Three Security Stories You May Have Missed: Industrial Switches, Russian Email Spying, and a Rail Ransomware Shakedown
A digest of under-reported threats: flaws in Siemens industrial network hardware, a Russian hacking campaign targeting Zimbra webmail servers, and a ransomware attack against Swiss train maker Stadler Rail.

Key points
- Siemens ROX II industrial switches contain multiple security flaws that could let attackers take control of critical network hardware.
- Russian hackers ran an espionage campaign targeting Zimbra webmail servers used by government and business organisations.
- Stadler Rail, a Swiss train manufacturer, faced a ransomware extortion attempt in which criminals stole data and demanded payment.
- SecurityWeek flagged all three stories as significant but under-covered in a recent news roundup.
What happened with the Siemens switch flaws?
Siemens ROX II switches, which are specialised network routing devices used to connect machines inside factories and power facilities, were found to carry multiple security vulnerabilities. A flaw in hardware like this matters because those devices sit at the heart of industrial control systems, the systems that keep lights on, water running, and production lines moving.
Siemens has published a security advisory detailing the affected firmware versions and recommended fixes. If your organisation uses ROX II hardware, check that advisory now and apply any available patches. Leaving unpatched kit on an operational network is the kind of opening attackers actively look for.
How did Russian hackers use email servers as a spying tool?
A campaign linked to Russian state-backed hackers targeted Zimbra, an email and calendar platform widely used by government agencies and businesses. Zimbra is essentially a webmail system, similar to Outlook or Gmail but run on an organisation's own servers rather than in the cloud.
The attackers exploited weaknesses in Zimbra installations to read emails, steal login credentials (usernames and passwords), and gain a foothold inside victim networks. Espionage campaigns like this rarely make loud headlines because nothing explodes and nothing stops working. The goal is quiet, long-term access.
Organisations running Zimbra should confirm they are on a fully patched version and review login logs for unusual access patterns.
What is the Stadler Rail ransomware story?
Stadler Rail, a Swiss manufacturer that builds trains and trams, confirmed that criminals broke into its IT network, stole a quantity of data, and then threatened to publish that data unless the company paid a ransom. This is the standard double-extortion playbook: encrypt files to cause disruption, then threaten a public data leak as extra pressure.
Ransomware (malicious software that locks or steals a company's files until a payment is made) has hit transport and manufacturing firms repeatedly in recent years because operational pressure creates urgency, and urgency is exactly what criminals want their victims to feel.
Stadler said at the time that production was not significantly disrupted, but the incident is a reminder that any large company with complex supply chains is a target.
| Story | Target | Nature of threat |
|---|---|---|
| Siemens ROX II flaws | Industrial network switches | Multiple software vulnerabilities |
| Russian Zimbra campaign | Government and business email servers | Credential theft and espionage |
| Stadler Rail attack | Swiss train manufacturer | Ransomware and data extortion |
What should ordinary people take away from this?
None of these incidents require immediate action from members of the public. However, employees at manufacturing firms, utilities, or organisations using Zimbra email should report any unusual login prompts or unexpected password-reset requests to their IT team straight away. Criminals often use stolen credentials for weeks before anyone notices.



