<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #ICS</title><description>Cybersecurity articles tagged #ICS on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI-Assisted PLC Exploit Porting: WAGO RCE via Claude</title><link>https://runtimerebel.com/blog/ai-assisted-plc-exploit-porting-wago-rce-via-claude</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-plc-exploit-porting-wago-rce-via-claude</guid><description>Forescout researchers used Anthropic&apos;s Claude to port a WAGO PLC RCE exploit, demonstrating AI&apos;s potential in offensive security but highlighting current challenges.</description><pubDate>Tue, 01 Sep 2026 12:56:06 GMT</pubDate><category>Industrial Control Systems</category><category>ICS</category><category>AI</category><category>Exploit Development</category><category>Anthropic Claude</category></item><item><title>Multistate Water System Attacks Target Exposed PLCs</title><link>https://runtimerebel.com/blog/multistate-water-system-attacks-target-exposed-plcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/multistate-water-system-attacks-target-exposed-plcs</guid><description>Attacks targeting poorly secured, internet-exposed PLCs in water systems are widening across multiple U.S. states, with Iran suspected.</description><pubDate>Tue, 11 Aug 2026 08:46:26 GMT</pubDate><category>ICS</category><category>OT Security</category><category>Critical Infrastructure</category><category>Iran</category><category>Water Utilities</category></item><item><title>Coordinated OT Attack Targets 30+ Minnesota Water Utilities</title><link>https://runtimerebel.com/blog/coordinated-ot-attack-targets-30-minnesota-water-utilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/coordinated-ot-attack-targets-30-minnesota-water-utilities</guid><description>Over 30 Minnesota water utilities were targeted in a coordinated cyberattack on operational technology, prompting a statewide incident response and investigation.</description><pubDate>Wed, 29 Jul 2026 17:17:22 GMT</pubDate><category>OT Security</category><category>Critical Infrastructure</category><category>Minnesota</category><category>ICS</category><category>Water Utility</category></item><item><title>CVE-2024-2821: Critical RCE in Daktronics Controllers — Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-2821-critical-rce-in-daktronics-controllers-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-2821-critical-rce-in-daktronics-controllers-patch-now</guid><description>Critical vulnerabilities (CVE-2024-2821, CVE-2024-2822, CVE-2024-2823) in Daktronics Venus 1500 and Vanguard controllers allow remote hacking of highway signs and…</description><pubDate>Tue, 30 Jun 2026 05:28:50 GMT</pubDate><category>Daktronics</category><category>CVE-2024-2821</category><category>CVE-2024-2822</category><category>CVE-2024-2823</category><category>ICS</category><category>SCADA</category><category>IoT</category><category>Improper Authentication</category><category>Remote Hacking</category><category>Critical Infrastructure</category></item><item><title>Rockwell RSLinx &lt;4.50.00 RCE via CVE-2020-13573 — Patch Now</title><link>https://runtimerebel.com/blog/rockwell-rslinx-4-50-00-rce-via-cve-2020-13573-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/rockwell-rslinx-4-50-00-rce-via-cve-2020-13573-patch-now</guid><description>Urgent advisory for Rockwell RSLinx Classic users. CVE-2020-13573, a stack-based buffer overflow, enables remote code execution and DoS. Patch &lt;=4.50.00.</description><pubDate>Thu, 18 Jun 2026 09:58:04 GMT</pubDate><category>Rockwell Automation</category><category>RSLinx Classic</category><category>CVE-2020-13573</category><category>Buffer Overflow</category><category>RCE</category><category>Denial of Service</category><category>ICS</category><category>Critical Manufacturing</category><category>Energy</category></item><item><title>CVE-2026-11317: Rockwell Logix DoS via CIP — Patch Critical ICS</title><link>https://runtimerebel.com/blog/cve-2026-11317-rockwell-logix-dos-via-cip-patch-critical-ics</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-11317-rockwell-logix-dos-via-cip-patch-critical-ics</guid><description>Critical Manufacturing faces high-severity DoS risk in Rockwell Automation Logix 5370 &amp; 5570 controllers from CVE-2026-11317. Patch now.</description><pubDate>Thu, 18 Jun 2026 09:57:33 GMT</pubDate><category>CVE-2026-11317</category><category>Rockwell Automation</category><category>Logix 5370</category><category>Logix 5570</category><category>CompactLogix</category><category>ControlLogix</category><category>GuardLogix</category><category>Denial of Service</category><category>ICS</category><category>Critical Manufacturing</category><category>CIP</category></item><item><title>ICS Exposure Persists as OT Attack Surface Expands</title><link>https://runtimerebel.com/blog/ics-exposure-persists-as-ot-attack-surface-expands</link><guid isPermaLink="true">https://runtimerebel.com/blog/ics-exposure-persists-as-ot-attack-surface-expands</guid><description>Analysis of Industrial Control System (ICS) exposure, its persistence amidst expanding attack surfaces, and vital steps for operational technology security.