Skip to main content
System Status
Critical 18
|
High 70
|
Medium 1
|
Feed Online
UPDATED: 2026-06-11 00:00 UTC

AVEVA Enterprise SCADA Deserialization Flaw (CVE-2025-7639): What ICSA-26-225-01 Means for Citect-Derived Deployments

CISA advisory ICSA-26-225-01 details a high-severity insecure deserialization vulnerability in AVEVA Enterprise SCADA — the platform formerly known as Citect SCADA — that lets a low-privileged operator escalate to code execution under the DNA Apps security group. Here's the technical breakdown and remediation path.

CISA ICSA-26-237-07: Hardcoded Credentials and Missing Authentication in FURUNO FA-50 AIS Transponders — No Patch Coming

CISA and JPCERT disclosed two vulnerabilities in the discontinued FURUNO FA-50 Class B AIS Transponder — hardcoded credentials (CVSS 9.1) and missing authentication on configuration functions (CVSS 7.5). With production ended in 2020 and no firmware update planned, mitigation falls entirely on vessel network segmentation.

Forescout Scan Finds 4,400+ Exposed Rockwell PLCs; 19 in Water-Attack Cities Vulnerable to 2017 Modbus Flaw

An August 3, 2026 internet-wide scan by Forescout Vedere Labs identified 4,407 internet-facing Rockwell/Allen-Bradley PLCs on port 44818, with 22 located in cities hit by the July water-sector campaign. Nineteen run MicroLogix 1400 firmware vulnerable to CVE-2017-16740, a nine-year-old Modbus TCP buffer overflow Rockwell patched in 2017 but many operators never applied.

CISA Advisory AA26-231A: Active Threat Actors Use AI-Generated Exploitation Scripts Against Siemens S7 Series PLCs

NSA, CISA, FBI, DOE, and EPA jointly warned on 19 August 2026 that threat actors are scanning for and probing internet-exposed Siemens S7-200 through S7-1500 controllers using AI-generated exploitation scripts disguised as monitoring tools, communicating over the S7comm protocol on TCP/102.

ICSA-25-352-07: Rockwell Micro800 Series IPv6 and CIP Fuzzing Flaws Enable Remote Denial of Service

CISA advisory ICSA-25-352-07 details two Rockwell Automation vulnerabilities -- CVE-2025-13823 and CVE-2025-13824 -- in Micro820, Micro850, and Micro870 controllers. Malformed IPv6 and CIP packets can drive the PLCs into recoverable or hard fault, halting control logic on machines and skid-level equipment across manufacturing and utility sites.

Phoenix Contact PLCnext and mGuard Security: CISA Advisory Roundup and Hardening Guide

Phoenix Contact is among the top five ICS vendors by CISA ICS-CERT advisory volume in 2026. Vulnerabilities span the PLCnext runtime environment, mGuard security routers, and WP 6xxx web panel HMIs — covering authentication bypass, remote code execution, cross-site scripting, and weak cryptography. This guide consolidates the advisory landscape and provides OT-specific hardening steps for each product family.

CISA AA26-097A: Iranian-Affiliated Actors Escalate PLC Exploitation Across Water, Energy, and Municipal OT

A July 2026 update to CISA advisory AA26-097A expands the confirmed scope of Iranian-affiliated PLC exploitation to Schneider Electric Modicon M340 and Siemens S7-1200 controllers, adding to the initial Rockwell Allen-Bradley targeting disclosed in April. Active exploitation of internet-facing PLCs is now confirmed across water, energy, and government facility sectors.

Siemens SIMATIC IoT2050 Advanced: Maximum-Severity Unauthenticated RCE in Industrial IoT Gateways

Siemens published a maximum-severity advisory in August 2026 Patch Tuesday covering a missing authentication vulnerability in SIMATIC IoT2050 Advanced devices. An unauthenticated remote attacker can execute arbitrary code with elevated privileges on the underlying server — a critical risk for IT/OT bridging deployments where these gateways connect operational technology networks to enterprise IT and cloud systems.

CVE-2026-59310 in OT Environments: Protecting Virtualised SCADA and Historian Infrastructure

VMware vCenter CVE-2026-59310 (CVSS 9.8, actively exploited) presents an acute risk in OT environments where virtualisation hosts historian servers, HMIs, engineering workstations, and SCADA applications. This advisory covers which OT components are most exposed, how vCenter compromise translates to OT network impact, and the OT-specific mitigations that reduce risk while patching proceeds.

