Energy Sector
85 articles covering energy OT/ICS security
Johnson Controls Simplex Incident Manager: ICSA-26-232-01 Discloses Cleartext Credential Storage Flaw
CISA published ICSA-26-232-01 on August 20, 2026, disclosing CVE-2026-27875, a cleartext-storage-in-memory vulnerability in Johnson Controls Simplex Incident Manager, an emergency and life-safety incident coordination platform used across critical manufacturing, commercial facilities, transportation, energy, and government sites worldwide. This advisory covers the vulnerability, exploitation requirements, and mitigations.
CVSS 10.0: Unauthenticated Root Command Injection in Haiwell IoT Cloud HMI Gateway (CVE-2026-19188)
A maximum-severity OS command injection flaw in Haiwell's IoT Cloud HMI Gateway lets unauthenticated remote attackers execute arbitrary commands as root through a Socket.io ping-test feature. CISA advisory ICSA-26-225-02 details the flaw, its exposure across energy, water, and manufacturing deployments, and patch guidance.
CISA Advisory ICSA-26-225-05: Four Vulnerabilities in ANDRITZ HIPASE-250 Hydropower SCADA
CISA published ICS advisory ICSA-26-225-05 on August 13, 2026 covering four vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA, a hydropower plant SCADA and automation platform. Flaws include an unauthenticated data/config endpoint, recoverable password storage, an unauthenticated logging-suppression endpoint, and a hard-coded VNC password on engineering workstations.
CISA Advisory AA26-231A: Active Threat Actors Use AI-Generated Exploitation Scripts Against Siemens S7 Series PLCs
NSA, CISA, FBI, DOE, and EPA jointly warned on 19 August 2026 that threat actors are scanning for and probing internet-exposed Siemens S7-200 through S7-1500 controllers using AI-generated exploitation scripts disguised as monitoring tools, communicating over the S7comm protocol on TCP/102.
ICSA-25-352-07: Rockwell Micro800 Series IPv6 and CIP Fuzzing Flaws Enable Remote Denial of Service
CISA advisory ICSA-25-352-07 details two Rockwell Automation vulnerabilities -- CVE-2025-13823 and CVE-2025-13824 -- in Micro820, Micro850, and Micro870 controllers. Malformed IPv6 and CIP packets can drive the PLCs into recoverable or hard fault, halting control logic on machines and skid-level equipment across manufacturing and utility sites.
Phoenix Contact PLCnext and mGuard Security: CISA Advisory Roundup and Hardening Guide
Phoenix Contact is among the top five ICS vendors by CISA ICS-CERT advisory volume in 2026. Vulnerabilities span the PLCnext runtime environment, mGuard security routers, and WP 6xxx web panel HMIs — covering authentication bypass, remote code execution, cross-site scripting, and weak cryptography. This guide consolidates the advisory landscape and provides OT-specific hardening steps for each product family.
Digital Twin Security: How Virtual Replicas Expand the OT Attack Surface
Industrial digital twins — virtual replicas of physical assets, processes, and systems — are expanding rapidly across energy, manufacturing, and transport. They introduce new network connectivity, data aggregation risks, and attack vectors into OT environments that have historically been air-gapped or tightly isolated.
CISA AA26-097A: Iranian-Affiliated Actors Escalate PLC Exploitation Across Water, Energy, and Municipal OT
A July 2026 update to CISA advisory AA26-097A expands the confirmed scope of Iranian-affiliated PLC exploitation to Schneider Electric Modicon M340 and Siemens S7-1200 controllers, adding to the initial Rockwell Allen-Bradley targeting disclosed in April. Active exploitation of internet-facing PLCs is now confirmed across water, energy, and government facility sectors.
Siemens SIMATIC IoT2050 Advanced: Maximum-Severity Unauthenticated RCE in Industrial IoT Gateways
Siemens published a maximum-severity advisory in August 2026 Patch Tuesday covering a missing authentication vulnerability in SIMATIC IoT2050 Advanced devices. An unauthenticated remote attacker can execute arbitrary code with elevated privileges on the underlying server — a critical risk for IT/OT bridging deployments where these gateways connect operational technology networks to enterprise IT and cloud systems.
