<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Industrial Control Systems</title><description>Cybersecurity articles tagged #Industrial Control Systems on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI-Assisted PLC Exploit Porting: WAGO RCE via Claude</title><link>https://runtimerebel.com/blog/ai-assisted-plc-exploit-porting-wago-rce-via-claude</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-plc-exploit-porting-wago-rce-via-claude</guid><description>Forescout researchers used Anthropic&apos;s Claude to port a WAGO PLC RCE exploit, demonstrating AI&apos;s potential in offensive security but highlighting current challenges.</description><pubDate>Tue, 01 Sep 2026 12:56:06 GMT</pubDate><category>Industrial Control Systems</category><category>ICS</category><category>AI</category><category>Exploit Development</category><category>Anthropic Claude</category></item><item><title>TSN Protocols Vulnerabilities Threaten OT Security</title><link>https://runtimerebel.com/blog/tsn-protocols-vulnerabilities-threaten-ot-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/tsn-protocols-vulnerabilities-threaten-ot-security</guid><description>New research reveals how unprotected Time-Sensitive Networking protocols in industrial systems could allow attackers to disrupt physical processes.</description><pubDate>Sun, 23 Aug 2026 16:17:17 GMT</pubDate><category>OT Security</category><category>Industrial Control Systems</category><category>Network Security</category><category>Vulnerabilities</category></item><item><title>RCE Vulnerabilities in Copeland XWEB Pro &amp; Danfoss AK-SM 800A Controllers</title><link>https://runtimerebel.com/blog/rce-vulnerabilities-in-copeland-xweb-pro-danfoss-ak-sm-800a-controllers</link><guid isPermaLink="true">https://runtimerebel.com/blog/rce-vulnerabilities-in-copeland-xweb-pro-danfoss-ak-sm-800a-controllers</guid><description>Claroty Team82 discovered multiple RCE vulnerabilities in Copeland XWEB Pro and Danfoss AK-SM 800A commercial refrigeration controllers.</description><pubDate>Fri, 14 Aug 2026 16:42:26 GMT</pubDate><category>RCE</category><category>Industrial Control Systems</category><category>OT Security</category><category>Copeland XWEB Pro</category><category>Danfoss AK SM 800A</category></item><item><title>CISA Warns: Cyberattacks Disrupting US Water Utilities&apos; PLCs</title><link>https://runtimerebel.com/blog/cisa-warns-cyberattacks-disrupting-us-water-utilities-plcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-warns-cyberattacks-disrupting-us-water-utilities-plcs</guid><description>CISA issues an urgent warning regarding increased cyberattacks targeting internet-exposed Programmable Logic Controllers (PLCs) in US water and wastewater systems…</description><pubDate>Fri, 31 Jul 2026 17:42:45 GMT</pubDate><category>CISA</category><category>Water Utilities</category><category>Wastewater Systems</category><category>PLCs</category><category>Industrial Control Systems</category><category>OT Security</category></item><item><title>CISA Urges Water Sector to Secure OT PLCs Amid Coordinated Attacks</title><link>https://runtimerebel.com/blog/cisa-urges-water-sector-to-secure-ot-plcs-amid-coordinated-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-urges-water-sector-to-secure-ot-plcs-amid-coordinated-attacks</guid><description>CISA warns water and wastewater utilities to secure internet-exposed OT controllers after coordinated intrusions targeted dozens of Minnesota systems.</description><pubDate>Fri, 31 Jul 2026 02:56:02 GMT</pubDate><category>CISA</category><category>Water Sector</category><category>Wastewater</category><category>OT Security</category><category>PLCs</category><category>Industrial Control Systems</category><category>Minnesota</category></item><item><title>CISA &amp; ACSC Advise Isolating OT Systems During Cyberattacks</title><link>https://runtimerebel.com/blog/cisa-acsc-advise-isolating-ot-systems-during-cyberattacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-acsc-advise-isolating-ot-systems-during-cyberattacks</guid><description>CISA and ACSC urge critical infrastructure to prepare isolating operational technology systems during cyberattacks to maintain essential services and limit impact.