#ICS
31 stories taggedICS · page 2 of 3.

Siemens Patches Four Flaws in SICAM 8 Grid Kit, Including a Firmware Signing Bypass
The German industrial giant is pushing V26.20 firmware for gear that sits inside power stations. One bug lets an insider install their own firmware.

A malformed packet can knock Rockwell's Flex 5000 Adapter offline until someone power-cycles it
Rockwell Automation has patched a denial-of-service flaw in a widely deployed factory-floor module. The fix ships as firmware 6.012.

The Machines That Run the World Are Running Decades-Old Software
Industrial control systems keep factories, water plants, and power grids alive. They also run code written before Wi-Fi existed. Fixing that is harder than it sounds.

Siemens, Schneider Electric, and Rockwell Fix Dozens of Flaws in Factory Control Systems
Three of the world's biggest industrial equipment makers patched a wave of security flaws in the software that runs power plants, factories, and water systems. Here is what that means in plain English.

Siemens tells industrial customers to patch RUGGEDCOM switches now, cites dozens of flaws in SINEC OS
The German engineering giant has shipped version 4.0 of its ruggedised network operating system to close a long list of bugs, including one rated 9.8 out of 10.

Iran, Russia, and China Have Been Quietly Attacking Water Systems — and the Door Was Usually Left Unlocked
A new threat-intelligence report finds three governments targeting water and wastewater infrastructure, not primarily to poison anyone, but to cause fear, probe weaknesses, and pre-position for future conflict. The tools they're using are embarrassingly basic.

Schneider Electric patches three flaws in PowerLogic P7 grid protection gear
The most serious bug lets an unauthenticated attacker knock the device's control screen offline. A firmware update is out.

CISA Flags Three Daktronics Controller Flaws That Could Let Attackers Hijack Highway Signs
A researcher found the vulnerabilities in controllers widely used to drive digital billboards and roadway message signs. Exploitation could mean someone else controls what drivers read.

ICS Security's 25-Year Reunion Is Headed to Nashville
The Industrial Control Systems Cybersecurity Conference marks a quarter-century in October 2026, touching down at the W Nashville for three days of OT threat intelligence.

CVE-2025-67038: Lantronix Serial-to-IP Flaw Moves From Research to Active Exploitation
A vulnerability disclosed through the BRIDGE:BREAK project is now seeing exploitation in the wild, raising fresh concerns about attacker interest in operational technology network edges.

CISA Flags Active Exploitation of Lantronix EDS5000 Code Injection Bug
CVE-2025-67038 carries a 9.8 CVSS. Federal agencies have until June 26, 2026 to patch — but if it's already being hit in the wild, that runway looks generous.

Fuel, Chemicals, Food: CISA Warns ATG Attacks Can Drain Tanks Silently
Hardcoded credentials and unauthenticated command execution leave automated tank gauges wide open. The fix list is embarrassingly short.

900+ Fuel Tank Gauges Still Hanging Off the Public Internet
ATG systems in gas stations, hospitals, and military sites are exposed to known CVEs — and nobody owns the patch cycle.

Feds Sound Alarm on Exposed Fuel Tank Gauges as Hackers Probe Critical Infrastructure
CISA, FBI, NSA and DOE say internet-facing ATG systems at fuel depots, hospitals and military sites are being scanned and hit. The fix is mostly operator hygiene.

Dragos Buys Phosphorus to Close the xIoT Visibility Gap
The OT security firm absorbs an extended-IoT specialist, promising customers a unified platform that can actually see—and fix—the devices most asset inventories quietly ignore.