threat-intel CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks CISA has revealed that over 100 internet-exposed water systems were targeted in July cyberattacks, primarily linked to Iranian threat actors. The agency is urging water and wastewater utilities to significantly reduce their internet exposure to mitigate future attacks on operational technology systems. SecurityWeek · 4d ago High IRUSiototcyberattack
threat-intel Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets Two critical vulnerabilities are being actively exploited to steal cloud credentials and secrets. MLflow (versions < 3.15.0) is experiencing SSRF attacks, allowing attackers to access cloud metadata and exfiltrate sensit… The Hacker News · Aug 18, 2026 Critical CVE-2026-64849CVE-2026-25895CVE-2026-25939ssrfpath traversalremote code execution
threat-intel ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks This week’s cybersecurity recap highlighted a concerning trend of AI-powered exploit generation, alongside a series of high-impact security incidents. A vulnerability in Coldcard hardware wallets led to an $88.6 million… The Hacker News · Aug 3, 2026 High CVE-2026-42897CVE-2026-66066CVE-2026-48449USIRaiexploithardware wallet
threat-intel US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States A coordinated cyberattack targeting the water and wastewater sector in the United States has expanded beyond Minnesota to at least seven states, with Iran suspected as the primary actor. The attacks are focused on operat… SecurityWeek · Aug 3, 2026 High IRUNAUotcyberattackiran
threat-intel CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs The CISA is urging water and wastewater systems to rapidly secure their operational technology (OT), specifically programmable logic controllers (PLCs), following a coordinated cyberattack in Minnesota that disrupted aut… SecurityWeek · Jul 30, 2026 High IRplcotcyberattack
threat-intel OT Security Startup Frenos Raises $1.52 Million Frenos, a US-based OT security startup, has raised an additional $1.52 million in funding, bringing their total to $6.4 million. This investment will be used to bolster their customer support and accelerate AI research a… SecurityWeek · Jul 28, 2026 Info otcybersecuritydigital twin
threat-intel CI Fortify – Advice for isolating vital systems The U.S. government, through CISA and ASD’s ACSC, has released guidance for critical infrastructure organizations to isolate vital operational technology and enabling systems from other networks. This proactive measure i… CISA Advisories · Jul 28, 2026 Medium critical infrastructurecybersecurityisolation
vulnerability Rockwell Patches Code Execution Flaws in Arena Simulation Software Rockwell Automation has released a patch to address four critical vulnerabilities in its Arena Simulation software, preventing attackers from executing arbitrary code on affected systems. These flaws stem from improper d… SecurityWeek · Jul 25, 2026 Critical CVE-2026-8085CVE-2026-8312CVE-2026-8313otsimulationmemory corruption
threat-intel Federal agencies broaden alert on Iran-linked OT attacks The U.S. government is widening its alert about ongoing cyberattacks targeting operational technology (OT) systems by Iranian-linked hackers. The initial warning focused on Rockwell Automation and Allen-Bradley PLCs, and… The Record · Jul 22, 2026 Medium IRotcyberattackplc
threat-intel Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy A collaborative research effort between Palo Alto Networks and Siemens has uncovered a critical, chained exploit within the Siemens ROX II operational technology (OT) switches. The vulnerability chain consists of three z… Palo Alto Unit 42 · Jul 17, 2026 Critical CVE-2025-40948CVE-2025-40947CVE-2025-40949otvulnerabilitycommand-injection
threat-intel Legacy Systems, Real-World Impacts: The Reality of OT Security This article highlights the unique challenges of securing Operational Technology (OT) systems compared to traditional IT environments. Unlike IT, OT vulnerabilities often lead to devastating real-world consequences – lik… SecurityWeek · Jul 16, 2026 High otcybersecurityvulnerability
threat-intel ISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 8, 2026 High icsotvulnerability
threat-intel ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. The report indicated a s… SANS Internet Storm Center · Jul 7, 2026 High icsotvulnerability
threat-intel ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 6, 2026 High icsotindustrial control systems
ransomware Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer Mackay Sugar, Australia's second-largest raw sugar producer, experienced a ransomware attack that disrupted operations at two of its cane-processing mills. The attack, attributed to the Gentlemen ransomware group (Storm-… SecurityWeek · Jun 15, 2026 High AUransomwareaustraliasugar
threat-intel CISA and Partners Urge Hardening Automatic Tank Gauge Systems CISA, alongside several US government agencies, has issued an alert regarding malicious cyber activity targeting Automatic Tank Gauge (ATG) systems used across sectors like energy, chemicals, and transportation. Cyber ac… CISA Advisories · Jun 2, 2026 High oticstank gauges
threat-intel Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control A critical command injection vulnerability (CVE-2026-8153) was discovered in the operating system of Universal Robots’ PolyScope 5 collaborative robots. This flaw allows unauthenticated attackers to gain remote access an… Dark Reading · May 20, 2026 Critical CVE-2026-8153DEcommand injectionotrobotics
threat-intel Real-World ICS Security Tales From the Trenches This article details real-world incidents involving industrial control systems (ICS) security vulnerabilities, highlighting the challenges of securing OT environments beyond traditional IT security practices. Two separat… SecurityWeek · May 20, 2026 High IRUSicsotlateral movement
vulnerability Kieback & Peter DDC Building Controllers This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript c… CISA Advisories · May 19, 2026 Medium CVE-2026-4293AUATCNxssbuilding automationot
vulnerability Siemens Ruggedcom Rox A vulnerability has been identified in Siemens Ruggedcom Rox devices, specifically within the Scheduler functionality, allowing authenticated remote attackers to execute arbitrary commands with root privileges. This is d… CISA Advisories · May 14, 2026 Critical CVE-2025-40949DEinput validationroot privilegescheduler