</description><pubDate>Tue, 28 Jul 2026 21:10:24 GMT</pubDate><category>CISA</category><category>ACSC</category><category>Critical Infrastructure</category><category>OT Security</category><category>Cyberattack Preparedness</category><category>Industrial Control Systems</category><category>Incident Response</category></item><item><title>Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws</title><link>https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</guid><description>Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.</description><pubDate>Fri, 24 Jul 2026 17:42:24 GMT</pubDate><category>DolphinX</category><category>Emerald Sleet</category><category>Winter Vivern</category><category>UNC4841</category><category>Zimbra</category><category>Linux Kernel</category><category>Siemens ROX II</category><category>Industrial Control Systems</category><category>APT</category><category>Ransomware</category><category>LockBit</category></item><item><title>Exposed US Gas Station ATG Systems Threaten Critical Infrastructure</title><link>https://runtimerebel.com/blog/exposed-us-gas-station-atg-systems-threaten-critical-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/exposed-us-gas-station-atg-systems-threaten-critical-infrastructure</guid><description>Over 900 US-based Automatic Tank Gauge (ATG) systems are exposed online, risking fuel theft, physical damage, and environmental incidents via remote access.</description><pubDate>Fri, 05 Jun 2026 16:55:14 GMT</pubDate><category>ATG</category><category>Critical Infrastructure</category><category>Industrial Control Systems</category><category>OT Security</category></item><item><title>CVE-2026-21404: NAVTOR NavBox SOAP Credential Bypass and Mitigation</title><link>https://runtimerebel.com/blog/cve-2026-21404-navtor-navbox-soap-credential-bypass-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-21404-navtor-navbox-soap-credential-bypass-and-mitigation</guid><description>NAVTOR NavBox version 4.16.1.20 is vulnerable to hard-coded credentials in its SOAP implementation, allowing local attackers to manipulate application files.</description><pubDate>Thu, 04 Jun 2026 17:10:49 GMT</pubDate><category>CVE-2026-21404</category><category>NAVTOR</category><category>NavBox</category><category>Industrial Control Systems</category><category>Hard Coded Credentials</category></item><item><title>Russian Intelligence Intensifies Tech Procurement and Infrastructure Recon</title><link>https://runtimerebel.com/blog/russian-intelligence-intensifies-tech-procurement-and-infrastructure-recon</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-intelligence-intensifies-tech-procurement-and-infrastructure-recon</guid><description>Russian spies are leveraging front companies and cyber espionage to bypass sanctions and gather intelligence for potential attacks on Western infrastructure.</description><pubDate>Sat, 30 May 2026 16:27:21 GMT</pubDate><category>Russian Intelligence</category><category>Sanctions Evasion</category><category>Industrial Control Systems</category><category>Supply Chain Security</category></item><item><title>OT Robot OS Command Injection: Unauthenticated RCE — Patch Now</title><link>https://runtimerebel.com/blog/ot-robot-os-command-injection-unauthenticated-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/ot-robot-os-command-injection-unauthenticated-rce-patch-now</guid><description>Critical command injection vulnerability in OT Robot OS allows unauthenticated attackers to gain remote control, posing significant disruption risks to industrial…</description><pubDate>Wed, 20 May 2026 17:14:09 GMT</pubDate><category>OT Robot OS</category><category>Command Injection</category><category>Industrial Control Systems</category><category>Robotics</category><category>RCE</category><category>Operational Technology</category><category>ICS</category></item><item><title>Fast16: Pre-Stuxnet Lua Malware Targets Nuclear Physics Simulations</title><link>https://runtimerebel.com/blog/fast16-pre-stuxnet-lua-malware-targets-nuclear-physics-simulations</link><guid isPermaLink="true">https://runtimerebel.com/blog/fast16-pre-stuxnet-lua-malware-targets-nuclear-physics-simulations</guid><description>New analysis reveals Fast16 malware tampered with uranium-compression simulations, predating Stuxnet as a sophisticated tool for nuclear cyber sabotage.