Skip to main content
System Status
Critical 18
|
High 70
|
Medium 1
|
Feed Online
UPDATED: 2026-06-11 00:00 UTC

ICSA-26-202-07: Rockwell FactoryTalk JWT Algorithm Confusion Allows Forged Authentication Tokens

CISA advisory ICSA-26-202-07 documents a JWT signature bypass in Rockwell Automation's FactoryTalk Services Platform 6.60. The vulnerability lets an attacker set the JWT algorithm to 'none' during Okta Web Authentication, forge tokens without a valid signature, and impersonate authorised users to access industrial system configurations. Patch is available.

PROFINET Security: Attack Surface Analysis and Hardening for Industrial Ethernet Networks

PROFINET is the dominant real-time industrial Ethernet protocol in European manufacturing and process automation, with over 70 million installed nodes worldwide. This guide covers PROFINET's attack surface, documented exploits, network segmentation requirements, and hardening controls for OT security practitioners.

Rockwell Automation ControlLogix and CompactLogix: Vulnerability Landscape and Hardening Guidance

Rockwell Automation's Logix family of programmable automation controllers has accumulated significant vulnerability history. This analysis covers key CVEs affecting ControlLogix and CompactLogix platforms, exploitation implications for industrial operations, and vendor-specific hardening steps.