ICS / OT
Vulnerabilities and intrusions affecting industrial control systems, SCADA, PLCs, and the operational-technology stack — plus the wider "physical-layer" surface of firmware in embedded devices and covert channels against air-gapped machines. Where a bug can mean a plant trip, not just a data breach.

MLflow SSRF, FUXA Auth Flaws Actively Exploited
Attackers are exploiting an SSRF in MLflow's AI platform and scanning FUXA SCADA installs—critical flaws in both enabling cloud credential theft and full RCE.

CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639
CISA advisory ICSA-26-225-01 covers CVE-2025-7639, a deserialization flaw that lets authenticated ICS operators execute code at elevated privilege.

ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact
Siemens, Schneider Electric, and Phoenix Contact issued security bulletins on August 12. CISA published parallel ICS advisories the same day. OT operators should review now.

Rogue SIM Cards Execute Attacker Code on Industrial Modems
SIM Toolkit commands give rogue SIMs code execution on cellular modules in EV chargers, industrial routers, and car telematics units, University of Birmingham and Fuzzware researchers confirm.

Polish Heat Plant Breached via Private Cellular OT Network
Attackers breached a Polish heat plant via private cellular APN, shutting down a steam turbine. The OT intrusion went undisclosed for months.

Iran Suspected in Multistate Water System PLC Attacks
Internet-exposed PLCs at water utilities across 12+ U.S. states are under active attack, with Iran-linked actors suspected. Default credentials and unencrypted protocols remain the core exposure.

84 Flaws Found in Open-Source 4G and 5G Cores
Researchers at NTU Singapore found 84 flaws in open-source 4G/5G core software, enabling DoS and session hijacking via GTP-C and PFCP protocol weaknesses.

CISA Warns of Rising Attacks on Water System PLCs
CISA flags a surge in attacks targeting internet-exposed PLCs in U.S. water and wastewater systems. Patch, segment, and remove direct internet exposure.

Coordinated OT Attack Hits 30+ Minnesota Water Systems
30 Minnesota water systems hit in a coordinated OT cyberattack July 26-27, knocking Braham's plant offline and triggering statewide incident response.

Why OT Isolation Is Harder Than the Advisory Says
CISA and ASD's joint OT isolation guidance is correct in what it recommends. What it leaves to inference is the physical-layer reality that makes the recommendation hard to execute.

CISA, ASD Issue Joint OT Isolation Guidance
CISA and Australia's ASD jointly urge critical infrastructure operators to pre-plan and rehearse OT isolation before a cyberattack forces the decision mid-incident.

AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes
AIVD and MIVD say Russian intel is hijacking exposed IP cameras across EU, NATO states, and Ukraine to watch military convoys and weapons shipments to Kyiv.

KNX account-lockout flaw added to CISA KEV, three years on
CVE-2023-4346 turns the KNX Association's account-lockout mechanism into a device-purge weapon on a building-automation bus. CISA added it to KEV under BOD 26-04.

Seven years on, CVE-2018-0171 draws a 13-state advisory
US, UK, and eleven allied governments co-signed a July 13 advisory naming FSB Centre 16 as the actor still pulling configs off end-of-life Cisco routers via CVE-2018-0171.

Six U-Boot flaws trace to one libfdt helper
Binarly disclosed six bugs in U-Boot's FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.

Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM
Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.

Tenda Router Backdoor Has No Patch. Here's What to Do.
CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn't respond. No fix is coming — here's the mitigation.

TrojPix: air-gap exfil via video-cable RF emanation
Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.

Armored Likho Ties BusySnake to Power-Sector Spying
Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.