</description><pubDate>Mon, 18 May 2026 09:19:15 GMT</pubDate><category>Fast16</category><category>Stuxnet</category><category>Nuclear Sabotage</category><category>Industrial Control Systems</category><category>Symantec</category><category>Carbon Black</category></item><item><title>Subnet Solutions PowerSYSTEM Center Vulnerabilities - Patch Now</title><link>https://runtimerebel.com/blog/subnet-solutions-powersystem-center-vulnerabilities-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/subnet-solutions-powersystem-center-vulnerabilities-patch-now</guid><description>CISA warns of high-severity vulnerabilities in Subnet Solutions PowerSYSTEM Center that allow sensitive data exposure and CRLF injection. Patch immediately.</description><pubDate>Tue, 12 May 2026 20:41:06 GMT</pubDate><category>CVE-2026-26289</category><category>CVE-2026-35504</category><category>Industrial Control Systems</category><category>Subnet Solutions</category><category>Energy Sector</category></item><item><title>Fast16 Malware: Revising the History of Cyber Sabotage</title><link>https://runtimerebel.com/blog/fast16-malware-revising-the-history-of-cyber-sabotage</link><guid isPermaLink="true">https://runtimerebel.com/blog/fast16-malware-revising-the-history-of-cyber-sabotage</guid><description>Researchers have uncovered &apos;fast16,&apos; a sophisticated malware framework from two decades ago, predating Stuxnet and rewriting the timeline of cyber sabotage.</description><pubDate>Mon, 27 Apr 2026 16:41:45 GMT</pubDate><category>Fast16</category><category>Stuxnet</category><category>Cyber Sabotage</category><category>Malware History</category><category>Industrial Control Systems</category><category>Threat Intelligence</category></item><item><title>Lotus Data Wiper Targets Venezuelan Energy Utilities</title><link>https://runtimerebel.com/blog/lotus-data-wiper-targets-venezuelan-energy-utilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/lotus-data-wiper-targets-venezuelan-energy-utilities</guid><description>Analysis of the Lotus data wiper targeting Venezuelan energy and utility firms in 2023. Understand its destructive capabilities and TTPs for defense.</description><pubDate>Tue, 21 Apr 2026 20:23:47 GMT</pubDate><category>Lotus</category><category>Data Wiper</category><category>Venezuela</category><category>Energy Sector</category><category>Utilities</category><category>Critical Infrastructure</category><category>Industrial Control Systems</category><category>Cybereason</category></item><item><title>BRIDGE:BREAK: 22 Flaws in Lantronix and Silex Serial Converters</title><link>https://runtimerebel.com/blog/bridge-break-22-flaws-in-lantronix-and-silex-serial-converters</link><guid isPermaLink="true">https://runtimerebel.com/blog/bridge-break-22-flaws-in-lantronix-and-silex-serial-converters</guid><description>Forescout researchers uncover 22 BRIDGE:BREAK vulnerabilities in Lantronix and Silex serial-to-IP converters, risking device hijacking and data tampering.</description><pubDate>Tue, 21 Apr 2026 16:29:38 GMT</pubDate><category>BRIDGE BREAK</category><category>Lantronix</category><category>Silex</category><category>Serial to Ethernet</category><category>Iot Security</category><category>Industrial Control Systems</category></item><item><title>PX4 Autopilot v1.16.0 RCE via CVE-2026-1579: Mitigation Guide</title><link>https://runtimerebel.com/blog/px4-autopilot-v1-16-0-rce-via-cve-2026-1579-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/px4-autopilot-v1-16-0-rce-via-cve-2026-1579-mitigation-guide</guid><description>Unauthenticated attackers can execute shell commands on PX4 Autopilot v1.16.0 via MAVLink. Learn how to enable message signing to secure autonomous systems.