CVE-2026-59310 in OT Environments: Protecting Virtualised SCADA and Historian Infrastructure
VMware vCenter CVE-2026-59310 (CVSS 9.8, actively exploited) presents an acute risk in OT environments where virtualisation hosts historian servers, HMIs, engineering workstations, and SCADA applications. This advisory covers which OT components are most exposed, how vCenter compromise translates to OT network impact, and the OT-specific mitigations that reduce risk while patching proceeds.
Johnson Controls C·CURE 9000 RCE Vulnerability: ICSA-26-204-01 Advisory and Mitigation
CISA published ICSA-26-204-01 on August 11, 2026, disclosing CVE-2026-21655, a remotely exploitable code execution vulnerability in Johnson Controls C·CURE 9000 physical access control systems. With a CVSS score of 9.8 and no authentication required, the flaw affects C·CURE 9000 versions prior to 3.0.3 deployed in enterprise and critical infrastructure physical security management. This advisory covers the vulnerability details, affected versions, exploitation risk in OT-adjacent environments, and recommended mitigations.
Wind Energy Cybersecurity: Turbine Controllers, SCADA, and Grid Integration Attack Surface
Wind farms depend on industrial control systems that manage turbine operation, power output, and grid integration — all increasingly networked and internet-connected for remote monitoring. This sector briefing covers the attack surface, documented threat actor interest, and hardening priorities for wind energy OT security teams.
Modbus and DNP3 Under Attack: Protocol Security and Detection for OT Networks
Modbus and DNP3 are the dominant SCADA communication protocols in energy, water, and manufacturing — and both were designed with zero authentication. This guide covers the specific attack techniques these protocols enable, real-world exploitation patterns from incident reports, and how OT security teams can add detection without disrupting production.
CISA ICS Advisories: August 2026 Roundup — Siemens, Honeywell, GE Vernova
CISA published multiple ICS security advisories in the first week of August 2026, covering critical vulnerabilities in Siemens SINEC NMS, Honeywell Experion PKS, and GE Vernova grid management systems. This roundup covers the disclosed vulnerabilities, affected product versions, CVSS scores, and recommended mitigations for OT security teams.
IEC 60870-5-104 Security: Protocol Analysis and Hardening for Power Grid SCADA
IEC 60870-5-104 (IEC 104) carries power grid telemetry and control traffic across TCP/IP with no authentication and no encryption in its base specification. It is deployed in substations, transmission grids, and distribution networks worldwide. This guide covers the attack surface, known exploitation patterns, and practical hardening measures.
Beckhoff TwinCAT and EtherCAT Security: Attack Surface Analysis and Hardening Guide
Beckhoff TwinCAT is one of the most widely deployed PC-based control platforms in European industrial environments. This guide covers the EtherCAT network protocol attack surface, TwinCAT ADS communication security, known vulnerabilities, and practical hardening steps for OT engineers and security teams.
CISA Updates AA26-097A: Iranian IRGC-Affiliated Actors Expand PLC Targeting to Siemens and Schneider Electric
CISA revised advisory AA26-097A on 22 July 2026, expanding the scope of Iranian IRGC-affiliated ICS targeting beyond the original Rockwell Automation and Unitronics findings to include Siemens TIA Portal and Schneider Electric environments. The update also adds new detection guidance for identifying malicious modifications within reusable PLC code modules — a forensic challenge distinct from detecting initial access.
OT Endpoint Security: Deploying EDR and XDR in Industrial Environments Without Disrupting Control Systems
Deploying endpoint detection and response tools on OT assets — PLCs, HMIs, engineering workstations, historians — requires a different approach than IT EDR rollouts. Aggressive scanning, real-time interception, and performance overhead that are acceptable on IT endpoints can destabilise industrial control systems. This guide covers agent versus agentless approaches, deployment sequencing, and what OT-specific EDR products actually monitor.
CyberAv3ngers Hits 30+ Minnesota Water Utilities: CISA AA26-097A Updated Advisory for PLC Operators
Iran-linked CyberAv3ngers struck more than 30 Minnesota water systems on July 26-27, 2026, exploiting Unitronics Vision Series default credentials and CVE-2021-22681 to take one plant offline. CISA updated advisory AA26-097A with new detection guidance for Rockwell Automation environments. Actionable steps for water and energy OT operators.
