✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Critical Manufacturing
Breach intelligence, attack campaigns, and threat reports targeting the Critical Manufacturing sector.
Explore Other Sectors
Critical Manufacturing Threat Reports
GE Vernova Enervista UR Setup Vulnerabilities Disclosed in 2026
In February 2026, GE Vernova disclosed two vulnerabilities in their Enervista UR Setup software versions prior to 8.70. CVE-2026-1762 involves a directory traversal flaw that allows unauthorized file manipulation, while CVE-2026-1763 pertains to a DLL hijacking issue enabling code execution with elevated privileges. Both vulnerabilities require local access for exploitation and have been addressed in version 8.70. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1762?utm_source=openai)) The disclosure underscores the importance of timely software updates and robust local security measures, especially in critical infrastructure sectors where such vulnerabilities can have significant operational impacts.
5 months ago
Kill Chain
Critical RADIUS Vulnerability in Hitachi Energy XMC20 Devices (CVE-2024-3596)
In July 2024, a critical vulnerability (CVE-2024-3596) was identified in the RADIUS protocol, affecting Hitachi Energy's XMC20 devices. This flaw allows an on-path attacker to forge RADIUS server responses by exploiting weaknesses in the MD5-based Response Authenticator, potentially granting unauthorized network access. The vulnerability impacts XMC20 versions R18, R17A, and earlier, particularly when configured for remote RADIUS authentication. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html?utm_source=openai)) The discovery underscores the risks associated with legacy cryptographic protocols like MD5. Organizations relying on RADIUS for authentication should promptly implement mitigations, such as enabling the Message-Authenticator attribute, to safeguard against potential exploits. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerability in Hitachi Energy's FOX61x Products (CVE-2024-3596)
In January 2026, Hitachi Energy disclosed a critical vulnerability (CVE-2024-3596) in its FOX61x products, specifically affecting versions R18 and R17A and earlier. This flaw, inherent in the RADIUS protocol under RFC 2865, allows local attackers to modify valid responses through a chosen-prefix collision attack on the MD5 Response Authenticator signature. Exploitation could compromise the confidentiality, integrity, and availability of the affected systems. The vulnerability is particularly relevant when FOX61x devices are configured to use remote RADIUS authentication. ([it4automation.com](https://it4automation.com/security-alerts/hitachi-energy-fox61x-foxcst-and-foxman-un-products/?utm_source=openai)) This incident underscores the persistent risks associated with legacy authentication protocols and the importance of implementing robust security measures. Organizations utilizing FOX61x devices are urged to apply the recommended mitigations promptly to prevent potential exploitation.
5 months ago
Kill Chain
Critical Vulnerability in Mitsubishi Electric's FREQSHIP-mini: CVE-2025-10314
In February 2026, Mitsubishi Electric disclosed a critical vulnerability (CVE-2025-10314) in its FREQSHIP-mini for Windows software, versions 8.0.0 to 8.0.2. The flaw arises from incorrect default permissions during installation, allowing local attackers to replace service executables or DLLs with malicious files. Exploiting this vulnerability enables arbitrary code execution with SYSTEM privileges, potentially leading to unauthorized access, data manipulation, or denial-of-service conditions. This vulnerability is particularly concerning for critical infrastructure sectors, including manufacturing and energy, where FREQSHIP-mini is commonly deployed. Organizations are urged to update to version 8.1.0 or later and implement recommended mitigation measures to prevent exploitation. ([jvn.jp](https://jvn.jp/en/jp/JVN64883963/?utm_source=openai))
5 months ago
Kill Chain
Critical Unauthenticated Access Vulnerability in Synectix LAN 232 TRIO
