Skip to content
feed: live
0dayNews
← All vendors
Vendor

ICS / OT

Vulnerabilities and intrusions affecting industrial control systems, SCADA, PLCs, and the operational-technology stack — plus the wider "physical-layer" surface of firmware in embedded devices and covert channels against air-gapped machines. Where a bug can mean a plant trip, not just a data breach.

0 CVEs27 articlesRSS
Articles
~/articles/2026-09-30-south-africa-atc-ransomware-operational-network
ics ot

Ransomware Hits South Africa Air Traffic Control

A ransomware toolkit was installed on at least one operational network at South Africa's air traffic control authority, prompting a request for international cybersecurity assistance.

read →
~/articles/2026-09-08-advantech-wise-6610-cve-2026-79697-rce
ics ot

Advantech WISE-6610 Firmware Hit by CVSS 9.9 RCE

A command injection in the WISE-6610 LoRaWAN gateway's Basic Station handler allows remote code execution. Exploit is public. Patch: firmware 1.2.4_20260821.

read →
~/articles/2026-09-03-forescout-vedere-claude-wago-plc-exploit-port
ics ot

Forescout Uses Claude to Port RCE Across WAGO PLCs

Vedere Labs used Claude to port a pre-auth RCE exploit between WAGO PLC models, showing AI tools can lower barriers to ICS exploitation.

read →
~/articles/2026-08-29-zbt-router-factory-implants-cve-2026-74232-74233
ics ot

ZBT Routers Ship With Factory-Installed Root Backdoors

VulnCheck found two undocumented firmware implants in Shenzhen ZBT routers: SPEAKINGSTONE and DARKLANTERN, each granting unauthenticated remote root access. Both carry CVSS 9.8 scores.

read →
~/articles/2026-08-27-cisa-red-team-critical-infrastructure-assessment
ics ot

CISA Red Team Fully Compromised Both Orgs; One Saw Nothing

CISA published simultaneous red team results for two critical infrastructure orgs. Both were fully compromised at domain level; only one detected the intrusion.

read →
~/articles/2026-08-26-treasury-sanctions-irgc-hackers-ics-breaches
ics ot

Treasury Sanctions IRGC-Linked Hackers Over ICS Attacks

The U.S. Treasury has sanctioned Iranian cyber actors tied to IRGC-linked groups responsible for critical infrastructure breaches, including the UK power plant shutdown confirmed Tuesday.

read →
~/articles/2026-08-25-iran-uk-power-plant-shutdown-sanctions
ics ot

Iran ICS Attack Shuts UK Power Plant; US Sanctions

A UK power plant went dark for four days after an Iran-linked cyberattack; the U.S. has now sanctioned Iranian nationals tied to the critical infrastructure campaign.

read →
~/articles/2026-08-20-nsa-fbi-ai-siemens-plc-attacks
ics ot

NSA, FBI Warn of AI-Powered Attacks on Siemens PLCs

NSA and FBI warn that AI-generated scripts are actively targeting Siemens S7 PLCs in U.S. critical infrastructure. Inventory, segment, and patch now.

read →
~/articles/2026-08-18-mlflow-fuxa-cve-exploitation-cloud-scada
ics ot

MLflow SSRF, FUXA Auth Flaws Actively Exploited

Attackers are exploiting an SSRF in MLflow's AI platform and scanning FUXA SCADA installs—critical flaws in both enabling cloud credential theft and full RCE.

read →
~/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639
ics ot

CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639

CISA advisory ICSA-26-225-01 covers CVE-2025-7639, a deserialization flaw that lets authenticated ICS operators execute code at elevated privilege.

read →
~/articles/2026-08-13-ics-patch-tuesday-siemens-schneider-phoenix-contact
ics ot

ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact

Siemens, Schneider Electric, and Phoenix Contact issued security bulletins on August 12. CISA published parallel ICS advisories the same day. OT operators should review now.

read →
~/articles/2026-08-11-malicious-sim-code-exec-cellular-iot-modules
ics ot

Rogue SIM Cards Execute Attacker Code on Industrial Modems

SIM Toolkit commands give rogue SIMs code execution on cellular modules in EV chargers, industrial routers, and car telematics units, University of Birmingham and Fuzzware researchers confirm.

