<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — ICS / OT</title><description>Vulnerabilities and intrusions affecting industrial control systems, SCADA, PLCs, and the operational-technology stack — plus the wider &quot;physical-layer&quot; surface of firmware in embedded devices and covert channels against air-gapped machines. Where a bug can mean a plant trip, not just a data breach. Combined article + CVE feed for the ICS / OT beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>MLflow SSRF, FUXA Auth Flaws Actively Exploited</title><link>https://0daynews.com/articles/2026-08-18-mlflow-fuxa-cve-exploitation-cloud-scada/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-18-mlflow-fuxa-cve-exploitation-cloud-scada/</guid><description>Attackers are exploiting an SSRF in MLflow&apos;s AI platform and scanning FUXA SCADA installs—critical flaws in both enabling cloud credential theft and full RCE.</description><pubDate>Tue, 18 Aug 2026 20:00:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639</title><link>https://0daynews.com/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639/</guid><description>CISA advisory ICSA-26-225-01 covers CVE-2025-7639, a deserialization flaw that lets authenticated ICS operators execute code at elevated privilege.</description><pubDate>Sat, 15 Aug 2026 12:00:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact</title><link>https://0daynews.com/articles/2026-08-13-ics-patch-tuesday-siemens-schneider-phoenix-contact/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-ics-patch-tuesday-siemens-schneider-phoenix-contact/</guid><description>Siemens, Schneider Electric, and Phoenix Contact issued security bulletins on August 12. CISA published parallel ICS advisories the same day. OT operators should review now.</description><pubDate>Thu, 13 Aug 2026 06:00:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Rogue SIM Cards Execute Attacker Code on Industrial Modems</title><link>https://0daynews.com/articles/2026-08-11-malicious-sim-code-exec-cellular-iot-modules/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-11-malicious-sim-code-exec-cellular-iot-modules/</guid><description>SIM Toolkit commands give rogue SIMs code execution on cellular modules in EV chargers, industrial routers, and car telematics units, University of Birmingham and Fuzzware researchers confirm.</description><pubDate>Tue, 11 Aug 2026 16:30:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Polish Heat Plant Breached via Private Cellular OT Network</title><link>https://0daynews.com/articles/2026-08-11-poland-heat-plant-private-apn-ot-breach/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-11-poland-heat-plant-private-apn-ot-breach/</guid><description>Attackers breached a Polish heat plant via private cellular APN, shutting down a steam turbine. The OT intrusion went undisclosed for months.</description><pubDate>Tue, 11 Aug 2026 06:00:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Iran Suspected in Multistate Water System PLC Attacks</title><link>https://0daynews.com/articles/2026-08-10-iran-water-plc-attacks-multistate/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-10-iran-water-plc-attacks-multistate/</guid><description>Internet-exposed PLCs at water utilities across 12+ U.S. states are under active attack, with Iran-linked actors suspected. Default credentials and unencrypted protocols remain the core exposure.</description><pubDate>Mon, 10 Aug 2026 23:45:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>84 Flaws Found in Open-Source 4G and 5G Cores</title><link>https://0daynews.com/articles/2026-08-02-ntu-84-flaws-4g-5g-core-networks/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-02-ntu-84-flaws-4g-5g-core-networks/</guid><description>Researchers at NTU Singapore found 84 flaws in open-source 4G/5G core software, enabling DoS and session hijacking via GTP-C and PFCP protocol weaknesses.</description><pubDate>Sun, 02 Aug 2026 04:00:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>CISA Warns of Rising Attacks on Water System PLCs</title><link>https://0daynews.com/articles/2026-07-31-cisa-water-utilities-plc-attacks/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-31-cisa-water-utilities-plc-attacks/</guid><description>CISA flags a surge in attacks targeting internet-exposed PLCs in U.S. water and wastewater systems. Patch, segment, and remove direct internet exposure.</description><pubDate>Fri, 31 Jul 2026 18:00:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Coordinated OT Attack Hits 30+ Minnesota Water Systems</title><link>https://0daynews.com/articles/2026-07-29-minnesota-water-ot-attack/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-minnesota-water-ot-attack/</guid><description>30 Minnesota water systems hit in a coordinated OT cyberattack July 26-27, knocking Braham&apos;s plant offline and triggering statewide incident response.