Johnson Controls C·CURE 9000 RCE Vulnerability: ICSA-26-204-01 Advisory and Mitigation

CISA published ICSA-26-204-01 on August 11, 2026, disclosing CVE-2026-21655, a remotely exploitable code execution vulnerability in Johnson Controls C·CURE 9000 physical access control systems. With a CVSS score of 9.8 and no authentication required, the flaw affects C·CURE 9000 versions prior to 3.0.3 deployed in enterprise and critical infrastructure physical security management. This advisory covers the vulnerability details, affected versions, exploitation risk in OT-adjacent environments, and recommended mitigations.

Aviation and Airport OT Security: ATM Systems, Ground Operations, and Emerging Threats

Airports and air traffic management infrastructure operate some of the most complex OT environments in critical infrastructure — mixing 1970s-era navigation systems with modern IP-connected ground handling, creating an attack surface that is both wide and poorly understood.

Wind Energy Cybersecurity: Turbine Controllers, SCADA, and Grid Integration Attack Surface

Wind farms depend on industrial control systems that manage turbine operation, power output, and grid integration — all increasingly networked and internet-connected for remote monitoring. This sector briefing covers the attack surface, documented threat actor interest, and hardening priorities for wind energy OT security teams.

CISA Alert: PLC Targeting Campaign Hits Water Utilities Across Seven US States

CISA's July 30, 2026 alert confirms a coordinated campaign targeting internet-exposed programmable logic controllers at water and wastewater utilities in at least seven states. Threat actors modified passwords to lock out operators and changed IP addresses to disconnect systems, causing boil-water notices and manual operations.

Modbus and DNP3 Under Attack: Protocol Security and Detection for OT Networks

Modbus and DNP3 are the dominant SCADA communication protocols in energy, water, and manufacturing — and both were designed with zero authentication. This guide covers the specific attack techniques these protocols enable, real-world exploitation patterns from incident reports, and how OT security teams can add detection without disrupting production.

CISA ICS Advisories: August 2026 Roundup — Siemens, Honeywell, GE Vernova

CISA published multiple ICS security advisories in the first week of August 2026, covering critical vulnerabilities in Siemens SINEC NMS, Honeywell Experion PKS, and GE Vernova grid management systems. This roundup covers the disclosed vulnerabilities, affected product versions, CVSS scores, and recommended mitigations for OT security teams.

IEC 60870-5-104 Security: Protocol Analysis and Hardening for Power Grid SCADA

IEC 60870-5-104 (IEC 104) carries power grid telemetry and control traffic across TCP/IP with no authentication and no encryption in its base specification. It is deployed in substations, transmission grids, and distribution networks worldwide. This guide covers the attack surface, known exploitation patterns, and practical hardening measures.

BACnet/IP Security: Attack Surface Analysis and Hardening for Building Automation Systems

BACnet/IP has no authentication in its base protocol and tens of thousands of internet-exposed devices. An attacker with network access can read from or write to HVAC, fire suppression, lighting, and access control systems without credentials. This guide covers the attack surface, real-world incident patterns, and hardening steps.

CISA Updates AA26-097A: Iranian IRGC-Affiliated Actors Expand PLC Targeting to Siemens and Schneider Electric

CISA revised advisory AA26-097A on 22 July 2026, expanding the scope of Iranian IRGC-affiliated ICS targeting beyond the original Rockwell Automation and Unitronics findings to include Siemens TIA Portal and Schneider Electric environments. The update also adds new detection guidance for identifying malicious modifications within reusable PLC code modules — a forensic challenge distinct from detecting initial access.

ICSA-26-202-07: Rockwell FactoryTalk JWT Algorithm Confusion Allows Forged Authentication Tokens

CISA advisory ICSA-26-202-07 documents a JWT signature bypass in Rockwell Automation's FactoryTalk Services Platform 6.60. The vulnerability lets an attacker set the JWT algorithm to 'none' during Okta Web Authentication, forge tokens without a valid signature, and impersonate authorised users to access industrial system configurations. Patch is available.

OT Patch Management in Practice: A Field Guide for Industrial Control System Operators

Patching industrial control systems is categorically different from IT patching. Production constraints, vendor dependency, and long asset lifecycles make standard patch cadences unworkable. This guide covers compensating controls, vendor coordination, and a realistic patching process for OT environments.

AI Workflow Tools in OT Environments: The Attack Surface Industrial Operators Are Building Without Noticing

n8n, Langflow, and Node-RED are being adopted in industrial environments for AI-driven process analytics, predictive maintenance, and historian integration. The NadMesh botnet now specifically targets these tools. This creates a new attack path from exposed AI workflow interfaces to OT data historians and, in poorly segmented environments, to SCADA systems.