Private 5G and LTE in OT Environments: Attack Surface and Security Architecture for Industrial Cellular
Manufacturers, utilities, and logistics operators are deploying private 5G and LTE networks to enable wireless OT connectivity for AGVs, robotics, sensors, and field devices. This guide covers the security architecture differences from Wi-Fi, the attack surface specific to industrial cellular, and hardening guidance for private cellular deployments.
AVEVA System Platform SCADA Security: Attack Surface, Vulnerabilities, and Hardening Guide
AVEVA System Platform (formerly Wonderware) is one of the most widely deployed SCADA and HMI platforms in industrial environments. This guide covers its attack surface, known vulnerability classes, and hardening practices for security teams and OT engineers.
ICSA-26-202-07: Rockwell FactoryTalk JWT Algorithm Confusion Allows Forged Authentication Tokens
CISA advisory ICSA-26-202-07 documents a JWT signature bypass in Rockwell Automation's FactoryTalk Services Platform 6.60. The vulnerability lets an attacker set the JWT algorithm to 'none' during Okta Web Authentication, forge tokens without a valid signature, and impersonate authorised users to access industrial system configurations. Patch is available.
OT Patch Management in Practice: A Field Guide for Industrial Control System Operators
Patching industrial control systems is categorically different from IT patching. Production constraints, vendor dependency, and long asset lifecycles make standard patch cadences unworkable. This guide covers compensating controls, vendor coordination, and a realistic patching process for OT environments.
Nuclear Sector OT Cybersecurity: Regulatory Requirements, APT Targeting, and Unique Risk Profile
Nuclear facilities operate under the most stringent OT cybersecurity regulatory frameworks in any sector. This briefing covers NRC and IAEA requirements, documented nation-state targeting campaigns, and the sector-specific defensive challenges that distinguish nuclear from other critical infrastructure.
AI Workflow Tools in OT Environments: The Attack Surface Industrial Operators Are Building Without Noticing
n8n, Langflow, and Node-RED are being adopted in industrial environments for AI-driven process analytics, predictive maintenance, and historian integration. The NadMesh botnet now specifically targets these tools. This creates a new attack path from exposed AI workflow interfaces to OT data historians and, in poorly segmented environments, to SCADA systems.
July 2026 ICS Patch Tuesday: Siemens CVSS 10 Auth Bypass, ABB and Rockwell Advisories
July 2026's ICS Patch Tuesday brought nine Siemens advisories including a CVSS 10.0 authentication bypass in Opencenter X, three ABB advisories, and a Rockwell advisory. Here's what OT/ICS security teams need to prioritise and the operational context for each critical finding.
OT Threat Hunting with Passive Network Monitoring: An ICS Practitioner Guide
OT threat hunting is fundamentally different from IT threat hunting — you can't run endpoint agents on PLCs, and active scanning can destabilise control systems. This guide covers passive network monitoring with Zeek and Suricata ICS decoders, OT-specific hunting hypotheses, and the protocol anomalies that separate legitimate traffic from attacker activity in industrial environments.
Nation-State Router Targeting at the OT Perimeter: Technical Response to CISA AA26-194A
CISA Advisory AA26-194A documents Russian FSB Center 16 exfiltrating router configurations from critical infrastructure globally via SNMP and Cisco Smart Install. For OT environments, perimeter routers hold additional sensitivity: they contain VPN configurations, routing to SCADA networks, and credentials that can enable lateral movement from IT into OT. This guide covers the OT-specific implications and hardening steps.
CISA Advisory ICSA-26-188-02: Hitachi Energy PROMOD V Supply Chain Management Vulnerabilities
CISA published ICS advisory ICSA-26-188-02 on July 7 2026 covering multiple vulnerabilities in Hitachi Energy PROMOD V, a supply chain management and planning tool used in energy sector operations. The advisory includes path traversal, authentication weaknesses, and an insecure direct object reference flaw.
