Tag

#ICS

38 stories taggedICS.

Full-frame photoreal editorial image of a dimly lit industrial control room at a water treatment plant, rows of SCADA screens glowing pale blue and amber, empty
Policy & Regulation

FBI and CISA warn critical infrastructure operators to rein in third-party ICS integrators

A new joint fact sheet asks water, power and manufacturing operators to lock down the outside engineers who quietly run their control systems.

4 min read
Photoreal editorial shot of a dimly lit industrial control room, rows of SCADA monitors showing abstract pipeline and grid schematics glowing blue and amber, on
Threat Intelligence

FBI warns foreign hackers raided a US industrial contractor for SCADA blueprints

A March-April 2025 intrusion at an industrial automation firm netted around 800 files on power and transport customers, and the FBI is telling critical infrastructure to rethink how much access it hands to outside integrators.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a modern automotive factory floor at low light, focused on a row of industrial control cabinets with blinkin
Vulnerabilities

A flaw in Mitsubishi factory networks lets attackers scramble the machines

CVE-2026-13584 hits more than 80 Mitsubishi Electric products that speak CC-Link IE TSN, the protocol wiring modern factory floors together.

3 min read
Industrial control system panels with buttons, gauges, and displays in a factory or power facility setting, with Patch Tuesday notification badges overlaid on c
Vulnerabilities

Schneider Electric, Siemens, and Aveva patch critical flaws in industrial control systems

September 2026's industrial Patch Tuesday brings fixes for authentication failures, hardcoded encryption keys, and a Linux kernel flaw that lets attackers gain full system control.

4 min read
An engineering workstation with CAD software open, a browser address bar highlighted showing a suspicious login URL, and user session indicators active on the d
Vulnerabilities

Siemens patches Teamcenter login flaw that could hijack engineer sessions

A reflected cross-site scripting bug in the /auth/ endpoint lets a crafted link run attacker code inside a logged-in user's browser. Siemens has shipped fixes across four release trains.

4 min read
An industrial control room with SCADA systems and power grid monitoring displays, overlaid session token streams with weak encryption indicators highlighted in
Vulnerabilities

Schneider Electric patches weak-randomness flaw across dozens of grid control products

A session-management bug rated 8.3 affects protection relays, gateways and SCADA software used in power, water and chemical plants worldwide.

3 min read
An industrial server being installed with its setup wizard displayed on a nearby console, a hand reaching toward the keyboard, security barrier icon shown disab
Vulnerabilities

OPC Foundation patches installer flaw that let a bystander hijack setup on industrial servers

A medium-severity bug in the OPC UA Local Discovery Server installer briefly exposes a high-privilege console anyone at the keyboard could grab.

3 min read
An industrial facility floor with manufacturing equipment and control systems, monitored by cameras and sensors, with a network diagram overlay showing deceptio
Opinion

The Hidden Blindspot in Industrial Cyberattacks, and How Fake Devices Help Fill It

When hackers cross from a company's office network into the systems that run physical equipment, the trail goes cold. A maturing technique called cyber deception is starting to change that.

5 min read
A factory floor with multiple Mitsubishi automation machines frozen mid-operation, with a malformed network packet visualization traveling across the machinery,
Vulnerabilities

Mitsubishi Electric factory gear can be knocked offline by a single crafted network packet

A flaw tracked as CVE-2025-3511 lets a remote attacker freeze dozens of Mitsubishi factory automation products with one malformed UDP message, forcing a manual reset to recover.

4 min read
A water treatment facility control room with SCADA systems and network-connected monitoring equipment, many accessed through exposed modems visible on facility
Threat Intelligence

More Than 100 Water Systems Were Hit by Hackers in July. Here's What CISA Found.

U.S. cybersecurity officials have put a number on the recent wave of attacks on drinking water and wastewater facilities: over 100 internet-connected systems targeted in a single month, most of them left exposed by a simple modem.

3 min read
An industrial factory floor with manufacturing equipment and control systems, cybersecurity warning banners and AI-generated script alerts visible on monitoring
Threat Intelligence

US agencies warn hackers are using AI to break into Siemens factory controllers

CISA, NSA, FBI, DOE and EPA say attackers are scanning the internet for exposed Siemens S7 PLCs and running AI-written scripts dressed up as monitoring tools.

4 min read
An industrial design workstation with 3D modelling software displaying a malformed CAD file causing a crash, error messages and system logs visible, security pa
Vulnerabilities

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine

A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

3 min read
An industrial control room with SCADA system displays showing pipeline and manufacturing equipment monitoring, a security alert panel highlighting a code execut
Vulnerabilities

AVEVA warns of code-execution flaw in Enterprise SCADA software used across pipelines and manufacturing

A high-severity deserialization bug lets an authenticated operator run code inside the industrial control system. AVEVA has shipped patches for every supported release.

4 min read
Water treatment facility control room with modern security monitoring station setup, network protection infrastructure visible, and new surveillance systems bei
Policy & Regulation

America's Drinking Water Networks Are Getting a Long-Overdue Security Upgrade

A new Senate bill and a first-of-its-kind monitoring centre launched at DEF CON aim to plug gaping security holes in the water systems that supply millions of American homes.

3 min read
Industrial control system screens for energy and water infrastructure running on displays, with a MongoDB database version number from 2020 visible in the syste
Vulnerabilities

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020

Industrial software used in energy and water plants bundles an old database carrying flaws that can leak memory and sidestep access controls.

3 min read
© 2026 Threat Vectr