</description><pubDate>Tue, 31 Mar 2026 20:19:35 GMT</pubDate><category>CVE-2026-1579</category><category>PX4 Autopilot</category><category>MAVLink</category><category>RCE</category><category>Industrial Control Systems</category></item><item><title>Industrial OT Attacks With Physical Consequences Decline 25%</title><link>https://runtimerebel.com/blog/industrial-ot-attacks-with-physical-consequences-decline-25</link><guid isPermaLink="true">https://runtimerebel.com/blog/industrial-ot-attacks-with-physical-consequences-decline-25</guid><description>Physical-impact cyberattacks on operational technology fell 25% in 2023, driven by a ransomware lull and complex technical barriers in OT environments.</description><pubDate>Fri, 27 Mar 2026 16:26:47 GMT</pubDate><category>OT Security</category><category>Critical Infrastructure</category><category>Industrial Control Systems</category><category>Waterfall Security</category><category>Volt Typhoon</category></item><item><title>CVE-2025-13901: Modicon M241, M251, M262 DoS Vulnerability Patch</title><link>https://runtimerebel.com/blog/cve-2025-13901-modicon-m241-m251-m262-dos-vulnerability-patch</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-13901-modicon-m241-m251-m262-dos-vulnerability-patch</guid><description>An unauthenticated DoS vulnerability (CVE-2025-13901) impacts Schneider Electric Modicon M241, M251, M262 controllers. Patch now to prevent ICS disruption.</description><pubDate>Thu, 19 Mar 2026 20:17:42 GMT</pubDate><category>CVE-2025-13901</category><category>Schneider Electric</category><category>Modicon M241</category><category>Modicon M251</category><category>Modicon M262</category><category>Industrial Control Systems</category><category>DoS</category></item><item><title>Siemens SICAM SIAPP SDK RCE and DoS Vulnerabilities: Patch Guide</title><link>https://runtimerebel.com/blog/siemens-sicam-siapp-sdk-rce-and-dos-vulnerabilities-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-sicam-siapp-sdk-rce-and-dos-vulnerabilities-patch-guide</guid><description>Siemens releases security updates for SICAM SIAPP SDK versions prior to 2.1.7 to address high-severity RCE, command injection, and buffer overflow flaws.</description><pubDate>Tue, 17 Mar 2026 20:16:43 GMT</pubDate><category>Siemens</category><category>SICAM SIAPP SDK</category><category>CVE-2026-25569</category><category>CVE-2026-25570</category><category>Industrial Control Systems</category><category>RCE</category></item><item><title>Siemens RUGGEDCOM APE1808 Critical Authentication Bypass — Patch Now</title><link>https://runtimerebel.com/blog/siemens-ruggedcom-ape1808-critical-authentication-bypass-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-ruggedcom-ape1808-critical-authentication-bypass-patch-now</guid><description>Security alert for Siemens RUGGEDCOM APE1808. Multiple vulnerabilities, including a 9.8 CVSS authentication bypass, affect ICS environments. Patch immediately.</description><pubDate>Thu, 12 Mar 2026 20:16:11 GMT</pubDate><category>CVE-2026-24858</category><category>Siemens</category><category>RUGGEDCOM</category><category>Fortinet</category><category>Industrial Control Systems</category><category>ICS Security</category></item><item><title>Kai Emerges with $125M for AI-Driven IT/OT Security Platform</title><link>https://runtimerebel.com/blog/kai-emerges-with-125m-for-ai-driven-it-ot-security-platform</link><guid isPermaLink="true">https://runtimerebel.com/blog/kai-emerges-with-125m-for-ai-driven-it-ot-security-platform</guid><description>Kai Security launches from stealth with $125M to address IT and OT convergence risks using an AI-powered platform for industrial environment protection.</description><pubDate>Tue, 10 Mar 2026 16:29:03 GMT</pubDate><category>Kai Security</category><category>OT Security</category><category>IT OT Convergence</category><category>Industrial Control Systems</category><category>Amir Zilberstein</category></item></channel></rss>