July 2026 ICS Patch Tuesday: Siemens CVSS 10 Auth Bypass, ABB and Rockwell Advisories

July 2026's ICS Patch Tuesday brought nine Siemens advisories including a CVSS 10.0 authentication bypass in Opencenter X, three ABB advisories, and a Rockwell advisory. Here's what OT/ICS security teams need to prioritise and the operational context for each critical finding.

Nation-State Router Targeting at the OT Perimeter: Technical Response to CISA AA26-194A

CISA Advisory AA26-194A documents Russian FSB Center 16 exfiltrating router configurations from critical infrastructure globally via SNMP and Cisco Smart Install. For OT environments, perimeter routers hold additional sensitivity: they contain VPN configurations, routing to SCADA networks, and credentials that can enable lateral movement from IT into OT. This guide covers the OT-specific implications and hardening steps.

ICS Patch Tuesday July 2026: Siemens TIA Portal RCE, Schneider IGSS Critical, Rockwell 12 Advisories

July 2026 ICS Patch Tuesday brings a significant advisory load: Siemens releases 18 advisories including a critical TIA Portal remote code execution flaw, Schneider Electric addresses a critical IGSS SCADA vulnerability, and Rockwell Automation publishes 12 advisories covering FactoryTalk and Logix controllers. Prioritisation guidance for OT security teams.

CISA July 2026 ICS Advisories: Satellite Ground Station Terminals and Building Automation Vulnerabilities

CISA's July 2026 ICS advisory batches covered 13 advisories across satellite communication terminals, EV charging management systems, and building automation controllers. This roundup covers the highest-priority items for OT and critical infrastructure security teams.

IEC 62443 in Practice: Security Levels, Zone-Conduit Model, and Implementation for OT Practitioners

IEC 62443 is the international standard series for industrial automation and control system security. This practitioner guide covers the security level framework, the zone-conduit network architecture model, and what implementation actually looks like for OT security teams — from SL-1 baseline controls to SL-3 nation-state-resistant configurations.

FSB Center 16 Poland Grid Attack: OT Sector Analysis and Critical Infrastructure Implications

The UK and EU attribution of December 2025's Poland energy grid attack to FSB Center 16 — an operation that nearly caused a blackout for half a million people — has direct implications for OT security in European energy and water sectors. Analysis of the attack characteristics, attribution dispute, and what ICS operators should take from the formal sanctions.

Smart Grid and Advanced Metering Infrastructure (AMI) Cybersecurity: Attack Surface and Hardening in 2026

Advanced Metering Infrastructure connects tens of millions of smart meters to utility head-end systems via RF mesh and cellular networks. The attack surface — bidirectional communication, large device counts, heterogeneous firmware, and direct connection to distribution grid controls — is poorly understood outside specialist OT security teams.

FrostyGoop: The ICS Malware That Weaponised Modbus TCP Against Energy Infrastructure

FrostyGoop (BUSTLEBERM) is the first publicly documented ICS-specific malware to directly communicate with industrial devices via Modbus TCP. Its January 2024 deployment against a Ukrainian district heating company — disrupting heat for 600 buildings in winter — demonstrates the operational impact of OT-native attack tools.

GhostLock CVE-2026-43499: Advisory for OT Environments Running Linux-Based Historian and SCADA Systems

The GhostLock Linux kernel vulnerability (CVE-2026-43499) enables local privilege escalation to root in approximately five seconds with 97% reliability. OT environments running Linux-based historian servers, OPC-UA gateways, and SCADA platforms are directly affected. Patching and mitigation guidance for industrial operators.

Maritime Port and Shipping OT Cybersecurity: IMO Compliance and Sector Threats 2026

Cyberattacks targeting maritime infrastructure surged 103% in 2025. This briefing covers port OT architecture, threat actors, attack vectors against vessel control systems and terminal management, and the IMO and IACS regulatory requirements now in force.

IEC 61850 Substation Automation Security: Attack Surface and Hardening for Power Grid Operators

IEC 61850 is the dominant protocol for digital substation automation — and it was designed for operational reliability, not security. GOOSE messages carry no authentication. MMS sessions use optional TLS that most deployments skip. This analysis covers the threat model and practical hardening for utilities and grid operators.

Data Center OT Security: BMS, EPMS, and Cooling System Vulnerabilities

AI infrastructure buildout has made data centers a critical OT environment that receives less security scrutiny than industrial facilities. Building Management Systems, Electrical Power Management Systems, and cooling controllers run on the same unpatched, internet-exposed architectures as manufacturing OT — with similar consequences when compromised.

