<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #SCADA</title><description>Cybersecurity articles tagged #SCADA on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Siemens and Schneider Patch Critical ICS Flaws — October 2024</title><link>https://runtimerebel.com/blog/siemens-and-schneider-patch-critical-ics-flaws-october-2024</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-and-schneider-patch-critical-ics-flaws-october-2024</guid><description>Siemens, Schneider Electric, and Rockwell Automation release critical updates for ICS products including SCALANCE, SINEC, and EcoStruxure platforms.</description><pubDate>Wed, 15 Jul 2026 10:07:48 GMT</pubDate><category>Siemens</category><category>Schneider Electric</category><category>Rockwell Automation</category><category>ICS Security</category><category>SCADA</category><category>CVE-2024-42359</category><category>CVE-2024-38311</category></item><item><title>Jesse McGraw (GhostExodus): Examining the First ICS Hacking Conviction</title><link>https://runtimerebel.com/blog/jesse-mcgraw-ghostexodus-examining-the-first-ics-hacking-conviction</link><guid isPermaLink="true">https://runtimerebel.com/blog/jesse-mcgraw-ghostexodus-examining-the-first-ics-hacking-conviction</guid><description>A technical analysis of Jesse McGraw (GhostExodus), his compromise of hospital HVAC systems, and the evolution of industrial control system security threats.</description><pubDate>Mon, 13 Jul 2026 14:43:16 GMT</pubDate><category>GhostExodus</category><category>Jesse McGraw</category><category>ICS Security</category><category>SCADA</category><category>Insider Threat</category></item><item><title>CVE-2024-2821: Critical RCE in Daktronics Controllers — Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-2821-critical-rce-in-daktronics-controllers-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-2821-critical-rce-in-daktronics-controllers-patch-now</guid><description>Critical vulnerabilities (CVE-2024-2821, CVE-2024-2822, CVE-2024-2823) in Daktronics Venus 1500 and Vanguard controllers allow remote hacking of highway signs and…</description><pubDate>Tue, 30 Jun 2026 05:28:50 GMT</pubDate><category>Daktronics</category><category>CVE-2024-2821</category><category>CVE-2024-2822</category><category>CVE-2024-2823</category><category>ICS</category><category>SCADA</category><category>IoT</category><category>Improper Authentication</category><category>Remote Hacking</category><category>Critical Infrastructure</category></item><item><title>CVE-2026-6332: Schneider Electric EcoStruxure HVAC Source Code Disclosure</title><link>https://runtimerebel.com/blog/cve-2026-6332-schneider-electric-ecostruxure-hvac-source-code-disclosure</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-6332-schneider-electric-ecostruxure-hvac-source-code-disclosure</guid><description>A cleartext storage vulnerability in Schneider Electric EcoStruxure Machine Expert HVAC (CVE-2026-6332) exposes sensitive source code. Update to v1.10.0.</description><pubDate>Thu, 28 May 2026 17:27:39 GMT</pubDate><category>CVE-2026-6332</category><category>Schneider Electric</category><category>EcoStruxure Machine Expert HVAC</category><category>ICS</category><category>SCADA</category><category>CWE-312</category><category>Source Code Disclosure</category><category>OT</category></item><item><title>Polish Water ICS Breaches: Attackers Alter Operational Parameters</title><link>https://runtimerebel.com/blog/polish-water-ics-breaches-attackers-alter-operational-parameters</link><guid isPermaLink="true">https://runtimerebel.com/blog/polish-water-ics-breaches-attackers-alter-operational-parameters</guid><description>Poland&apos;s ABW reports unauthorized access to five water treatment plants where attackers gained control over operational parameters, risking public safety.</description><pubDate>Fri, 08 May 2026 12:39:04 GMT</pubDate><category>ICS Security</category><category>Poland</category><category>Critical Infrastructure</category><category>OT Security</category><category>SCADA</category></item><item><title>AI-Driven Cyberattack Fails to Breach OT Systems via SCADA Login</title><link>https://runtimerebel.com/blog/ai-driven-cyberattack-fails-to-breach-ot-systems-via-scada-login</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-cyberattack-fails-to-breach-ot-systems-via-scada-login</guid><description>Analysis of the first AI-driven cyberattack targeting OT. Despite advanced automation, the campaign failed to bypass standard SCADA login interfaces.</description><pubDate>Thu, 07 May 2026 16:43:36 GMT</pubDate><category>AI Driven Attack</category><category>ICS Security</category><category>SCADA</category><category>OT Defense</category><category>Automation</category></item><item><title>CVE-2025-14510: ABB Ability OPTIMAX Azure AD SSO Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2025-14510-abb-ability-optimax-azure-ad-sso-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-14510-abb-ability-optimax-azure-ad-sso-auth-bypass</guid><description>CISA warns of CVE-2025-14510 impacting ABB Ability OPTIMAX, allowing authentication bypass on Azure AD SSO integrations. Patch immediately.</description><pubDate>Fri, 01 May 2026 00:56:01 GMT</pubDate><category>CVE-2025-14510</category><category>ABB Ability OPTIMAX</category><category>Authentication Bypass</category><category>Azure Active Directory SSO</category><category>ICS</category><category>SCADA</category><category>Energy Sector</category><category>Water and Wastewater</category></item><item><title>Iranian APT Exploits Rockwell Automation PLCs: Securing Critical Infrastructure OT Devices</title><link>https://runtimerebel.com/blog/iranian-apt-exploits-rockwell-automation-plcs-securing-critical-infrastructure-ot-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-apt-exploits-rockwell-automation-plcs-securing-critical-infrastructure-ot-devices</guid><description>Iranian-affiliated APT actors are exploiting internet-facing Rockwell Automation PLCs, disrupting US critical infrastructure.