ICS Patch Tuesday July 2026: Siemens TIA Portal RCE, Schneider IGSS Critical, Rockwell 12 Advisories
July 2026 ICS Patch Tuesday brings a significant advisory load: Siemens releases 18 advisories including a critical TIA Portal remote code execution flaw, Schneider Electric addresses a critical IGSS SCADA vulnerability, and Rockwell Automation publishes 12 advisories covering FactoryTalk and Logix controllers. Prioritisation guidance for OT security teams.
CISA July 2026 ICS Advisories: Satellite Ground Station Terminals and Building Automation Vulnerabilities
CISA's July 2026 ICS advisory batches covered 13 advisories across satellite communication terminals, EV charging management systems, and building automation controllers. This roundup covers the highest-priority items for OT and critical infrastructure security teams.
IEC 62443 in Practice: Security Levels, Zone-Conduit Model, and Implementation for OT Practitioners
IEC 62443 is the international standard series for industrial automation and control system security. This practitioner guide covers the security level framework, the zone-conduit network architecture model, and what implementation actually looks like for OT security teams — from SL-1 baseline controls to SL-3 nation-state-resistant configurations.
FSB Center 16 Poland Grid Attack: OT Sector Analysis and Critical Infrastructure Implications
The UK and EU attribution of December 2025's Poland energy grid attack to FSB Center 16 — an operation that nearly caused a blackout for half a million people — has direct implications for OT security in European energy and water sectors. Analysis of the attack characteristics, attribution dispute, and what ICS operators should take from the formal sanctions.
MQTT Security in IIoT: Authentication, TLS, and Broker Hardening
MQTT is the dominant messaging protocol for Industrial IoT — used in energy monitoring, manufacturing telemetry, building automation, and smart grid applications. Its minimal design and widespread default configurations leave most deployments exposed to unauthenticated access, data interception, and command injection. This guide covers the attack surface and hardening approach.
Smart Grid and Advanced Metering Infrastructure (AMI) Cybersecurity: Attack Surface and Hardening in 2026
Advanced Metering Infrastructure connects tens of millions of smart meters to utility head-end systems via RF mesh and cellular networks. The attack surface — bidirectional communication, large device counts, heterogeneous firmware, and direct connection to distribution grid controls — is poorly understood outside specialist OT security teams.
U-Boot Vulnerabilities in Industrial Control Systems: Embedded Firmware Security in 2026
U-Boot is the dominant open-source bootloader for embedded Linux devices — including industrial routers, RTUs, PLCs, and SCADA components. Vulnerabilities in U-Boot's FIT image parsing and boot verification logic have direct implications for OT device firmware integrity and secure boot trust chains.
FrostyGoop: The ICS Malware That Weaponised Modbus TCP Against Energy Infrastructure
FrostyGoop (BUSTLEBERM) is the first publicly documented ICS-specific malware to directly communicate with industrial devices via Modbus TCP. Its January 2024 deployment against a Ukrainian district heating company — disrupting heat for 600 buildings in winter — demonstrates the operational impact of OT-native attack tools.
GhostLock CVE-2026-43499: Advisory for OT Environments Running Linux-Based Historian and SCADA Systems
The GhostLock Linux kernel vulnerability (CVE-2026-43499) enables local privilege escalation to root in approximately five seconds with 97% reliability. OT environments running Linux-based historian servers, OPC-UA gateways, and SCADA platforms are directly affected. Patching and mitigation guidance for industrial operators.
IEC 61850 Substation Automation Security: Attack Surface and Hardening for Power Grid Operators
IEC 61850 is the dominant protocol for digital substation automation — and it was designed for operational reliability, not security. GOOSE messages carry no authentication. MMS sessions use optional TLS that most deployments skip. This analysis covers the threat model and practical hardening for utilities and grid operators.
ABB PCM600 ICSA-26-120-02: Arbitrary Code Execution via Malicious Messages in Protection Relay Configuration
CISA advisory ICSA-26-120-02 documents a critical code execution vulnerability in ABB's PCM600 Protection and Control IED Manager, exploitable via malicious message processing through a vulnerable SharpZip.dll component. The tool is widely deployed for configuring protection relays in energy and critical manufacturing. No authentication is required for exploitation.
