OT/ICS Security Intelligence
Protecting Industrial Infrastructure from Cyber Threats
Advisories, threat reports, and sector briefings for OT/ICS security practitioners. Covering energy, water, manufacturing, and critical infrastructure.
108
Advisories
5
Sectors
4
Content Types
Critical Advisory
Critical Advisory — Active Threat
CISA Advisory AA26-231A: Active Threat Actors Use AI-Generated Exploitation Scripts Against Siemens S7 Series PLCs
NSA, CISA, FBI, DOE, and EPA jointly warned on 19 August 2026 that threat actors are scanning for and probing internet-exposed Siemens S7-200 through S7-1500 controllers using AI-generated exploitation scripts disguised as monitoring tools, communicating over the S7comm protocol on TCP/102.
Active Advisories View All →
CVE-2025-7639 AVEVA Enterprise SCADA Deserialization Flaw (CVE-2025-7639): What ICSA-26-225-01 Means for Citect-Derived Deployments Aug 26, 2026 Vuln Analysis CISA ICSA-26-237-07: Hardcoded Credentials and Missing Authentication in FURUNO FA-50 AIS Transponders — No Patch Coming Aug 26, 2026 CVE-2026-55676 Six Flaws in CISA's Own Malcolm Network Analysis Tool Put OT Monitoring Stacks at Risk Aug 25, 2026 CVE-2026-27875 Johnson Controls Simplex Incident Manager: ICSA-26-232-01 Discloses Cleartext Credential Storage Flaw Aug 24, 2026 Vuln Analysis CVSS 10.0: Unauthenticated Root Command Injection in Haiwell IoT Cloud HMI Gateway (CVE-2026-19188) Aug 23, 2026 CVE-2017-16740 Forescout Scan Finds 4,400+ Exposed Rockwell PLCs; 19 in Water-Attack Cities Vulnerable to 2017 Modbus Flaw Aug 22, 2026
Sector Coverage All Sectors →
Energy
Electric utilities, generation, transmission & distribution
Water
Water treatment, wastewater, distribution systems
Manufacturing
Industrial production, process manufacturing, automotive
Petrochemical
Oil & gas, refining, chemical processing
Communications
Industrial comms infrastructure, private networks