</description><pubDate>Sat, 13 Jun 2026 01:04:32 GMT</pubDate><category>ICS</category><category>OT Security</category><category>Critical Infrastructure</category><category>Attack Surface</category></item><item><title>Siemens KACO Blueplanet Inverter Vulnerabilities: CVE-2025-40946 &amp; CVE-2026-41125</title><link>https://runtimerebel.com/blog/siemens-kaco-blueplanet-inverter-vulnerabilities-cve-2025-40946-cve-2026-41125</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-kaco-blueplanet-inverter-vulnerabilities-cve-2025-40946-cve-2026-41125</guid><description>Critical Siemens KACO Blueplanet Inverters are vulnerable to credential derivation (CVE-2025-40946) and SQL injection (CVE-2026-41125).</description><pubDate>Tue, 09 Jun 2026 17:02:56 GMT</pubDate><category>Siemens</category><category>KACO Blueplanet Inverters</category><category>ICS</category><category>Energy Sector</category><category>CVE-2025-40946</category><category>CVE-2026-41125</category><category>Hard Coded Key</category><category>SQL Injection</category><category>Operational Technology</category></item><item><title>Hitachi Energy MACH HiDraw RCE via CVE-2026-7310 — Patch Guide</title><link>https://runtimerebel.com/blog/hitachi-energy-mach-hidraw-rce-via-cve-2026-7310-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/hitachi-energy-mach-hidraw-rce-via-cve-2026-7310-patch-guide</guid><description>Hitachi Energy addresses a heap-based buffer overflow in MACH HiDraw version 9.22. Learn how to mitigate CVE-2026-7310 and protect critical ICS assets.</description><pubDate>Thu, 04 Jun 2026 17:11:13 GMT</pubDate><category>Hitachi Energy</category><category>MACH HiDraw</category><category>CVE-2026-7310</category><category>ICS</category><category>Buffer Overflow</category></item><item><title>CVE-2026-6332: Schneider Electric EcoStruxure HVAC Source Code Disclosure</title><link>https://runtimerebel.com/blog/cve-2026-6332-schneider-electric-ecostruxure-hvac-source-code-disclosure</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-6332-schneider-electric-ecostruxure-hvac-source-code-disclosure</guid><description>A cleartext storage vulnerability in Schneider Electric EcoStruxure Machine Expert HVAC (CVE-2026-6332) exposes sensitive source code. Update to v1.10.0.</description><pubDate>Thu, 28 May 2026 17:27:39 GMT</pubDate><category>CVE-2026-6332</category><category>Schneider Electric</category><category>EcoStruxure Machine Expert HVAC</category><category>ICS</category><category>SCADA</category><category>CWE-312</category><category>Source Code Disclosure</category><category>OT</category></item><item><title>CVE-2021-22291: ABB EIBPORT V3 &lt;3.9.2 Session Hijacking Vulnerability</title><link>https://runtimerebel.com/blog/cve-2021-22291-abb-eibport-v3-3-9-2-session-hijacking-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2021-22291-abb-eibport-v3-3-9-2-session-hijacking-vulnerability</guid><description>ABB EIBPORT V3 devices are vulnerable to CVE-2021-22291 (XSS/session hijacking), allowing unauthenticated access and configuration changes. Patch immediately.</description><pubDate>Thu, 28 May 2026 17:27:09 GMT</pubDate><category>CVE-2021-22291</category><category>ABB EIBPORT</category><category>XSS</category><category>Session Hijacking</category><category>ICS</category><category>Building Automation</category><category>Critical Manufacturing</category></item><item><title>CVE-2026-7251: Hard-coded Password in Eppendorf BioFlo 320</title><link>https://runtimerebel.com/blog/cve-2026-7251-hard-coded-password-in-eppendorf-bioflo-320</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-7251-hard-coded-password-in-eppendorf-bioflo-320</guid><description>Critical hard-coded password vulnerability (CVE-2026-7251) in Eppendorf BioFlo 320 bioreactors allows full remote control. Patch immediately.</description><pubDate>Tue, 26 May 2026 20:49:09 GMT</pubDate><category>CVE-2026-7251</category><category>Eppendorf BioFlo 320</category><category>Hard Coded Password</category><category>VNC</category><category>Healthcare</category><category>ICS</category><category>Bioreactor</category></item><item><title>ABB B&amp;R Automation Studio &lt;6.5: Multiple Critical SQLite Vulnerabilities</title><link>https://runtimerebel.com/blog/abb-b-r-automation-studio-6-5-multiple-critical-sqlite-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/abb-b-r-automation-studio-6-5-multiple-critical-sqlite-vulnerabilities</guid><description>Critical SQLite vulnerabilities in ABB B&amp;R Automation Studio &lt;6.5 expose ICS to RCE, data exposure, and unauthorized access. Update to version 6.5 immediately.