vulnerability Rockwell Automation 1734 POINT I/O Rockwell Automation’s 1734 POINT I/O module is vulnerable to a denial-of-service attack due to improper handling of crafted CIP messages, potentially causing a system fault and requiring a restart. CISA urges organizatio… CISA Advisories · Jul 21, 2026 Medium CVE-2026-10573USvulnerabilitydenial-of-servicecontrol systems
vulnerability Rockwell Automation FactoryTalk DataMosaix Rockwell Automation has issued a security advisory regarding a critical vulnerability (CVE-2026-9292) in its FactoryTalk DataMosaix Private Cloud software. An authenticated attacker can inject malicious scripts that are… CISA Advisories · Jul 16, 2026 Critical CVE-2026-9292cve-2026-9292xsscwe-79
threat-intel ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell This Patch Tuesday saw significant security updates released by Siemens, Schneider Electric, Rockwell Automation, ABB, and Mitsubishi Electric to address a range of vulnerabilities in their industrial control systems (IC… SecurityWeek · Jul 15, 2026 High GEicspatch tuesdayvulnerability
vulnerability Rockwell Automation 1715-AENTR EtherNet/IP Adapter Rockwell Automation’s 1715-AENTR EtherNet/IP Adapter is vulnerable to a security flaw that could allow unauthorized remote access to a debug port, potentially leading to file deletion, task stopping, memory modification,… CISA Advisories · Jul 14, 2026 High CVE-2026-10577vulnerabilitycveindustrial control systems
threat-intel ISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 8, 2026 High icsotvulnerability
vulnerability Siemens Mendix Studio Pro Siemens has issued an advisory regarding a critical file parsing vulnerability in Mendix Studio Pro. Versions prior to V10.24.21 and V11.6.7 are susceptible to code execution if a user opens and runs a maliciously crafte… CISA Advisories · Jul 7, 2026 Critical CVE-2026-48192code-injectionindustrial-control-systemics
threat-intel Threat landscape for industrial automation systems. Q1 2026 In Q1 2026, the effectiveness of blocking malicious objects on industrial control systems (ICS) decreased significantly, reaching 19.6%, a three-year low. Growth in blocked threats was most pronounced in Southern Europe… Securelist · Jul 7, 2026 Medium UNRUSOicsindustrial control systemsmalware
threat-intel ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. The report indicated a s… SANS Internet Storm Center · Jul 7, 2026 High icsotvulnerability
threat-intel ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 6, 2026 High icsotindustrial control systems
vulnerability Rockwell Automation FactoryTalk Analytics PavilionX This advisory from CISA details a critical vulnerability in Rockwell Automation’s FactoryTalk Analytics PavilionX software, specifically versions below 7.01. The flaw, stemming from improper authorization enforcement in… CISA Advisories · Jun 16, 2026 Critical CVE-2025-14272UScveauthorizationapi
threat-intel CISA and Partners Urge Hardening Automatic Tank Gauge Systems CISA, alongside several US government agencies, has issued an alert regarding malicious cyber activity targeting Automatic Tank Gauge (ATG) systems used across sectors like energy, chemicals, and transportation. Cyber ac… CISA Advisories · Jun 2, 2026 High oticstank gauges
threat-intel This month in security with Tony Anscombe – May 2026 edition In May 2026, Poland experienced cyberattacks targeting industrial control systems at water treatment facilities, mirroring attacks against the Polish energy sector. Simultaneously, a previously unknown group conducted a… WeLiveSecurity · May 29, 2026 Medium PLicscyberattacksai
threat-intel Real-World ICS Security Tales From the Trenches This article details real-world incidents involving industrial control systems (ICS) security vulnerabilities, highlighting the challenges of securing OT environments beyond traditional IT security practices. Two separat… SecurityWeek · May 20, 2026 High IRUSicsotlateral movement
threat-intel Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) This report from Palo Alto Unit 42 details a significant escalation of cyber risk originating from Iran following a 47-day internet outage. Iranian threat actors, identified as CL-STA-1128 (Cyber Av3ngers), are now aggre… Palo Alto Unit 42 · Apr 17, 2026 High USIRILoticsphishing