threat-intel CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks CISA has revealed that over 100 internet-exposed water systems were targeted in July cyberattacks, primarily linked to Iranian threat actors. The agency is urging water and wastewater utilities to significantly reduce their internet exposure to mitigate future attacks on operational technology systems. SecurityWeek · 4d ago High IRUSiototcyberattack
vulnerability Siemens SIMATIC IoT2050 Advanced A vulnerability in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed allows unauthenticated remote attackers to create malicious flows and execute arbitrary code on the underlying ser… CISA Advisories · 5d ago Critical CVE-2026-58115vulnerabilityindustrial control systemsnode-red
threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware
threat-intel AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure A U.S. government advisory warns of an active threat targeting critical infrastructure organizations, specifically Siemens S7 PLCs, utilizing AI-generated exploit scripts. Threat actors are leveraging internet scanning t… The Hacker News · Aug 20, 2026 High USCHplcindustrial control systemics
threat-intel Hackers Using AI to Target Siemens PLCs in Critical US Sectors US government agencies have issued a cybersecurity advisory warning critical infrastructure organizations about a growing threat of hackers using AI to target Siemens PLCs. The attackers are scanning for exposed PLCs and… SecurityWeek · Aug 20, 2026 High USicsplccybersecurity
threat-intel NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology The NSA and FBI have issued an urgent warning about a growing threat where hackers are utilizing AI-generated exploit scripts to target critical infrastructure organizations, specifically focusing on Siemens S7 Series PL… The Record · Aug 19, 2026 High IRplccybersecurityai
threat-intel Defending Against an Active Threat to Siemens S7 Series PLCs The National Security Agency (NSA), CISA, FBI, DOE, and EPA are issuing an advisory warning of an active cyber threat targeting Siemens S7 Series Programmable Logic Controllers (PLCs). Threat actors are leveraging AI to… CISA Advisories · Aug 19, 2026 High icsplccybersecurity
threat-intel Prison for data analyst who tried to extort $2.5 million from his employer A former data analyst, Cameron Curry, was sentenced to 24 months in prison after attempting to extort $2.5 million from his former employer, Brightly Software (now part of Siemens). Curry gained access to sensitive emplo… Graham Cluley · Aug 19, 2026 High USinsider threatdata breachextortion
vulnerability Siemens Simcenter Nastran A stack overflow vulnerability exists in Siemens Simcenter Nastran and Femap versions prior to V2606, potentially allowing remote code execution. Siemens has released updates to address the issue. Organizations are advis… CISA Advisories · Aug 18, 2026 High CVE-2026-59086stack-overflowremote-code-executionindustrial-control-systems
vulnerability Siemens LOGO! Soft Comfort Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling, allowing a local attacker to extract the master key and decrypt project data or remove passwords. These v… CISA Advisories · Aug 13, 2026 High CVE-2026-57262CVE-2026-57263GEencryptionpasswordhardcoded
vulnerability Siemens License Server (SLS) Siemens License Server (SLS) versions prior to 5.3 are vulnerable to two separate attacks: a local privilege escalation due to an insecure sudoers policy, allowing an attacker to execute arbitrary commands and plant mali… CISA Advisories · Aug 13, 2026 Critical CVE-2026-69108CVE-2026-69109vulnerabilitysudopath traversal
vulnerability Siemens Solid Edge Siemens Solid Edge versions 2025 and 2026 are vulnerable to multiple file parsing vulnerabilities, including out-of-bounds reads and writes, and use-after-free errors, when processing PAR, PSM, and DFT files. These vulne… CISA Advisories · Aug 13, 2026 High CVE-2026-50058CVE-2026-50059CVE-2026-50060vulnerabilityfile-parsingcad
vulnerability Siemens Siveillance Video Siemens has released security advisories addressing a Remote Code Execution (RCE) vulnerability in its Siveillance Video Management Servers. Versions V2023 R3 through V2025 are affected, allowing users with edit permissi… CISA Advisories · Aug 13, 2026 High CVE-2026-3014rcecve-2026-3014industrial control systems
vulnerability Siemens Parasolid Siemens Parasolid versions V38.0 and V38.1 are vulnerable to an out-of-bounds read vulnerability when parsing X_T files, potentially allowing an attacker to execute arbitrary code. Siemens has released updates to address… CISA Advisories · Aug 13, 2026 High CVE-2026-64629vulnerabilitysupply-chainindustrial-control-systems
vulnerability Siemens Desigo DXR and PXC Controllers A denial-of-service vulnerability exists in Siemens Desigo DXR and PXC controllers, exploitable by sending malformed BACnet packets. This can cause the devices to stop responding to queries, requiring a device reset or r… CISA Advisories · Aug 13, 2026 High CVE-2026-59693industrial control systemsbacnetdenial of service
vulnerability Siemens Simcenter Femap Siemens Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads BMP files. An attacker could exploit these flaws to execute code within the current process, potentiall… CISA Advisories · Aug 13, 2026 High CVE-2026-59700CVE-2026-59701vulnerabilitycontrol-systemfile-parsing
threat-intel Siemens RUGGEDCOM APE1808 A CISA advisory, in collaboration with Siemens ProductCERT, highlights vulnerabilities in Siemens RUGGEDCOM APE1808 devices when used with Fortinet NGFW. These vulnerabilities, including Cross-Site Scripting and Path Tra… CISA Advisories · Aug 12, 2026 High CVE-2026-23573CVE-2026-59839GEindustrial control systemscwe-79cwe-22
supply-chain Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack Over 2,500 organizations and 434,000 CI/CD pipelines were impacted by a supply chain attack involving the LiteLLM AI library. The attack stemmed from a compromised version of Aqua Security’s Trivy vulnerability scanner,… SecurityWeek · Aug 12, 2026 High supply chainaicredentials
supply-chain Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations A supply-chain attack linked to Aqua Security's Trivy scanner has resulted in the release of two malicious LiteLLM packages containing credential-stealing code. CloudSEK identified over 2,500 organizations potentially ex… The Hacker News · Aug 12, 2026 High CVE-2026-33634USEUsupply chaincredential theftpypi
vulnerability ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Several major industrial automation vendors – Siemens, Schneider Electric, and Phoenix Contact – released security patches to address critical vulnerabilities in their ICS products. These flaws could allow attackers to e… SecurityWeek · Aug 12, 2026 High icsindustrial control systemspatch tuesday