</description><pubDate>Sat, 23 May 2026 00:56:27 GMT</pubDate><category>ABB</category><category>B R Automation Studio</category><category>SQLite</category><category>ICS</category><category>OT</category><category>CVE-2025-6965</category><category>CVE-2025-3277</category><category>CVE-2019-19646</category><category>CVE-2019-8457</category><category>CVE-2017-10989</category><category>RCE</category><category>Buffer Overflow</category><category>Memory Corruption</category><category>Zero Trust</category></item><item><title>CVE-2022-4304: Hitachi Energy GMS600 Timing Side Channel Vulnerability</title><link>https://runtimerebel.com/blog/cve-2022-4304-hitachi-energy-gms600-timing-side-channel-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2022-4304-hitachi-energy-gms600-timing-side-channel-vulnerability</guid><description>Hitachi Energy GMS600 versions 1.3.0-1.3.1 affected by CVE-2022-4304, an OpenSSL timing side channel leading to TLS decryption. Patch to 1.3.2 now.</description><pubDate>Thu, 21 May 2026 20:43:48 GMT</pubDate><category>CVE-2022-4304</category><category>Hitachi Energy GMS600</category><category>OpenSSL</category><category>Timing Side Channel</category><category>Critical Manufacturing</category><category>ICS</category><category>CWE-203</category></item><item><title>OT Robot OS Command Injection: Unauthenticated RCE — Patch Now</title><link>https://runtimerebel.com/blog/ot-robot-os-command-injection-unauthenticated-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/ot-robot-os-command-injection-unauthenticated-rce-patch-now</guid><description>Critical command injection vulnerability in OT Robot OS allows unauthenticated attackers to gain remote control, posing significant disruption risks to industrial…</description><pubDate>Wed, 20 May 2026 17:14:09 GMT</pubDate><category>OT Robot OS</category><category>Command Injection</category><category>Industrial Control Systems</category><category>Robotics</category><category>RCE</category><category>Operational Technology</category><category>ICS</category></item><item><title>CVE-2026-4293: Kieback &amp; Peter DDC XSS — Mitigate Building Controller Risks</title><link>https://runtimerebel.com/blog/cve-2026-4293-kieback-peter-ddc-xss-mitigate-building-controller-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-4293-kieback-peter-ddc-xss-mitigate-building-controller-risks</guid><description>CISA warns of CVE-2026-4293, a Cross-site Scripting vulnerability in Kieback &amp; Peter DDC Building Controllers.</description><pubDate>Tue, 19 May 2026 20:43:11 GMT</pubDate><category>Kieback Peter</category><category>DDC Building Controllers</category><category>CVE-2026-4293</category><category>XSS</category><category>Cross Site Scripting</category><category>ICS</category><category>OT Security</category><category>Building Automation</category><category>CWE-79</category></item><item><title>CVE-2026-40175: Siemens gWAP RCE via Axios Prototype Pollution</title><link>https://runtimerebel.com/blog/cve-2026-40175-siemens-gwap-rce-via-axios-prototype-pollution</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-40175-siemens-gwap-rce-via-axios-prototype-pollution</guid><description>Siemens gWAP is vulnerable to RCE via CVE-2026-40175, a prototype pollution flaw in the Axios HTTP client library. Update to v3.1.1 or later.</description><pubDate>Thu, 14 May 2026 20:40:58 GMT</pubDate><category>CVE-2026-40175</category><category>Siemens gWAP</category><category>Axios</category><category>RCE</category><category>Prototype Pollution</category><category>Critical Manufacturing</category><category>ICS</category></item><item><title>CVE-2026-6411: MAXHUB Pivot Client Hardcoded AES Key — Patch Guide</title><link>https://runtimerebel.com/blog/cve-2026-6411-maxhub-pivot-client-hardcoded-aes-key-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-6411-maxhub-pivot-client-hardcoded-aes-key-patch-guide</guid><description>Exploit analysis of CVE-2026-6411 in MAXHUB Pivot client. Learn how hardcoded AES keys and MQTT enrollment flaws lead to data disclosure and DoS.</description><pubDate>Fri, 08 May 2026 08:40:11 GMT</pubDate><category>CVE-2026-6411</category><category>MAXHUB</category><category>Cryptographic Failure</category><category>MQTT</category><category>ICS</category></item><item><title>ABB B&amp;R Automation Runtime DoS via CVE-2025-11044 — Patch Now</title><link>https://runtimerebel.com/blog/abb-b-r-automation-runtime-dos-via-cve-2025-11044-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/abb-b-r-automation-runtime-dos-via-cve-2025-11044-patch-now</guid><description>An unauthenticated network DoS vulnerability (CVE-2025-11044) affects ABB B&amp;R Automation Runtime, allowing permanent system halts. Immediate patching is critical.