Modbus Protocol Security: Attack Surface, Exploitation, and OT Network Hardening
Modbus is the most widely deployed industrial protocol in the world — and one of the least secure. This guide covers the Modbus attack surface, documented exploitation techniques used against OT environments, and practical hardening measures for energy, water, and manufacturing defenders.
ICSA-26-181-02: FUXA SCADA CVE-2026-13207 -- Path Traversal to Unauthenticated RCE
ICS-CERT advisory ICSA-26-181-02 covers a dot-segment path normalization bypass in FUXA open-source SCADA software that allows unauthenticated remote code execution. CVSS v4 score 8.6. Deployments in water, energy, and manufacturing are exposed.
OT Incident Response: The First 48 Hours
When a cyber incident hits an operational technology environment, the first 48 hours determine whether a brief outage becomes a prolonged shutdown. This playbook covers the critical decisions, sequencing, and OT-specific considerations that IR teams need to get right from the first alert.
Siemens S7comm Protocol: Attack Surface, Unauthenticated Access, and OT Network Detection
S7comm is Siemens' proprietary PLC communication protocol. Legacy S7comm lacks authentication and encryption, enabling unauthenticated read/write access to process data and PLC control commands. This guide covers the attack surface, documented exploit techniques, and detection approaches for OT defenders.
CISA June 2026 ICS Advisories: Siemens WinCC and Rockwell RSLinx RCE
CISA released a batch of 10 ICS advisories on June 23, 2026, including critical vulnerabilities in Siemens WinCC Certificate Manager and SIPROTEC 5. Separately, ICSA-26-167-02 documents an unauthenticated stack-based buffer overflow in Rockwell Automation RSLinx Classic enabling remote code execution.
EV Charging Infrastructure Cybersecurity: OCPP Vulnerabilities, Grid Attack Surfaces, and Operator Obligations
The rapid buildout of EV charging infrastructure has created a new OT attack surface at the intersection of transportation, energy, and consumer technology. This briefing covers OCPP protocol vulnerabilities, documented attack incidents, the grid stability risk from coordinated charging manipulation, and what operators need to implement to meet emerging regulatory standards.
EtherNet/IP and CIP Security: Attack Surface, Vulnerabilities, and Hardening
EtherNet/IP is the dominant industrial Ethernet protocol in North American manufacturing, used in Allen-Bradley PLCs, robotics, and drive systems. This analysis covers the CIP protocol attack surface, known exploitation patterns, CIP Security extension adoption, and network hardening guidance.
Securing OT Remote Access: VPN, ZTNA, and Jump Server Architecture for Industrial Networks
Remote access to operational technology environments expanded dramatically during 2020-2022 and was never fully locked down. This guide covers the specific risks of each remote access pattern — vendor VPNs, site VPNs, jump servers, and ZTNA — and the hardening steps that reduce the attack surface without breaking the maintenance workflows OT teams depend on.
PIPEDREAM and COSMICENERGY: The ICS Malware Frameworks Built for Grid Disruption
PIPEDREAM (disclosed April 2022) and COSMICENERGY (May 2023) are the two most sophisticated ICS-targeting malware frameworks to emerge since TRITON. Both target industrial protocols used in power and energy infrastructure. This analysis covers their architecture, capabilities, and what they mean for defenders.
NERC CIP in 2026: Where Compliance Ends and Real OT Security Begins
NERC CIP is the compliance baseline for US bulk electric system cybersecurity — not a security ceiling. This briefing examines where NERC CIP requirements leave real gaps: low-impact assets, supply chain enforcement, operational technology visibility, and the delta between checkbox compliance and defensible OT security posture.
Solar Inverter OT Security 2026: Solarman, Deye, and 195GW of Grid Attack Surface
Bitdefender researchers disclosed critical vulnerabilities in Solarman and Deye solar inverter management platforms in 2024-2025, covering 195GW of installed capacity. OAuth token endpoint flaws, JWT reuse attacks, and hard-coded credentials created paths from the internet to grid-connected OT equipment. This article covers the vulnerability classes, the attack surface, and what energy sector operators need to assess.