</description><pubDate>Tue, 07 Apr 2026 20:21:14 GMT</pubDate><category>Iranian APT</category><category>Cyber Av3ngers</category><category>Rockwell Automation</category><category>Allen Bradley</category><category>PLC</category><category>OT Security</category><category>Critical Infrastructure</category><category>HMI</category><category>SCADA</category><category>Government</category><category>Water and Wastewater</category><category>Energy</category></item><item><title>Mitsubishi Electric ICS Vulnerabilities Expose SQL Credentials</title><link>https://runtimerebel.com/blog/mitsubishi-electric-ics-vulnerabilities-expose-sql-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitsubishi-electric-ics-vulnerabilities-expose-sql-credentials</guid><description>High-severity vulnerabilities (CVE-2025-14815, CVE-2025-14816) in Mitsubishi Electric ICS/SCADA products risk SQL credential exposure and data compromise.</description><pubDate>Tue, 07 Apr 2026 16:31:20 GMT</pubDate><category>CVE-2025-14815</category><category>CVE-2025-14816</category><category>Mitsubishi Electric</category><category>GENESIS64</category><category>ICONICS Suite</category><category>ICS</category><category>SCADA</category><category>Cleartext Storage</category><category>Critical Manufacturing</category><category>SQL Server</category></item><item><title>CVE-2025-13957: Hard-coded Credentials in Schneider EcoStruxure DCE</title><link>https://runtimerebel.com/blog/cve-2025-13957-hard-coded-credentials-in-schneider-ecostruxure-dce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-13957-hard-coded-credentials-in-schneider-ecostruxure-dce</guid><description>Hard-coded credentials in Schneider Electric EcoStruxure Data Center Expert v9.0 and prior (CVE-2025-13957) allow information disclosure and RCE if SOCKS Proxy is…</description><pubDate>Tue, 17 Mar 2026 20:17:31 GMT</pubDate><category>CVE-2025-13957</category><category>Schneider Electric</category><category>EcoStruxure IT Data Center Expert</category><category>Hard Coded Credentials</category><category>ICS</category><category>SCADA</category><category>Operational Technology</category></item><item><title>CVE-2026-3611: Critical Auth Bypass in Honeywell IQ4x BMS Controllers</title><link>https://runtimerebel.com/blog/cve-2026-3611-critical-auth-bypass-in-honeywell-iq4x-bms-controllers</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3611-critical-auth-bypass-in-honeywell-iq4x-bms-controllers</guid><description>CISA warns of a critical authentication bypass (CVE-2026-3611) in Honeywell IQ4x BMS Controllers, allowing unauthenticated attackers administrative access and potential…</description><pubDate>Tue, 10 Mar 2026 20:15:15 GMT</pubDate><category>CVE-2026-3611</category><category>Honeywell IQ4x</category><category>BMS Controller</category><category>ICS</category><category>SCADA</category><category>Authentication Bypass</category><category>Critical Infrastructure</category><category>CWE-306</category></item><item><title>Honeywell IQ4 Vulnerability: Assessing Internet Exposure &amp; Impact</title><link>https://runtimerebel.com/blog/honeywell-iq4-vulnerability-assessing-internet-exposure-impact</link><guid isPermaLink="true">https://runtimerebel.com/blog/honeywell-iq4-vulnerability-assessing-internet-exposure-impact</guid><description>A researcher claims thousands of internet-exposed Honeywell IQ4 building controllers are vulnerable. Understand the potential impact and mitigation strategies.</description><pubDate>Tue, 03 Mar 2026 16:24:11 GMT</pubDate><category>Honeywell IQ4</category><category>Building Management Systems</category><category>ICS Security</category><category>OT Security</category><category>SCADA</category></item><item><title>Multiple DoS/RCE Vulnerabilities in Yokogawa CENTUM VP R6, R7</title><link>https://runtimerebel.com/blog/multiple-dos-rce-vulnerabilities-in-yokogawa-centum-vp-r6-r7</link><guid isPermaLink="true">https://runtimerebel.com/blog/multiple-dos-rce-vulnerabilities-in-yokogawa-centum-vp-r6-r7</guid><description>CISA alerts to multiple medium-severity vulnerabilities in Yokogawa CENTUM VP R6 and R7, allowing DoS and RCE via crafted packets in critical infrastructure…</description><pubDate>Thu, 26 Feb 2026 20:16:44 GMT</pubDate><category>Yokogawa</category><category>CENTUM VP</category><category>ICS</category><category>SCADA</category><category>CVE-2025-1924</category><category>CVE-2025-48019</category><category>CVE-2025-48020</category><category>CVE-2025-48021</category><category>CVE-2025-48022</category><category>CVE-2025-48023</category><category>Denial of Service</category><category>Arbitrary Code Execution</category><category>Critical Manufacturing</category><category>Energy</category><category>Food and Agriculture</category></item><item><title>Critical RCE Flaws in InSAT MasterSCADA BUK-TS Affect ICS</title><link>https://runtimerebel.com/blog/critical-rce-flaws-in-insat-masterscada-buk-ts-affect-ics</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-rce-flaws-in-insat-masterscada-buk-ts-affect-ics</guid><description>Two critical vulnerabilities (SQLi, OS Command Injection) in InSAT MasterSCADA BUK-TS lead to remote code execution, impacting critical infrastructure sectors globally.</description><pubDate>Wed, 25 Feb 2026 04:43:53 GMT</pubDate><category>CVE-2026-21410</category><category>CVE-2026-22553</category><category>InSAT MasterSCADA BUK TS</category><category>SQL Injection</category><category>OS Command Injection</category><category>RCE</category><category>ICS</category><category>SCADA</category><category>Critical Manufacturing</category><category>Energy</category><category>Water and Wastewater</category></item></channel></rss>