</category><category>ICS Security</category></item><item><title>ZionSiphon Malware Targets Israeli Water Treatment ICS</title><link>https://runtimerebel.com/blog/zionsiphon-malware-targets-israeli-water-treatment-ics</link><guid isPermaLink="true">https://runtimerebel.com/blog/zionsiphon-malware-targets-israeli-water-treatment-ics</guid><description>Security analysis of ZionSiphon, a backdoor malware targeting Israeli desalination and water treatment facilities via ICS vulnerabilities.</description><pubDate>Fri, 17 Apr 2026 08:43:29 GMT</pubDate><category>ZionSiphon</category><category>ICS Security</category><category>Water Infrastructure</category><category>Cyber Av3ngers</category><category>Israel</category></item><item><title>Analyzing ZionSiphon: Malware Targeting Water Treatment OT Systems</title><link>https://runtimerebel.com/blog/analyzing-zionsiphon-malware-targeting-water-treatment-ot-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/analyzing-zionsiphon-malware-targeting-water-treatment-ot-systems</guid><description>Investigate ZionSiphon malware, an OT-specific threat designed to sabotage water treatment and desalination facilities.</description><pubDate>Fri, 17 Apr 2026 00:44:40 GMT</pubDate><category>ZionSiphon</category><category>OT Security</category><category>ICS Security</category><category>Water Treatment</category><category>Critical Infrastructure</category><category>Sabotage</category></item><item><title>OT Cryptographic Readiness: Addressing the PQC Attestation Gap</title><link>https://runtimerebel.com/blog/ot-cryptographic-readiness-addressing-the-pqc-attestation-gap</link><guid isPermaLink="true">https://runtimerebel.com/blog/ot-cryptographic-readiness-addressing-the-pqc-attestation-gap</guid><description>OT asset owners struggle to meet regulatory PQC attestation requirements due to a lack of visibility tools, creating a false sense of security in ICS environments.</description><pubDate>Mon, 13 Apr 2026 20:26:06 GMT</pubDate><category>ICS Security</category><category>OT Security</category><category>Post Quantum Cryptography</category><category>Compliance</category><category>PQC</category></item><item><title>CVE-2026-4436: High-Severity Flaw in GPL Odorizers GPL750</title><link>https://runtimerebel.com/blog/cve-2026-4436-high-severity-flaw-in-gpl-odorizers-gpl750</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-4436-high-severity-flaw-in-gpl-odorizers-gpl750</guid><description>High-severity vulnerability CVE-2026-4436 in GPL Odorizers GPL750 allows remote attackers to manipulate gas odorant levels. Learn how to patch affected systems.</description><pubDate>Fri, 10 Apr 2026 08:43:09 GMT</pubDate><category>CVE-2026-4436</category><category>GPL Odorizers</category><category>ICS Security</category><category>Modbus</category><category>CWE-306</category></item><item><title>Siemens SICAM 8 CPCI85 and RTUM85 DoS Vulnerabilities: Patch Guide</title><link>https://runtimerebel.com/blog/siemens-sicam-8-cpci85-and-rtum85-dos-vulnerabilities-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-sicam-8-cpci85-and-rtum85-dos-vulnerabilities-patch-guide</guid><description>Siemens issued an advisory for SICAM 8 products fixing vulnerabilities in CPCI85 and RTUM85 that could cause system crashes in critical infrastructure.</description><pubDate>Fri, 03 Apr 2026 08:26:50 GMT</pubDate><category>Siemens</category><category>SICAM 8</category><category>CVE-2026-27663</category><category>CVE-2026-27664</category><category>ICS Security</category><category>Denial of Service</category></item><item><title>Iranian Hacktivists Target Infrastructure: Reality vs. Rhetoric</title><link>https://runtimerebel.com/blog/iranian-hacktivists-target-infrastructure-reality-vs-rhetoric</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-hacktivists-target-infrastructure-reality-vs-rhetoric</guid><description>Analysis of Iran-aligned hacktivist groups, their limited technical impact on Gulf infrastructure, and the role of psychological operations in cyber warfare.</description><pubDate>Wed, 25 Mar 2026 08:21:20 GMT</pubDate><category>Iran Hacktivism</category><category>Cyber Av3ngers</category><category>Handala</category><category>Gulf Region</category><category>ICS Security</category></item><item><title>Siemens RUGGEDCOM APE1808 Critical Authentication Bypass — Patch Now</title><link>https://runtimerebel.com/blog/siemens-ruggedcom-ape1808-critical-authentication-bypass-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-ruggedcom-ape1808-critical-authentication-bypass-patch-now</guid><description>Security alert for Siemens RUGGEDCOM APE1808. Multiple vulnerabilities, including a 9.8 CVSS authentication bypass, affect ICS environments. Patch immediately.