read →
~/articles/2026-08-11-poland-heat-plant-private-apn-ot-breach
ics ot

Polish Heat Plant Breached via Private Cellular OT Network

Attackers breached a Polish heat plant via private cellular APN, shutting down a steam turbine. The OT intrusion went undisclosed for months.

read →
~/articles/2026-08-10-iran-water-plc-attacks-multistate
ics ot

Iran Suspected in Multistate Water System PLC Attacks

Internet-exposed PLCs at water utilities across 12+ U.S. states are under active attack, with Iran-linked actors suspected. Default credentials and unencrypted protocols remain the core exposure.

read →
~/articles/2026-08-02-ntu-84-flaws-4g-5g-core-networks
ics ot

84 Flaws Found in Open-Source 4G and 5G Cores

Researchers at NTU Singapore found 84 flaws in open-source 4G/5G core software, enabling DoS and session hijacking via GTP-C and PFCP protocol weaknesses.

read →
~/articles/2026-07-31-cisa-water-utilities-plc-attacks
ics ot

CISA Warns of Rising Attacks on Water System PLCs

CISA flags a surge in attacks targeting internet-exposed PLCs in U.S. water and wastewater systems. Patch, segment, and remove direct internet exposure.

read →
~/articles/2026-07-29-minnesota-water-ot-attack
ics ot

Coordinated OT Attack Hits 30+ Minnesota Water Systems

30 Minnesota water systems hit in a coordinated OT cyberattack July 26-27, knocking Braham's plant offline and triggering statewide incident response.

read →
~/articles/2026-07-29-ot-isolation-field-reality-explainer
Explainer
ics ot

Why OT Isolation Is Harder Than the Advisory Says

CISA and ASD's joint OT isolation guidance is correct in what it recommends. What it leaves to inference is the physical-layer reality that makes the recommendation hard to execute.

read →
~/articles/2026-07-28-cisa-asd-ot-isolation-guidance
ics ot

CISA, ASD Issue Joint OT Isolation Guidance

CISA and Australia's ASD jointly urge critical infrastructure operators to pre-plan and rehearse OT isolation before a cyberattack forces the decision mid-incident.

read →
~/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine
ics ot

AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes

AIVD and MIVD say Russian intel is hijacking exposed IP cameras across EU, NATO states, and Ukraine to watch military convoys and weapons shipments to Kyiv.

read →
~/articles/2026-07-15-knx-cve-2023-4346-cisa-kev-account-lockout-bod-26-04
ics ot

KNX account-lockout flaw added to CISA KEV, three years on

CVE-2023-4346 turns the KNX Association's account-lockout mechanism into a device-purge weapon on a building-automation bus. CISA added it to KEV under BOD 26-04.

read →
~/articles/2026-07-13-fsb-centre-16-cve-2018-0171-router-hygiene-csa
ics ot

Seven years on, CVE-2018-0171 draws a 13-state advisory

US, UK, and eleven allied governments co-signed a July 13 advisory naming FSB Centre 16 as the actor still pulling configs off end-of-life Cisco routers via CVE-2018-0171.

read →
~/articles/2026-07-11-u-boot-libfdt-fit-parsing-six-brly-flaws
ics ot

Six U-Boot flaws trace to one libfdt helper

Binarly disclosed six bugs in U-Boot's FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.

read →
~/articles/2026-07-09-talos-vdr-wolfssl-geovision-vtk-dicom-disclosure
ics ot

Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM

Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.

read →
~/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched
ics ot

Tenda Router Backdoor Has No Patch. Here's What to Do.

CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn't respond. No fix is coming — here's the mitigation.

read →
~/articles/2026-07-06-trojpix-air-gap-video-cable-emanation-shandong
Analysis
ics ot

TrojPix: air-gap exfil via video-cable RF emanation

Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.

read →
~/articles/2026-07-04-armored-likho-busysnake-power-sector-kaspersky
ics ot

Armored Likho Ties BusySnake to Power-Sector Spying

Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.

read →