Chemical Sector OT Security: Safety Systems, Process Control, and Attack Paths in High-Consequence Environments

The chemical sector operates Safety Instrumented Systems alongside distributed control networks in environments where a cyber-physical incident can cause mass casualties. Triton/TRISIS set the benchmark for targeted SIS attacks in 2017; the threat has evolved but the fundamental exposure remains. This briefing covers the chemical sector OT threat landscape, SIS attack paths, and applicable compliance frameworks.

OT Incident Response: The First 48 Hours

When a cyber incident hits an operational technology environment, the first 48 hours determine whether a brief outage becomes a prolonged shutdown. This playbook covers the critical decisions, sequencing, and OT-specific considerations that IR teams need to get right from the first alert.

Siemens S7comm Protocol: Attack Surface, Unauthenticated Access, and OT Network Detection

S7comm is Siemens' proprietary PLC communication protocol. Legacy S7comm lacks authentication and encryption, enabling unauthenticated read/write access to process data and PLC control commands. This guide covers the attack surface, documented exploit techniques, and detection approaches for OT defenders.

CISA June 2026 ICS Advisories: Siemens WinCC and Rockwell RSLinx RCE

CISA released a batch of 10 ICS advisories on June 23, 2026, including critical vulnerabilities in Siemens WinCC Certificate Manager and SIPROTEC 5. Separately, ICSA-26-167-02 documents an unauthenticated stack-based buffer overflow in Rockwell Automation RSLinx Classic enabling remote code execution.

EV Charging Infrastructure Cybersecurity: OCPP Vulnerabilities, Grid Attack Surfaces, and Operator Obligations

The rapid buildout of EV charging infrastructure has created a new OT attack surface at the intersection of transportation, energy, and consumer technology. This briefing covers OCPP protocol vulnerabilities, documented attack incidents, the grid stability risk from coordinated charging manipulation, and what operators need to implement to meet emerging regulatory standards.

Securing OT Remote Access: VPN, ZTNA, and Jump Server Architecture for Industrial Networks

Remote access to operational technology environments expanded dramatically during 2020-2022 and was never fully locked down. This guide covers the specific risks of each remote access pattern — vendor VPNs, site VPNs, jump servers, and ZTNA — and the hardening steps that reduce the attack surface without breaking the maintenance workflows OT teams depend on.

Railway and Transport SCADA Cybersecurity: Attack Surfaces, Nation-State Threats, and TSA Directives

Railway and mass transit systems operate a complex mix of operational technology — signalling, SCADA, ETCS, and passenger information systems — across environments that were designed for availability and safety, not cyber resilience. This briefing covers the attack surface, documented threat actor targeting, and current regulatory requirements under TSA's rail cybersecurity directives.

NERC CIP in 2026: Where Compliance Ends and Real OT Security Begins

NERC CIP is the compliance baseline for US bulk electric system cybersecurity — not a security ceiling. This briefing examines where NERC CIP requirements leave real gaps: low-impact assets, supply chain enforcement, operational technology visibility, and the delta between checkbox compliance and defensible OT security posture.

Food and Agriculture OT Security: A Sector Facing Escalating Cyber Threats

Ransomware disruptions to JBS, NEW Cooperative, Crystal Valley, and Dole demonstrated that food and agriculture OT is a material critical infrastructure target. As FDA traceability requirements add digital connectivity to previously isolated systems, the attack surface is expanding while security maturity lags.

Solar Inverter OT Security 2026: Solarman, Deye, and 195GW of Grid Attack Surface

Bitdefender researchers disclosed critical vulnerabilities in Solarman and Deye solar inverter management platforms in 2024-2025, covering 195GW of installed capacity. OAuth token endpoint flaws, JWT reuse attacks, and hard-coded credentials created paths from the internet to grid-connected OT equipment. This article covers the vulnerability classes, the attack surface, and what energy sector operators need to assess.

Oil and Gas Pipeline Cybersecurity: TSA Directives, OT Threat Landscape, and Compliance Requirements in 2026

The TSA's pipeline cybersecurity directives have fundamentally changed the compliance environment for US pipeline operators. This analysis covers the directive requirements, the OT threat actors specifically targeting oil and gas infrastructure, and the technical controls that actually move the needle.