</description><pubDate>Wed, 06 May 2026 00:49:26 GMT</pubDate><category>CVE-2025-11044</category><category>ABB</category><category>B R Automation Runtime</category><category>ICS</category><category>DoS</category><category>CWE-770</category><category>Critical Manufacturing</category></item><item><title>CVE-2025-11043: ABB Automation Studio &lt;6.5 Improper Certificate Validation</title><link>https://runtimerebel.com/blog/cve-2025-11043-abb-automation-studio-6-5-improper-certificate-validation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-11043-abb-automation-studio-6-5-improper-certificate-validation</guid><description>Critical manufacturing systems running ABB B&amp;R Automation Studio &lt;6.5 are vulnerable to CVE-2025-11043, allowing data interception and spoofing via improper certificate…</description><pubDate>Wed, 06 May 2026 00:48:57 GMT</pubDate><category>CVE-2025-11043</category><category>ABB B R Automation Studio</category><category>Improper Certificate Validation</category><category>Critical Manufacturing</category><category>ICS</category><category>OPC UA</category><category>ANSL Over TLS</category></item><item><title>CVE-2025-14510: ABB Ability OPTIMAX Azure AD SSO Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2025-14510-abb-ability-optimax-azure-ad-sso-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-14510-abb-ability-optimax-azure-ad-sso-auth-bypass</guid><description>CISA warns of CVE-2025-14510 impacting ABB Ability OPTIMAX, allowing authentication bypass on Azure AD SSO integrations. Patch immediately.</description><pubDate>Fri, 01 May 2026 00:56:01 GMT</pubDate><category>CVE-2025-14510</category><category>ABB Ability OPTIMAX</category><category>Authentication Bypass</category><category>Azure Active Directory SSO</category><category>ICS</category><category>SCADA</category><category>Energy Sector</category><category>Water and Wastewater</category></item><item><title>ABB AWIN Gateways Authentication Bypass and DoS Vulnerabilities</title><link>https://runtimerebel.com/blog/abb-awin-gateways-authentication-bypass-and-dos-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/abb-awin-gateways-authentication-bypass-and-dos-vulnerabilities</guid><description>Critical vulnerabilities in ABB AWIN GW100 and GW120 gateways could allow unauthenticated attackers to reboot devices or extract sensitive configuration data.</description><pubDate>Thu, 30 Apr 2026 16:41:24 GMT</pubDate><category>CVE-2025-13777</category><category>CVE-2025-13778</category><category>CVE-2025-13779</category><category>ABB</category><category>ICS</category><category>Manufacturing</category></item><item><title>ABB Symphony Plus Engineering: Fix PostgreSQL RCE Vulnerabilities</title><link>https://runtimerebel.com/blog/abb-symphony-plus-engineering-fix-postgresql-rce-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/abb-symphony-plus-engineering-fix-postgresql-rce-vulnerabilities</guid><description>ABB Ability Symphony Plus Engineering is vulnerable to RCE via legacy PostgreSQL components. Learn how to mitigate CVE-2024-7348 and secure ICS networks.</description><pubDate>Thu, 30 Apr 2026 16:40:58 GMT</pubDate><category>ABB</category><category>Postgresql</category><category>ICS</category><category>CVE-2023-5869</category><category>CVE-2024-7348</category><category>RCE</category><category>Critical Infrastructure</category></item><item><title>NSA GRASSMARLIN XXE Vulnerability CVE-2026-6807 — Mitigation Guide</title><link>https://runtimerebel.com/blog/nsa-grassmarlin-xxe-vulnerability-cve-2026-6807-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/nsa-grassmarlin-xxe-vulnerability-cve-2026-6807-mitigation-guide</guid><description>CISA warns of a Medium-severity XXE vulnerability in NSA GRASSMARLIN. With the tool reaching end-of-life, defenders must address CVE-2026-6807 via decommissioning.</description><pubDate>Wed, 29 Apr 2026 08:55:03 GMT</pubDate><category>CVE-2026-6807</category><category>NSA</category><category>GRASSMARLIN</category><category>ICS</category><category>XXE</category><category>CWE-611</category></item><item><title>CVE-2025-65856: Authentication Bypass in Xiongmai XM530 IP Cameras</title><link>https://runtimerebel.com/blog/cve-2025-65856-authentication-bypass-in-xiongmai-xm530-ip-cameras</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-65856-authentication-bypass-in-xiongmai-xm530-ip-cameras</guid><description>Critical authentication bypass (CVE-2025-65856) in Xiongmai XM530 IP Camera firmware allows unauthenticated remote access to video streams and sensitive data.