Oil and Gas Pipeline Cybersecurity: TSA Directives, OT Threat Landscape, and Compliance Requirements in 2026
The TSA's pipeline cybersecurity directives have fundamentally changed the compliance environment for US pipeline operators. This analysis covers the directive requirements, the OT threat actors specifically targeting oil and gas infrastructure, and the technical controls that actually move the needle.
PROFINET Security: Attack Surface Analysis and Hardening for Industrial Ethernet Networks
PROFINET is the dominant real-time industrial Ethernet protocol in European manufacturing and process automation, with over 70 million installed nodes worldwide. This guide covers PROFINET's attack surface, documented exploits, network segmentation requirements, and hardening controls for OT security practitioners.
CISA ICS Advisory Roundup: Inductive Automation Ignition, ICONICS GENESIS64, and Mitsubishi Electric Vulnerabilities June 2026
CISA released nine ICS advisories in June 2026 covering critical and high-severity vulnerabilities in Inductive Automation Ignition, ICONICS/Mitsubishi GENESIS64, and Axis network cameras used in OT environments. This roundup covers the operational risk and remediation priorities.
DNP3 Protocol Security: Authentication, Attack Vectors, and Hardening for Energy and Water Utilities
DNP3 is the dominant SCADA communication protocol for energy and water utilities in North America. This guide covers its security architecture, known attack vectors, DNP3 Secure Authentication v5, and practical hardening for operational environments.
Ransomware in OT Environments: How Manufacturing and Energy Operators Are Being Hit in 2026
Ransomware groups are no longer stopping at IT systems. This sector briefing covers how operators in manufacturing, energy, and water treatment are being targeted in 2026 — the specific OT attack vectors, operational impact patterns, and the defensive controls that matter most.
ICS Patch Tuesday June 2026: Critical Vulnerabilities in Siemens, Honeywell, and Mitsubishi Electric Products
The June 2026 ICS Patch Tuesday cycle brings critical and high-severity advisories affecting Siemens industrial networks, Honeywell building and process control systems, and Mitsubishi Electric PLCs. OT security teams should prioritise triage and remediation planning for affected assets.
CISA Advisory: Automatic Tank Gauge Systems Under Active Attack — What OT Operators Need to Do Now
CISA, FBI, NSA, and five other US federal agencies issued a joint advisory in June 2026 warning of active malicious cyber activity targeting internet-exposed automatic tank gauge (ATG) systems across the energy, water, transportation, and critical infrastructure sectors. Attackers are exploiting authentication bypass and command execution flaws to modify pump controls and disable safety alerts.
OPC UA Security: Attack Surface Analysis and Hardening Recommendations for Industrial Environments
OPC Unified Architecture has become the dominant interoperability standard for industrial communication — and a consistent target in ICS-focused threat campaigns. This analysis covers the OPC UA threat model, documented vulnerability classes from recent CVEs, known exploitation by nation-state actors, and the hardening steps that reduce exposure without breaking operational continuity.
Advantech WebAccess/SCADA: Multiple High-Severity Vulnerabilities Enable Remote Code Execution
Advisories covering Advantech WebAccess/SCADA document path traversal, unrestricted file upload, and SQL injection vulnerabilities rated up to CVSS 8.8. WebAccess/SCADA is deployed across manufacturing, energy, and water treatment facilities globally. This analysis covers the vulnerability classes, exploitation paths, and immediate mitigations for OT operators.
Rockwell Automation ControlLogix and CompactLogix: Vulnerability Landscape and Hardening Guidance
Rockwell Automation's Logix family of programmable automation controllers has accumulated significant vulnerability history. This analysis covers key CVEs affecting ControlLogix and CompactLogix platforms, exploitation implications for industrial operations, and vendor-specific hardening steps.
Record 508 ICS Advisories in 2025: What the Vulnerability Surge Means for OT Defenders
Forescout's analysis of 2025 ICS security advisories identifies a record 508 advisories covering 2,155 vulnerabilities — with 82% rated high or critical. Field controllers, PLCs, and SCADA systems are the primary targets, and the growing share of advisories with no available patch creates an unresolvable exposure category that demands compensating controls.
