#ICS
38 stories taggedICS.

FBI and CISA warn critical infrastructure operators to rein in third-party ICS integrators
A new joint fact sheet asks water, power and manufacturing operators to lock down the outside engineers who quietly run their control systems.

FBI warns foreign hackers raided a US industrial contractor for SCADA blueprints
A March-April 2025 intrusion at an industrial automation firm netted around 800 files on power and transport customers, and the FBI is telling critical infrastructure to rethink how much access it hands to outside integrators.

A flaw in Mitsubishi factory networks lets attackers scramble the machines
CVE-2026-13584 hits more than 80 Mitsubishi Electric products that speak CC-Link IE TSN, the protocol wiring modern factory floors together.

Schneider Electric, Siemens, and Aveva patch critical flaws in industrial control systems
September 2026's industrial Patch Tuesday brings fixes for authentication failures, hardcoded encryption keys, and a Linux kernel flaw that lets attackers gain full system control.

Siemens patches Teamcenter login flaw that could hijack engineer sessions
A reflected cross-site scripting bug in the /auth/ endpoint lets a crafted link run attacker code inside a logged-in user's browser. Siemens has shipped fixes across four release trains.

Schneider Electric patches weak-randomness flaw across dozens of grid control products
A session-management bug rated 8.3 affects protection relays, gateways and SCADA software used in power, water and chemical plants worldwide.

OPC Foundation patches installer flaw that let a bystander hijack setup on industrial servers
A medium-severity bug in the OPC UA Local Discovery Server installer briefly exposes a high-privilege console anyone at the keyboard could grab.

The Hidden Blindspot in Industrial Cyberattacks, and How Fake Devices Help Fill It
When hackers cross from a company's office network into the systems that run physical equipment, the trail goes cold. A maturing technique called cyber deception is starting to change that.

Mitsubishi Electric factory gear can be knocked offline by a single crafted network packet
A flaw tracked as CVE-2025-3511 lets a remote attacker freeze dozens of Mitsubishi factory automation products with one malformed UDP message, forcing a manual reset to recover.

More Than 100 Water Systems Were Hit by Hackers in July. Here's What CISA Found.
U.S. cybersecurity officials have put a number on the recent wave of attacks on drinking water and wastewater facilities: over 100 internet-connected systems targeted in a single month, most of them left exposed by a simple modem.

US agencies warn hackers are using AI to break into Siemens factory controllers
CISA, NSA, FBI, DOE and EPA say attackers are scanning the internet for exposed Siemens S7 PLCs and running AI-written scripts dressed up as monitoring tools.

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine
A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

AVEVA warns of code-execution flaw in Enterprise SCADA software used across pipelines and manufacturing
A high-severity deserialization bug lets an authenticated operator run code inside the industrial control system. AVEVA has shipped patches for every supported release.

America's Drinking Water Networks Are Getting a Long-Overdue Security Upgrade
A new Senate bill and a first-of-its-kind monitoring centre launched at DEF CON aim to plug gaping security holes in the water systems that supply millions of American homes.

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020
Industrial software used in energy and water plants bundles an old database carrying flaws that can leak memory and sidestep access controls.