</description><pubDate>Thu, 23 Apr 2026 20:27:17 GMT</pubDate><category>CVE-2025-65856</category><category>Xiongmai</category><category>XM530 IP Camera</category><category>Authentication Bypass</category><category>ONVIF</category><category>ICS</category><category>CWE-306</category></item><item><title>CVE-2026-27668: Privilege Escalation in Siemens RUGGEDCOM CROSSBOW</title><link>https://runtimerebel.com/blog/cve-2026-27668-privilege-escalation-in-siemens-ruggedcom-crossbow</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-27668-privilege-escalation-in-siemens-ruggedcom-crossbow</guid><description>Authenticated User Administrators can escalate privileges in Siemens RUGGEDCOM CROSSBOW SAM-P versions prior to 5.8. Update to mitigate CVE-2026-27668 risks.</description><pubDate>Wed, 22 Apr 2026 08:45:24 GMT</pubDate><category>CVE-2026-27668</category><category>Siemens</category><category>RUGGEDCOM</category><category>Privilege Escalation</category><category>ICS</category></item><item><title>Silex SD-330AC and AMC Manager RCE via CVE-2026-32956 — Patch Now</title><link>https://runtimerebel.com/blog/silex-sd-330ac-and-amc-manager-rce-via-cve-2026-32956-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/silex-sd-330ac-and-amc-manager-rce-via-cve-2026-32956-patch-now</guid><description>Silex Technology devices face critical RCE and DoS risks via 13 vulnerabilities. Critical infrastructure defenders must update to firmware Ver 1.50 immediately.</description><pubDate>Wed, 22 Apr 2026 08:45:02 GMT</pubDate><category>Silex Technology</category><category>CVE-2026-32956</category><category>SD 330AC</category><category>AMC Manager</category><category>ICS</category><category>RCE</category></item><item><title>Securing Serial-to-IP Devices: Mitigating Thousands of OT Bugs</title><link>https://runtimerebel.com/blog/securing-serial-to-ip-devices-mitigating-thousands-of-ot-bugs</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-serial-to-ip-devices-mitigating-thousands-of-ot-bugs</guid><description>Industrial serial-to-IP converters are riddled with thousands of vulnerabilities, posing a significant risk to legacy infrastructure and OT environments.</description><pubDate>Mon, 20 Apr 2026 20:19:45 GMT</pubDate><category>OT Security</category><category>ICS</category><category>Serial to IP</category><category>Industrial Networking</category><category>Legacy Systems</category></item><item><title>CVE-2026-5387: AVEVA Pipeline Simulation Privilege Escalation</title><link>https://runtimerebel.com/blog/cve-2026-5387-aveva-pipeline-simulation-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-5387-aveva-pipeline-simulation-privilege-escalation</guid><description>Unauthenticated attackers can exploit CVE-2026-5387 in AVEVA Pipeline Simulation &lt;=2025_SP1_build_7.1.9497.6351 to modify critical ICS simulation parameters and training…</description><pubDate>Fri, 17 Apr 2026 05:05:22 GMT</pubDate><category>CVE-2026-5387</category><category>AVEVA</category><category>Pipeline Simulation</category><category>ICS</category><category>Critical Manufacturing</category><category>Missing Authorization</category><category>Privilege Escalation</category></item><item><title>ICS Patch Tuesday: 8 Industrial Giants Patch Critical Vulnerabilities</title><link>https://runtimerebel.com/blog/ics-patch-tuesday-8-industrial-giants-patch-critical-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/ics-patch-tuesday-8-industrial-giants-patch-critical-vulnerabilities</guid><description>Analysis of new security advisories from Siemens, Schneider Electric, and others regarding critical infrastructure vulnerabilities and remediation steps.</description><pubDate>Wed, 15 Apr 2026 08:40:53 GMT</pubDate><category>ICS</category><category>Siemens</category><category>Schneider Electric</category><category>CVE-2024-22061</category><category>Rockwell Automation</category></item><item><title>Iranian Actors Target Rockwell PLCs: 4,000 US Devices Exposed</title><link>https://runtimerebel.com/blog/iranian-actors-target-rockwell-plcs-4000-us-devices-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-actors-target-rockwell-plcs-4000-us-devices-exposed</guid><description>Iranian-linked cyber actors have identified nearly 4,000 exposed US industrial control systems, primarily Rockwell Automation PLCs, raising critical infrastructure…</description><pubDate>Fri, 10 Apr 2026 16:24:02 GMT</pubDate><category>Iran</category><category>Rockwell Automation</category><category>PLC</category><category>ICS</category><category>Critical Infrastructure</category><category>Cyberattacks</category><category>Exposure</category></item><item><title>CVE-2025-13926: Critical Flaw in Contemporary Controls BASC 20T</title><link>https://runtimerebel.com/blog/cve-2025-13926-critical-flaw-in-contemporary-controls-basc-20t</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-13926-critical-flaw-in-contemporary-controls-basc-20t</guid><description>CISA warns of a CVSS 9.8 vulnerability in Contemporary Controls BASControl20 3.1. Attackers can forge packets to reconfigure or delete PLC components.