vulnerability Multiples vulnérabilités dans les produits Siemens (12 août 2026) Siemens has announced multiple vulnerabilities in its industrial automation products, including Desigo DXR2, PXC3, PXC4, PXC5, and IoT2050 Advanced. These vulnerabilities could allow attackers to execute arbitrary code r… CERT-FR · Aug 12, 2026 High CVE-2026-58115CVE-2026-59693industrial control systemsicscybersecurity
threat-intel Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine Polish power plant operators suffered a significant cyberattack that led to the shutdown of a steam turbine and process-water treatment system. The attack exploited a private cellular network used by the grid operator to… The Hacker News · Aug 11, 2026 High CVE-2023-32349CVE-2023-32350PLprivate apnindustrial control systemscyberattack
threat-intel Multistate Water System Attacks Widen, Iran Suspected A coordinated campaign targeting water and wastewater systems across multiple states is underway, potentially linked to Iran and the CyberAv3ngers hacktivist group. Threat actors are exploiting poorly secured PLCs – indu… Dark Reading · Aug 10, 2026 High IRplccyberattackcritical infrastructure
threat-intel Poland uncovers second heat plant cyberattack that went hidden for months Poland’s CERT Polska uncovered a cyberattack targeting a combined heat and power plant that went undetected for months, highlighting a previously unknown attack vector involving private cellular networks. The attack, occ… The Record · Aug 10, 2026 High PORUcyberattackindustrial control systemsprivate cellular network
threat-intel Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Polish CERT has revealed a second, parallel cyberattack targeting a smaller CHP plant supplying heat to 50,000 residents, utilizing a novel private APN attack vector. The attack, attributed to Russian APT group Sandworm,… SecurityWeek · Aug 10, 2026 High PLicsindustrial control systemsprivate apn
threat-intel Water Sector Cyberattacks Reportedly Hit at Least 12 States A growing number of US states, including Minnesota, Michigan, and Georgia, are experiencing cyberattacks targeting water and wastewater facilities. The FBI has linked these attacks to Iran, specifically targeting interne… SecurityWeek · Aug 5, 2026 High IRicsiotcyberattack
threat-intel US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States A coordinated cyberattack targeting the water and wastewater sector in the United States has expanded beyond Minnesota to at least seven states, with Iran suspected as the primary actor. The attacks are focused on operat… SecurityWeek · Aug 3, 2026 High IRUNAUotcyberattackiran
threat-intel CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs The CISA is urging water and wastewater systems to rapidly secure their operational technology (OT), specifically programmable logic controllers (PLCs), following a coordinated cyberattack in Minnesota that disrupted aut… SecurityWeek · Jul 30, 2026 High IRplcotcyberattack
threat-intel Minnesota Water Utility Attacks Expose Sector's Cyber-Risks A coordinated cyberattack targeting over 30 community water systems in Minnesota, potentially linked to Iran-backed actors, highlighted the vulnerability of critical infrastructure to state-sponsored cyber espionage. The… Dark Reading · Jul 30, 2026 High IRirancyberattackcritical infrastructure
threat-intel Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline A coordinated cyberattack targeted over 30 community water systems in Minnesota, leading to operational disruptions and communications failures. While the exact number of compromised systems remains unclear, the attacks… The Hacker News · Jul 29, 2026 High UNcritical infrastructureindustrial control systemscyberattack
threat-intel Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks Dozens of water utilities in Minnesota were targeted in a coordinated cyberattack on their operational technology (OT) systems. While services remained operational, attackers disrupted automated control functions, leadin… SecurityWeek · Jul 29, 2026 High IRiotindustrial control systemscyberattack
vulnerability Siemens Mendix Runtime A gap in Siemens Mendix Runtime documentation regarding access rules for the System.User entity has been identified, potentially leading developers to apply overly permissive access rules, exposing sensitive user data an… CISA Advisories · Jul 28, 2026 Critical CVE-2026-7891mendixaccess-controlindustrial-control-systems
vulnerability Siemens Desigo CC A stack-based buffer overflow vulnerability in Siemens Desigo CC versions V7, V8, and V9 (prior to V9.0.1) has been identified, potentially allowing remote code execution. Siemens has released patches and recommends upda… CISA Advisories · Jul 28, 2026 High CVE-2025-15467DEstack-buffer-overflowcwe-787open ssl
vulnerability Siemens SIMATIC S7-PLCSIM Advanced A vulnerability in Siemens SIMATIC S7-PLCSIM Advanced could allow an unauthenticated attacker to cause a denial-of-service condition by overwhelming the application with high-volume multicast network traffic. Siemens is… CISA Advisories · Jul 28, 2026 High CVE-2026-54429DEindustrial control systemscve-2026-54429denial of service
threat-intel ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories This week's "ThreatsDay" bulletin highlights a diverse range of security threats, from malware targeting PLCs with Iranian involvement to AI-generated vulnerabilities and deceptive apps. Key concerns include a GitHub sup… The Hacker News · Jul 23, 2026 High IRmalwarethreat intelligencesupply-chain
threat-intel US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices The US government has issued an updated cybersecurity advisory warning of ongoing Iranian-linked attacks targeting industrial control systems (ICS) manufactured by Siemens, Schneider Electric, and Rockwell Automation. Ha… SecurityWeek · Jul 23, 2026 High IRicsindustrial control systemsplc
threat-intel Federal agencies broaden alert on Iran-linked OT attacks The U.S. government is widening its alert about ongoing cyberattacks targeting operational technology (OT) systems by Iranian-linked hackers. The initial warning focused on Rockwell Automation and Allen-Bradley PLCs, and… The Record · Jul 22, 2026 Medium IRotcyberattackplc
vulnerability Siemens IAM Client Siemens has identified a critical unquoted search path vulnerability in its IAM Client SDK, potentially allowing an authenticated local attacker to escalate privileges. Multiple Siemens products, including COMOS, Designc… CISA Advisories · Jul 21, 2026 Critical CVE-2025-40945cwe-426unquoted search pathiam client
threat-intel Siemens SIDIS Secured SmartPlug Siemens SIDIS Secured SmartPlug versions prior to V7.26.0310 are affected by multiple vulnerabilities stemming from components like OpenSSL, OpenSSH, and libarchive. These vulnerabilities include side-channel attacks, in… CISA Advisories · Jul 21, 2026 High CVE-2022-23303CVE-2019-9494CVE-2022-23304vulnerabilitysupply-chainopen ssl
vulnerability Siemens Opcenter X Siemens Opcenter X versions prior to V2604 contain a critical authentication bypass vulnerability, allowing an unauthenticated attacker to gain full unauthorized access to the application. Siemens has released a new vers… CISA Advisories · Jul 21, 2026 Critical CVE-2026-56451DEauthenticationjwtcwe-347