</description><pubDate>Thu, 12 Mar 2026 20:16:11 GMT</pubDate><category>CVE-2026-24858</category><category>Siemens</category><category>RUGGEDCOM</category><category>Fortinet</category><category>Industrial Control Systems</category><category>ICS Security</category></item><item><title>Siemens SIDIS Prime Vulnerabilities: Analysis and Patch Guidance</title><link>https://runtimerebel.com/blog/siemens-sidis-prime-vulnerabilities-analysis-and-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-sidis-prime-vulnerabilities-analysis-and-patch-guidance</guid><description>Siemens SIDIS Prime before V4.0.800 faces 23 vulnerabilities, including RCE and DoS. Learn how to mitigate these risks in critical manufacturing environments.</description><pubDate>Thu, 12 Mar 2026 20:15:39 GMT</pubDate><category>Siemens</category><category>SIDIS Prime</category><category>CVE-2024-29857</category><category>CVE-2025-64756</category><category>ICS Security</category></item><item><title>Hikvision and Rockwell Automation CVEs: CISA KEV Mitigation Guide</title><link>https://runtimerebel.com/blog/hikvision-and-rockwell-automation-cves-cisa-kev-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/hikvision-and-rockwell-automation-cves-cisa-kev-mitigation-guide</guid><description>CISA adds Hikvision CVE-2017-7921 and Rockwell Automation flaws to the KEV catalog. Learn how to detect and mitigate these critical CVSS 9.8 vulnerabilities.</description><pubDate>Fri, 06 Mar 2026 08:14:58 GMT</pubDate><category>CVE-2017-7921</category><category>Hikvision</category><category>Rockwell Automation</category><category>CISA KEV</category><category>ICS Security</category></item><item><title>Hitachi Energy RTU500 CMU Firmware Vulnerabilities: Patch Guidance</title><link>https://runtimerebel.com/blog/hitachi-energy-rtu500-cmu-firmware-vulnerabilities-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/hitachi-energy-rtu500-cmu-firmware-vulnerabilities-patch-guidance</guid><description>Hitachi Energy issues critical patches for RTU500 series CMU firmware addressing high-severity DoS and information disclosure risks (CVE-2026-1773, CVE-2024-8176).</description><pubDate>Wed, 04 Mar 2026 04:37:17 GMT</pubDate><category>CVE-2026-1773</category><category>CVE-2024-8176</category><category>Hitachi Energy</category><category>RTU500</category><category>ICS Security</category></item><item><title>Mobiliti e-mobi.hu EV Chargers: Critical Auth Bypass &amp; DoS Vulnerabilities</title><link>https://runtimerebel.com/blog/mobiliti-e-mobi-hu-ev-chargers-critical-auth-bypass-dos-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/mobiliti-e-mobi-hu-ev-chargers-critical-auth-bypass-dos-vulnerabilities</guid><description>Critical vulnerabilities in Mobiliti e-mobi.hu EV charging stations (all versions) allow unauthenticated attackers to gain administrative control or disrupt services.</description><pubDate>Tue, 03 Mar 2026 20:14:21 GMT</pubDate><category>CVE-2026-26051</category><category>CVE-2026-20882</category><category>CVE-2026-27764</category><category>CVE-2026-27777</category><category>Mobiliti E Mobi Hu</category><category>EV Charging</category><category>ICS Security</category><category>OT Security</category><category>Energy Sector</category><category>Transportation Systems</category><category>Missing Authentication</category><category>Denial of Service</category></item><item><title>Honeywell IQ4 Vulnerability: Assessing Internet Exposure &amp; Impact</title><link>https://runtimerebel.com/blog/honeywell-iq4-vulnerability-assessing-internet-exposure-impact</link><guid isPermaLink="true">https://runtimerebel.com/blog/honeywell-iq4-vulnerability-assessing-internet-exposure-impact</guid><description>A researcher claims thousands of internet-exposed Honeywell IQ4 building controllers are vulnerable. Understand the potential impact and mitigation strategies.</description><pubDate>Tue, 03 Mar 2026 16:24:11 GMT</pubDate><category>Honeywell IQ4</category><category>Building Management Systems</category><category>ICS Security</category><category>OT Security</category><category>SCADA</category></item></channel></rss>