</description><pubDate>Fri, 10 Apr 2026 08:41:43 GMT</pubDate><category>CVE-2025-13926</category><category>Contemporary Controls</category><category>ICS</category><category>PLC</category><category>CWE-807</category></item><item><title>Iran-Linked Cyber Attacks Persist Despite Israel-Hezbollah Ceasefire</title><link>https://runtimerebel.com/blog/iran-linked-cyber-attacks-persist-despite-israel-hezbollah-ceasefire</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-linked-cyber-attacks-persist-despite-israel-hezbollah-ceasefire</guid><description>Iran-affiliated threat actors maintain operational tempo against US critical infrastructure, disregarding kinetic pauses in Middle East regional conflicts.</description><pubDate>Thu, 09 Apr 2026 04:52:31 GMT</pubDate><category>Iran</category><category>IRGC</category><category>Critical Infrastructure</category><category>Cyber Av3ngers</category><category>ICS</category></item><item><title>Iranian Hackers Targeting U.S. Critical Infrastructure via PLCs</title><link>https://runtimerebel.com/blog/iranian-hackers-targeting-u-s-critical-infrastructure-via-plcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-hackers-targeting-u-s-critical-infrastructure-via-plcs</guid><description>U.S. agencies warn of Iran-linked hackers disrupting critical infrastructure by exploiting internet-exposed PLCs to manipulate data and halt operations.</description><pubDate>Wed, 08 Apr 2026 08:32:44 GMT</pubDate><category>PLC Security</category><category>Critical Infrastructure</category><category>OT Security</category><category>Iran Affiliated Hackers</category><category>ICS</category></item><item><title>Mitsubishi Electric ICS Vulnerabilities Expose SQL Credentials</title><link>https://runtimerebel.com/blog/mitsubishi-electric-ics-vulnerabilities-expose-sql-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitsubishi-electric-ics-vulnerabilities-expose-sql-credentials</guid><description>High-severity vulnerabilities (CVE-2025-14815, CVE-2025-14816) in Mitsubishi Electric ICS/SCADA products risk SQL credential exposure and data compromise.</description><pubDate>Tue, 07 Apr 2026 16:31:20 GMT</pubDate><category>CVE-2025-14815</category><category>CVE-2025-14816</category><category>Mitsubishi Electric</category><category>GENESIS64</category><category>ICONICS Suite</category><category>ICS</category><category>SCADA</category><category>Cleartext Storage</category><category>Critical Manufacturing</category><category>SQL Server</category></item><item><title>Ivanti Connect Secure RCE: Internal Network Vulnerability Detection</title><link>https://runtimerebel.com/blog/ivanti-connect-secure-rce-internal-network-vulnerability-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-connect-secure-rce-internal-network-vulnerability-detection</guid><description>Analyze the impact of Ivanti Connect Secure vulnerabilities and learn how to conduct internal network vulnerability scanning for Ivanti appliances to detect flaws.</description><pubDate>Fri, 03 Apr 2026 08:29:48 GMT</pubDate><category>Ivanti</category><category>CVE-2023-46805</category><category>CVE-2024-21887</category><category>ICS</category><category>RCE</category></item><item><title>Yokogawa CENTUM VP CVE-2025-7741 Hardcoded Password Patch Guidance</title><link>https://runtimerebel.com/blog/yokogawa-centum-vp-cve-2025-7741-hardcoded-password-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/yokogawa-centum-vp-cve-2025-7741-hardcoded-password-patch-guidance</guid><description>CISA identifies a hardcoded password in Yokogawa CENTUM VP (CVE-2025-7741). Learn how to secure the PROG account and apply the R7.01.10 patch now.</description><pubDate>Fri, 03 Apr 2026 08:28:20 GMT</pubDate><category>CVE-2025-7741</category><category>Yokogawa</category><category>CENTUM VP</category><category>ICS</category><category>CWE-259</category></item><item><title>CVE-2026-3356: Anritsu Remote Spectrum Monitor Authentication Bypass</title><link>https://runtimerebel.com/blog/cve-2026-3356-anritsu-remote-spectrum-monitor-authentication-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3356-anritsu-remote-spectrum-monitor-authentication-bypass</guid><description>Critical CVE-2026-3356 allows authentication bypass in Anritsu Remote Spectrum Monitors.</description><pubDate>Tue, 31 Mar 2026 20:19:02 GMT</pubDate><category>CVE-2026-3356</category><category>Anritsu</category><category>Remote Spectrum Monitor</category><category>MS27100A</category><category>MS27101A</category><category>MS27102A</category><category>MS27103A</category><category>Authentication Bypass</category><category>ICS</category><category>Critical Infrastructure</category></item><item><title>CVE-2026-3587: WAGO Switches CLI Escape Leads to Full Device Compromise</title><link>https://runtimerebel.com/blog/cve-2026-3587-wago-switches-cli-escape-leads-to-full-device-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3587-wago-switches-cli-escape-leads-to-full-device-compromise</guid><description>Critical flaw CVE-2026-3587 in WAGO Industrial Managed Switches allows unauthenticated remote attackers to fully compromise devices via CLI escape.