CISA ICS Advisory Roundup: Inductive Automation Ignition, ICONICS GENESIS64, and Mitsubishi Electric Vulnerabilities June 2026

CISA released nine ICS advisories in June 2026 covering critical and high-severity vulnerabilities in Inductive Automation Ignition, ICONICS/Mitsubishi GENESIS64, and Axis network cameras used in OT environments. This roundup covers the operational risk and remediation priorities.

Building Automation System Security: BACnet, BMS Hardening, and the OT-IT Convergence Risk

Building automation systems control HVAC, lighting, access control, and fire suppression across commercial and industrial facilities. As BAS deployments converge with IP networks, legacy protocols like BACnet and Modbus are now internet-adjacent — with predictable results for attack surface.

CISA Advisory: Automatic Tank Gauge Systems Under Active Attack — What OT Operators Need to Do Now

CISA, FBI, NSA, and five other US federal agencies issued a joint advisory in June 2026 warning of active malicious cyber activity targeting internet-exposed automatic tank gauge (ATG) systems across the energy, water, transportation, and critical infrastructure sectors. Attackers are exploiting authentication bypass and command execution flaws to modify pump controls and disable safety alerts.

Maritime OT Security 2026: ECDIS Vulnerabilities, AIS Spoofing, and the Threat to Port Systems

Maritime operational technology spans navigation systems, ship management platforms, and port infrastructure — all increasingly networked, poorly patched, and targeted by both state and criminal actors. This sector briefing covers the current maritime threat landscape, key vulnerability classes in ECDIS and AIS, GPS/GNSS spoofing in contested regions, and the IMO and DNV frameworks guiding the sector's security response.

OPC UA Security: Attack Surface Analysis and Hardening Recommendations for Industrial Environments

OPC Unified Architecture has become the dominant interoperability standard for industrial communication — and a consistent target in ICS-focused threat campaigns. This analysis covers the OPC UA threat model, documented vulnerability classes from recent CVEs, known exploitation by nation-state actors, and the hardening steps that reduce exposure without breaking operational continuity.

Advantech WebAccess/SCADA: Multiple High-Severity Vulnerabilities Enable Remote Code Execution

Advisories covering Advantech WebAccess/SCADA document path traversal, unrestricted file upload, and SQL injection vulnerabilities rated up to CVSS 8.8. WebAccess/SCADA is deployed across manufacturing, energy, and water treatment facilities globally. This analysis covers the vulnerability classes, exploitation paths, and immediate mitigations for OT operators.

Record 508 ICS Advisories in 2025: What the Vulnerability Surge Means for OT Defenders

Forescout's analysis of 2025 ICS security advisories identifies a record 508 advisories covering 2,155 vulnerabilities — with 82% rated high or critical. Field controllers, PLCs, and SCADA systems are the primary targets, and the growing share of advisories with no available patch creates an unresolvable exposure category that demands compensating controls.

CISA's Zero Trust Roadmap for OT: What the April 2026 Joint Guidance Means for Industrial Operators

CISA's April 2026 joint guidance 'Adapting Zero Trust Principles to Operational Technology' lays out a practical roadmap for applying zero trust in environments where the standard IT playbook doesn't work — legacy protocols, uptime requirements, and safety constraints included.

Schneider Electric EcoStruxure Vulnerability Roundup: Critical Advisories Affecting Energy, Manufacturing, and Data Centre Operations

Schneider Electric has issued multiple CISA-coordinated advisories in 2026 covering critical vulnerabilities across the EcoStruxure platform suite -- including a CVSS 9.8 deserialization flaw in the Foxboro DCS Advisor, hard-coded credentials in Data Center Expert, and local RCE in Power Monitoring Expert.

IEC 62443: The OT Security Standard Your Procurement Team Needs to Understand

IEC 62443 is the international standard series for industrial cybersecurity. This explainer covers the structure of the standard, what Security Levels mean in practice, the zones and conduits model, and how to reference 62443 in vendor contracts to actually improve your security posture.

Four-Faith Routers Under Active Attack, Iranian Threat Actors Hit US Fuel Systems

Mass exploitation of two vulnerabilities in Four-Faith industrial routers began May 12 with 139 attacking IPs observed against 15,800 exposed devices. Meanwhile, Iranian-linked threat actors continue automated attacks against Automatic Tank Gauge systems at US petrol stations.

OT Threat Landscape 2026: New Dragos Groups, Shrinking Exploit Windows, and the Visibility Crisis

Dragos's 2026 OT cybersecurity year-in-review identifies 26 threat groups specifically targeting operational technology -- including three newly tracked groups -- as exploit timelines compress to 24 days and fewer than one in ten OT networks have active monitoring. A practical analysis for OT security practitioners.