Automotive Sector
4 articles covering automotive OT/ICS security
Beckhoff TwinCAT and EtherCAT Security: Attack Surface Analysis and Hardening Guide
Beckhoff TwinCAT is one of the most widely deployed PC-based control platforms in European industrial environments. This guide covers the EtherCAT network protocol attack surface, TwinCAT ADS communication security, known vulnerabilities, and practical hardening steps for OT engineers and security teams.
ICSA-26-202-07: Rockwell FactoryTalk JWT Algorithm Confusion Allows Forged Authentication Tokens
CISA advisory ICSA-26-202-07 documents a JWT signature bypass in Rockwell Automation's FactoryTalk Services Platform 6.60. The vulnerability lets an attacker set the JWT algorithm to 'none' during Okta Web Authentication, forge tokens without a valid signature, and impersonate authorised users to access industrial system configurations. Patch is available.
PROFINET Security: Attack Surface Analysis and Hardening for Industrial Ethernet Networks
PROFINET is the dominant real-time industrial Ethernet protocol in European manufacturing and process automation, with over 70 million installed nodes worldwide. This guide covers PROFINET's attack surface, documented exploits, network segmentation requirements, and hardening controls for OT security practitioners.
Rockwell Automation ControlLogix and CompactLogix: Vulnerability Landscape and Hardening Guidance
Rockwell Automation's Logix family of programmable automation controllers has accumulated significant vulnerability history. This analysis covers key CVEs affecting ControlLogix and CompactLogix platforms, exploitation implications for industrial operations, and vendor-specific hardening steps.