Advertisement
AI-Assisted PLC Exploit Porting: WAGO RCE via Claude
Forescout researchers used Anthropic's Claude to port a WAGO PLC RCE exploit, demonstrating AI's potential in offensive security but highlighting current challenges.
TSN Protocols Vulnerabilities Threaten OT Security
New research reveals how unprotected Time-Sensitive Networking protocols in industrial systems could allow attackers to disrupt physical processes.
RCE Vulnerabilities in Copeland XWEB Pro & Danfoss AK-SM 800A Controllers
Claroty Team82 discovered multiple RCE vulnerabilities in Copeland XWEB Pro and Danfoss AK-SM 800A commercial refrigeration controllers.
CISA Warns: Cyberattacks Disrupting US Water Utilities' PLCs
CISA issues an urgent warning regarding increased cyberattacks targeting internet-exposed Programmable Logic Controllers (PLCs) in US water and wastewater systems…
CISA Urges Water Sector to Secure OT PLCs Amid Coordinated Attacks
CISA warns water and wastewater utilities to secure internet-exposed OT controllers after coordinated intrusions targeted dozens of Minnesota systems.
CISA & ACSC Advise Isolating OT Systems During Cyberattacks
CISA and ACSC urge critical infrastructure to prepare isolating operational technology systems during cyberattacks to maintain essential services and limit impact.
Advertisement
Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws
Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.
Exposed US Gas Station ATG Systems Threaten Critical Infrastructure
Over 900 US-based Automatic Tank Gauge (ATG) systems are exposed online, risking fuel theft, physical damage, and environmental incidents via remote access.
CVE-2026-21404: NAVTOR NavBox SOAP Credential Bypass and Mitigation
NAVTOR NavBox version 4.16.1.20 is vulnerable to hard-coded credentials in its SOAP implementation, allowing local attackers to manipulate application files.
Russian Intelligence Intensifies Tech Procurement and Infrastructure Recon
Russian spies are leveraging front companies and cyber espionage to bypass sanctions and gather intelligence for potential attacks on Western infrastructure.
OT Robot OS Command Injection: Unauthenticated RCE — Patch Now
Critical command injection vulnerability in OT Robot OS allows unauthenticated attackers to gain remote control, posing significant disruption risks to industrial…
Fast16: Pre-Stuxnet Lua Malware Targets Nuclear Physics Simulations
New analysis reveals Fast16 malware tampered with uranium-compression simulations, predating Stuxnet as a sophisticated tool for nuclear cyber sabotage.
Subnet Solutions PowerSYSTEM Center Vulnerabilities - Patch Now
CISA warns of high-severity vulnerabilities in Subnet Solutions PowerSYSTEM Center that allow sensitive data exposure and CRLF injection. Patch immediately.
Fast16 Malware: Revising the History of Cyber Sabotage
Researchers have uncovered 'fast16,' a sophisticated malware framework from two decades ago, predating Stuxnet and rewriting the timeline of cyber sabotage.
Lotus Data Wiper Targets Venezuelan Energy Utilities
Analysis of the Lotus data wiper targeting Venezuelan energy and utility firms in 2023. Understand its destructive capabilities and TTPs for defense.
BRIDGE:BREAK: 22 Flaws in Lantronix and Silex Serial Converters
Forescout researchers uncover 22 BRIDGE:BREAK vulnerabilities in Lantronix and Silex serial-to-IP converters, risking device hijacking and data tampering.
PX4 Autopilot v1.16.0 RCE via CVE-2026-1579: Mitigation Guide
Unauthenticated attackers can execute shell commands on PX4 Autopilot v1.16.0 via MAVLink. Learn how to enable message signing to secure autonomous systems.
Industrial OT Attacks With Physical Consequences Decline 25%
Physical-impact cyberattacks on operational technology fell 25% in 2023, driven by a ransomware lull and complex technical barriers in OT environments.
CVE-2025-13901: Modicon M241, M251, M262 DoS Vulnerability Patch
An unauthenticated DoS vulnerability (CVE-2025-13901) impacts Schneider Electric Modicon M241, M251, M262 controllers. Patch now to prevent ICS disruption.
Siemens SICAM SIAPP SDK RCE and DoS Vulnerabilities: Patch Guide
Siemens releases security updates for SICAM SIAPP SDK versions prior to 2.1.7 to address high-severity RCE, command injection, and buffer overflow flaws.
Siemens RUGGEDCOM APE1808 Critical Authentication Bypass — Patch Now
Security alert for Siemens RUGGEDCOM APE1808. Multiple vulnerabilities, including a 9.8 CVSS authentication bypass, affect ICS environments. Patch immediately.
Kai Emerges with $125M for AI-Driven IT/OT Security Platform
Kai Security launches from stealth with $125M to address IT and OT convergence risks using an AI-powered platform for industrial environment protection.