CISA's Zero Trust Roadmap for OT: What the April 2026 Joint Guidance Means for Industrial Operators
CISA's April 2026 joint guidance 'Adapting Zero Trust Principles to Operational Technology' lays out a practical roadmap for applying zero trust in environments where the standard IT playbook doesn't work — legacy protocols, uptime requirements, and safety constraints included.
Iranian APT Groups Escalate Attacks on Internet-Exposed PLCs: Water, Energy and Government Under Threat
Since March 2026, Iranian-affiliated APT actors have been conducting disruptive attacks on internet-exposed programmable logic controllers across US critical infrastructure — particularly water/wastewater, energy, and government services. A joint advisory from CISA, FBI, NSA and US Cyber Command details the campaign and recommended mitigations.
Siemens May 2026 ICS Patch Tuesday: Device Takeover in Sentron Energy Meters, Root RCE in Ruggedcom, and 300+ Third-Party Flaws in CN4100
Siemens published 18 security advisories in May 2026's ICS Patch Tuesday, with critical findings in the Sentron 7KT PAC1261 energy data manager, Ruggedcom Rox, Simatic CN4100, and Opcenter RDnL manufacturing platform. This roundup covers the highest-impact advisories with operational guidance for affected sectors.
CISA ICS Advisory Roundup: Kaleris Navis N4, Delta Electronics CNCSoft, and ABB EIBPORT (May 2026)
CISA released eight ICS advisories and one medical device advisory on May 28, 2026, covering critical vulnerabilities in transportation management, CNC motion control, and industrial building automation systems. This analysis covers the highest-impact advisories and operational guidance for affected organisations.
Schneider Electric EcoStruxure Vulnerability Roundup: Critical Advisories Affecting Energy, Manufacturing, and Data Centre Operations
Schneider Electric has issued multiple CISA-coordinated advisories in 2026 covering critical vulnerabilities across the EcoStruxure platform suite -- including a CVSS 9.8 deserialization flaw in the Foxboro DCS Advisor, hard-coded credentials in Data Center Expert, and local RCE in Power Monitoring Expert.
CISA CI Fortify: What the New OT Isolation Guidance Means for Operational Technology Operators
CISA's CI Fortify initiative moves beyond standard patching guidance to address a harder problem: how critical infrastructure OT environments maintain operational continuity when internet, cloud, and telecom connectivity is severed during a geopolitical cyber crisis.
IEC 62443: The OT Security Standard Your Procurement Team Needs to Understand
IEC 62443 is the international standard series for industrial cybersecurity. This explainer covers the structure of the standard, what Security Levels mean in practice, the zones and conduits model, and how to reference 62443 in vendor contracts to actually improve your security posture.
Four-Faith Routers Under Active Attack, Iranian Threat Actors Hit US Fuel Systems
Mass exploitation of two vulnerabilities in Four-Faith industrial routers began May 12 with 139 attacking IPs observed against 15,800 exposed devices. Meanwhile, Iranian-linked threat actors continue automated attacks against Automatic Tank Gauge systems at US petrol stations.
OT Threat Landscape 2026: New Dragos Groups, Shrinking Exploit Windows, and the Visibility Crisis
Dragos's 2026 OT cybersecurity year-in-review identifies 26 threat groups specifically targeting operational technology -- including three newly tracked groups -- as exploit timelines compress to 24 days and fewer than one in ten OT networks have active monitoring. A practical analysis for OT security practitioners.
Default Credentials, Internet-Exposed PLCs, and the Unsophisticated Actor Problem
CISA's April 2026 joint advisory warns of Iranian-affiliated actors targeting internet-facing PLCs with basic techniques. The Poland energy attack demonstrated the real-world consequences. This analysis covers the threat, affected protocols, and what operators must do now.
CISA ICS Advisory Bundle: WAGO PFC, AVEVA Plant SCADA, and Beckhoff TwinCAT Vulnerabilities
CISA released seven ICS advisories on May 21, 2026, covering authentication and remote code execution vulnerabilities in WAGO PFC controllers, AVEVA Plant SCADA (formerly Citect), and Beckhoff TwinCAT runtime. Together these advisories affect PLC, SCADA, and automation runtime platforms deployed across manufacturing, energy, and building automation sectors globally.