</description><pubDate>Wed, 29 Jul 2026 16:10:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Why OT Isolation Is Harder Than the Advisory Says</title><link>https://0daynews.com/articles/2026-07-29-ot-isolation-field-reality-explainer/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-ot-isolation-field-reality-explainer/</guid><description>CISA and ASD&apos;s joint OT isolation guidance is correct in what it recommends. What it leaves to inference is the physical-layer reality that makes the recommendation hard to execute.</description><pubDate>Wed, 29 Jul 2026 06:00:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>CISA, ASD Issue Joint OT Isolation Guidance</title><link>https://0daynews.com/articles/2026-07-28-cisa-asd-ot-isolation-guidance/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-cisa-asd-ot-isolation-guidance/</guid><description>CISA and Australia&apos;s ASD jointly urge critical infrastructure operators to pre-plan and rehearse OT isolation before a cyberattack forces the decision mid-incident.</description><pubDate>Tue, 28 Jul 2026 20:00:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes</title><link>https://0daynews.com/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine/</guid><description>AIVD and MIVD say Russian intel is hijacking exposed IP cameras across EU, NATO states, and Ukraine to watch military convoys and weapons shipments to Kyiv.</description><pubDate>Mon, 20 Jul 2026 14:15:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>KNX account-lockout flaw added to CISA KEV, three years on</title><link>https://0daynews.com/articles/2026-07-15-knx-cve-2023-4346-cisa-kev-account-lockout-bod-26-04/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-knx-cve-2023-4346-cisa-kev-account-lockout-bod-26-04/</guid><description>CVE-2023-4346 turns the KNX Association&apos;s account-lockout mechanism into a device-purge weapon on a building-automation bus. CISA added it to KEV under BOD 26-04.</description><pubDate>Wed, 15 Jul 2026 20:15:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Seven years on, CVE-2018-0171 draws a 13-state advisory</title><link>https://0daynews.com/articles/2026-07-13-fsb-centre-16-cve-2018-0171-router-hygiene-csa/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-fsb-centre-16-cve-2018-0171-router-hygiene-csa/</guid><description>US, UK, and eleven allied governments co-signed a July 13 advisory naming FSB Centre 16 as the actor still pulling configs off end-of-life Cisco routers via CVE-2018-0171.</description><pubDate>Mon, 13 Jul 2026 11:20:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Six U-Boot flaws trace to one libfdt helper</title><link>https://0daynews.com/articles/2026-07-11-u-boot-libfdt-fit-parsing-six-brly-flaws/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-u-boot-libfdt-fit-parsing-six-brly-flaws/</guid><description>Binarly disclosed six bugs in U-Boot&apos;s FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.</description><pubDate>Sat, 11 Jul 2026 11:15:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM</title><link>https://0daynews.com/articles/2026-07-09-talos-vdr-wolfssl-geovision-vtk-dicom-disclosure/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-talos-vdr-wolfssl-geovision-vtk-dicom-disclosure/</guid><description>Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.</description><pubDate>Thu, 09 Jul 2026 22:35:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Tenda Router Backdoor Has No Patch. Here&apos;s What to Do.</title><link>https://0daynews.com/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched/</guid><description>CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn&apos;t respond. No fix is coming — here&apos;s the mitigation.</description><pubDate>Wed, 08 Jul 2026 01:15:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>TrojPix: air-gap exfil via video-cable RF emanation</title><link>https://0daynews.com/articles/2026-07-06-trojpix-air-gap-video-cable-emanation-shandong/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-06-trojpix-air-gap-video-cable-emanation-shandong/</guid><description>Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.</description><pubDate>Mon, 06 Jul 2026 15:00:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item><item><title>Armored Likho Ties BusySnake to Power-Sector Spying</title><link>https://0daynews.com/articles/2026-07-04-armored-likho-busysnake-power-sector-kaspersky/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-armored-likho-busysnake-power-sector-kaspersky/</guid><description>Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.</description><pubDate>Sat, 04 Jul 2026 05:15:00 GMT</pubDate><category>ICS / OT</category><category>article</category></item></channel></rss>