</description><pubDate>Thu, 26 Mar 2026 16:39:32 GMT</pubDate><category>CVE-2026-3587</category><category>WAGO</category><category>Industrial Managed Switches</category><category>ICS</category><category>Operational Technology</category><category>Hidden Functionality</category><category>Unauthenticated Remote</category><category>Firmware Vulnerability</category></item><item><title>Schneider Electric Plant iT/Brewmaxx RCE via Multiple Redis Vulnerabilities</title><link>https://runtimerebel.com/blog/schneider-electric-plant-it-brewmaxx-rce-via-multiple-redis-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/schneider-electric-plant-it-brewmaxx-rce-via-multiple-redis-vulnerabilities</guid><description>Multiple critical and high-severity vulnerabilities in Schneider Electric Plant iT/Brewmaxx 9.60+ (Redis component) enable RCE and privilege escalation, affecting…</description><pubDate>Tue, 24 Mar 2026 20:21:08 GMT</pubDate><category>Schneider Electric</category><category>Plant iT Brewmaxx</category><category>Redis</category><category>RCE</category><category>Privilege Escalation</category><category>ICS</category><category>OT</category><category>CVE-2025-49844</category><category>CVE-2025-46817</category><category>CVE-2025-46818</category><category>CVE-2025-46819</category></item><item><title>CVE-2026-2417: Pharos Controls RCE via Missing Authentication</title><link>https://runtimerebel.com/blog/cve-2026-2417-pharos-controls-rce-via-missing-authentication</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-2417-pharos-controls-rce-via-missing-authentication</guid><description>Critical vulnerability (CVE-2026-2417) in Pharos Controls Mosaic Show Controller firmware 2.15.3 allows unauthenticated root RCE. Upgrade to 2.16+ immediately.</description><pubDate>Tue, 24 Mar 2026 20:20:34 GMT</pubDate><category>CVE-2026-2417</category><category>Pharos Controls</category><category>Mosaic Show Controller</category><category>ICS</category><category>RCE</category><category>Critical Infrastructure</category><category>CWE-306</category></item><item><title>CVE-2025-13902: Patching Schneider Electric Modicon Controllers</title><link>https://runtimerebel.com/blog/cve-2025-13902-patching-schneider-electric-modicon-controllers</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-13902-patching-schneider-electric-modicon-controllers</guid><description>Schneider Electric Modicon M241 and M251 controllers face XSS risks via CVE-2025-13902. Learn how to patch firmware and secure industrial control networks.</description><pubDate>Thu, 19 Mar 2026 16:26:40 GMT</pubDate><category>CVE-2025-13902</category><category>Schneider Electric</category><category>Modicon</category><category>ICS</category><category>XSS</category></item><item><title>CVE-2026-2273: Schneider Electric EcoStruxure Automation Expert RCE</title><link>https://runtimerebel.com/blog/cve-2026-2273-schneider-electric-ecostruxure-automation-expert-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-2273-schneider-electric-ecostruxure-automation-expert-rce</guid><description>Schneider Electric has addressed a high-severity code injection vulnerability (CVE-2026-2273) in EcoStruxure Automation Expert that risks full system compromise.</description><pubDate>Thu, 19 Mar 2026 16:26:18 GMT</pubDate><category>CVE-2026-2273</category><category>Schneider Electric</category><category>EcoStruxure</category><category>ICS</category><category>Code Injection</category></item><item><title>CVE-2025-13957: Hard-coded Credentials in Schneider EcoStruxure DCE</title><link>https://runtimerebel.com/blog/cve-2025-13957-hard-coded-credentials-in-schneider-ecostruxure-dce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-13957-hard-coded-credentials-in-schneider-ecostruxure-dce</guid><description>Hard-coded credentials in Schneider Electric EcoStruxure Data Center Expert v9.0 and prior (CVE-2025-13957) allow information disclosure and RCE if SOCKS Proxy is…</description><pubDate>Tue, 17 Mar 2026 20:17:31 GMT</pubDate><category>CVE-2025-13957</category><category>Schneider Electric</category><category>EcoStruxure IT Data Center Expert</category><category>Hard Coded Credentials</category><category>ICS</category><category>SCADA</category><category>Operational Technology</category></item><item><title>ICS Patch Tuesday: Siemens, Schneider, Moxa Fix Critical Flaws</title><link>https://runtimerebel.com/blog/ics-patch-tuesday-siemens-schneider-moxa-fix-critical-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/ics-patch-tuesday-siemens-schneider-moxa-fix-critical-flaws</guid><description>Industrial leaders Siemens, Schneider Electric, Moxa, and Mitsubishi Electric address over 40 vulnerabilities in critical ICS hardware and software components.