Honeywell Experion PKS and C300 Controller Vulnerabilities: RCE Risk in Process DCS
Multiple vulnerabilities in Honeywell's Experion Process Knowledge System and C300 controller affect distributed control systems in oil and gas, petrochemical, and chemical processing facilities. Chained, the flaws provide an unauthenticated path from network access to code execution on the C300 controller's real-time OS, with potential to disrupt or manipulate industrial processes.
NIS2 OT Compliance: What the 2026 Enforcement Wave Means for Industrial Operators
EU member states are now issuing the first formal NIS2 enforcement actions against operators of essential services. Industrial operators — energy utilities, water authorities, manufacturing firms, and transport operators — face binding cybersecurity obligations, supply chain security requirements, and 24-hour incident reporting duties that the prior NIS1 regime did not meaningfully enforce. What actually changed and what OT teams need to do.
GE Vernova Grid Solutions SCADA Vulnerabilities: Path Traversal and Privilege Escalation in Energy Management
Multiple vulnerabilities in GE Vernova's Grid Solutions EMS/SCADA platform affect energy management systems used by electric utilities, grid operators, and transmission system operators globally. The highest-severity flaw allows unauthenticated path traversal enabling access to sensitive configuration files on the EMS server.
CISA Advisory: ABB AC500 PLC Remote Code Execution in Manufacturing and Process Control
CISA has issued an advisory covering a critical remote code execution vulnerability in ABB's AC500 PLC series, one of the most widely deployed programmable logic controller families in European manufacturing, paper and pulp, food processing, and water infrastructure. The flaw affects the Modbus TCP server component and requires no authentication to exploit.
CISA ICS Advisory: Siemens RUGGEDCOM and SCADABr Remote Code Execution
CISA has released a critical ICS advisory covering unauthenticated remote code execution vulnerabilities in Siemens RUGGEDCOM network devices and SCADABr SCADA software, both widely deployed in energy and manufacturing environments.
CISA Advisory: Hitachi Energy RTU500 Series Authentication Bypass in Grid SCADA
CISA has published an advisory covering multiple vulnerabilities in Hitachi Energy's RTU500 series, widely deployed as remote terminal units in power grid substations and transmission infrastructure. An authentication bypass flaw allows unauthenticated attackers on the device network to read and modify RTU configuration — a direct threat to substation automation and grid stability.
Claroty 2026 State of XIoT Security: OT Vulnerability Disclosures Hit New High
Claroty's annual State of XIoT Security report documents record-high vulnerability disclosures across operational technology, IoT, and connected medical devices. OT vulnerabilities now account for the majority of disclosed flaws, with critical infrastructure sectors facing compounded exposure from legacy device lifecycles and the accelerating advisory pace.
Volt Typhoon Pre-Positioning in US and UK OT Networks
China-nexus threat actor Volt Typhoon has systematically infiltrated operational technology networks across US and UK critical infrastructure sectors, establishing persistent footholds in energy, water, and communications systems for potential future disruption.
OT Network Segmentation: Purdue Model, DMZ Design, and Historian Isolation
A practical guide to network segmentation in OT environments, covering the Purdue Reference Model, industrial DMZ architecture, data historian isolation, and the tradeoffs between operational access and security posture.
TRITON/TRISIS: The Malware Designed to Kill
TRITON is the only publicly known malware explicitly engineered to disable Safety Instrumented Systems -- the last line of defense against industrial catastrophes. An analysis of its architecture, targeting of Schneider Electric Triconex controllers, and what it means for safety system cybersecurity.
Modbus and DNP3: Inherent Security Weaknesses in Legacy Industrial Protocols
Modbus and DNP3 were designed for reliability and interoperability, not security. An analysis of the structural security weaknesses in both protocols -- unauthenticated commands, lack of encryption, spoofing, and replay attacks -- and the compensating controls available to practitioners.
The OT Asset Inventory Problem: Visibility Gaps, Passive Discovery, and Unmanaged Devices
Most industrial operators cannot accurately enumerate the devices on their OT networks. This visibility gap is the foundational barrier to OT security -- you cannot protect what you cannot see. A practical look at passive discovery tools, the limits of vendor inventories, and strategies for building actionable asset visibility.