</description><pubDate>Wed, 11 Mar 2026 08:17:11 GMT</pubDate><category>ICS</category><category>Siemens</category><category>Schneider Electric</category><category>Moxa</category><category>Mitsubishi Electric</category><category>Industrial Cybersecurity</category><category>CVE-2024-4203</category></item><item><title>CVE-2025-57176: Unauthenticated File Upload in Ceragon Siklu Devices</title><link>https://runtimerebel.com/blog/cve-2025-57176-unauthenticated-file-upload-in-ceragon-siklu-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-57176-unauthenticated-file-upload-in-ceragon-siklu-devices</guid><description>An unauthenticated file upload vulnerability (CVE-2025-57176) in Ceragon Siklu MultiHaul and EtherHaul series devices poses risks to critical communications…</description><pubDate>Tue, 10 Mar 2026 20:15:45 GMT</pubDate><category>CVE-2025-57176</category><category>Ceragon</category><category>Siklu</category><category>MultiHaul</category><category>EtherHaul</category><category>Unauthenticated File Upload</category><category>CWE-434</category><category>ICS</category><category>OT Security</category></item><item><title>CVE-2026-3611: Critical Auth Bypass in Honeywell IQ4x BMS Controllers</title><link>https://runtimerebel.com/blog/cve-2026-3611-critical-auth-bypass-in-honeywell-iq4x-bms-controllers</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3611-critical-auth-bypass-in-honeywell-iq4x-bms-controllers</guid><description>CISA warns of a critical authentication bypass (CVE-2026-3611) in Honeywell IQ4x BMS Controllers, allowing unauthenticated attackers administrative access and potential…</description><pubDate>Tue, 10 Mar 2026 20:15:15 GMT</pubDate><category>CVE-2026-3611</category><category>Honeywell IQ4x</category><category>BMS Controller</category><category>ICS</category><category>SCADA</category><category>Authentication Bypass</category><category>Critical Infrastructure</category><category>CWE-306</category></item><item><title>CVE-2026-3094: Delta CNCSoft-G2 Out-of-bounds Write RCE</title><link>https://runtimerebel.com/blog/cve-2026-3094-delta-cncsoft-g2-out-of-bounds-write-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3094-delta-cncsoft-g2-out-of-bounds-write-rce</guid><description>Delta Electronics CNCSoft-G2 is vulnerable to an out-of-bounds write (CVE-2026-3094) allowing remote code execution. Update to V2.1.0.39.</description><pubDate>Thu, 05 Mar 2026 20:17:47 GMT</pubDate><category>CVE-2026-3094</category><category>Delta Electronics</category><category>CNCSoft G2</category><category>ICS</category><category>OT</category><category>Critical Manufacturing</category><category>Out of Bounds Write</category><category>RCE</category></item><item><title>Multiple DoS/RCE Vulnerabilities in Yokogawa CENTUM VP R6, R7</title><link>https://runtimerebel.com/blog/multiple-dos-rce-vulnerabilities-in-yokogawa-centum-vp-r6-r7</link><guid isPermaLink="true">https://runtimerebel.com/blog/multiple-dos-rce-vulnerabilities-in-yokogawa-centum-vp-r6-r7</guid><description>CISA alerts to multiple medium-severity vulnerabilities in Yokogawa CENTUM VP R6 and R7, allowing DoS and RCE via crafted packets in critical infrastructure…</description><pubDate>Thu, 26 Feb 2026 20:16:44 GMT</pubDate><category>Yokogawa</category><category>CENTUM VP</category><category>ICS</category><category>SCADA</category><category>CVE-2025-1924</category><category>CVE-2025-48019</category><category>CVE-2025-48020</category><category>CVE-2025-48021</category><category>CVE-2025-48022</category><category>CVE-2025-48023</category><category>Denial of Service</category><category>Arbitrary Code Execution</category><category>Critical Manufacturing</category><category>Energy</category><category>Food and Agriculture</category></item><item><title>Critical Authentication Flaws in Chargemap EV Infrastructure</title><link>https://runtimerebel.com/blog/critical-authentication-flaws-in-chargemap-ev-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-authentication-flaws-in-chargemap-ev-infrastructure</guid><description>CISA warns of critical vulnerabilities in Chargemap EV charging stations, including unauthenticated WebSocket access and session hijacking (CVE-2026-25851).</description><pubDate>Thu, 26 Feb 2026 20:16:22 GMT</pubDate><category>CVE-2026-25851</category><category>Chargemap</category><category>EV Charging</category><category>ICS</category><category>Energy Sector</category><category>OCPP</category><category>WebSocket</category></item></channel></rss>