In February 2026, a critical vulnerability (CVE-2026-1633) was identified in the Synectix LAN 232 TRIO 3-Port serial to Ethernet adapter. This flaw allows unauthenticated users to access the device's web management interface, enabling them to modify critical settings or perform a factory reset. The vulnerability has a CVSS score of 10.0, indicating maximum severity. Synectix is no longer in business, leaving the affected devices without official support or patches. ([securityonline.info](https://securityonline.info/unpatchable-critical-cisa-issues-cvss-10-0-alert-for-synectix-adapters/?utm_source=openai)) This incident underscores the risks associated with using unsupported legacy devices in critical infrastructure. Organizations must proactively identify and replace such equipment to mitigate potential security threats. ([securityonline.info](https://securityonline.info/unpatchable-critical-cisa-issues-cvss-10-0-alert-for-synectix-adapters/?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerability in iba Systems ibaPDA Exposes Industrial Systems to Unauthorized Access
In January 2026, a critical vulnerability (CVE-2025-14988) was identified in iba Systems' ibaPDA software, version 8.12.0. This flaw allowed unauthorized actions on the file system, potentially compromising the confidentiality, integrity, and availability of affected systems. The vulnerability was reported by Siemens and disclosed by CISA on January 27, 2026. ([iba-ag.com](https://www.iba-ag.com/en/security/iba-2025-04?utm_source=openai)) Given ibaPDA's widespread use in critical manufacturing sectors worldwide, this vulnerability posed significant risks to industrial operations. Organizations were urged to update to version 8.12.1 or later to mitigate potential exploitation. ([iba-ag.com](https://www.iba-ag.com/en/security/iba-2025-04?utm_source=openai))
5 months ago
Kill Chain
Johnson Controls iSTAR ICU Tool Faces Critical Stack Buffer Overflow Vulnerability
In January 2026, Johnson Controls Inc. disclosed a significant vulnerability (CVE-2025-26386) affecting its iSTAR Configuration Utility (ICU) tool, versions up to 6.9.7. The issue, a stack-based buffer overflow, could be exploited by a remote attacker, potentially causing a failure in the operating system hosting the ICU tool. Although there have been no reported cases of active exploitation as of the disclosure, the vulnerability poses a risk to critical infrastructure sectors—including commercial facilities, energy, and government services—where the affected product is widely deployed. Security researchers at Tenable responsibly reported the flaw to CISA, who published the advisory. This incident rolls out against the backdrop of increasing attention to the cybersecurity of operational technology (OT) in industrial and critical infrastructure, with regulators and operators emphasizing timely patching and network segmentation practices to prevent lateral movement and operational disruption.
6 months ago
Kill Chain
Siemens RUGGEDCOM ROS 2025: TLS Input Validation Vulnerability Disrupts Industrial Devices
In December 2025, Siemens disclosed a vulnerability (CVE-2025-40935) affecting multiple RUGGEDCOM ROS devices widely used in industrial control environments. The flaw resides in improper input validation during the TLS certificate upload process, which could allow an authenticated remote attacker to crash and automatically reboot the affected device, causing a temporary denial of service. Siemens promptly released security updates (V5.10.1 or later), and CISA amplified the advisory to increase awareness across critical infrastructure sectors globally. The vulnerability mainly impacts operational continuity, as no data compromise or persistent system access was observed. This incident underscores growing concerns about device-level vulnerabilities in operational technology environments, particularly as attackers increasingly target the industrial sector. The urgency around patching and secure configuration reflects an industry-wide shift toward defense-in-depth strategies and proactive risk mitigation for critical infrastructure.
6 months ago
Kill Chain
Axis Communications 2025: Critical Camera System Vulnerabilities Threaten OT Security
In December 2025, Axis Communications disclosed multiple critical vulnerabilities affecting their Camera Station Pro, Camera Station, and Device Manager products. The issues, discovered by cybersecurity researchers from Claroty Team82, include flaws such as deserialization of untrusted data, improper certificate validation, authentication bypass, and local privilege escalation. These vulnerabilities could allow an attacker to remotely execute arbitrary code, intercept communications via man-in-the-middle attacks, or bypass authentication mechanisms, significantly compromising the security posture of organizations using these systems globally. Patches are now available and users are urged to upgrade immediately. This incident highlights a growing trend in targeting surveillance and control infrastructure, reflecting the increased attention threat actors are placing on operational technology and critical manufacturing environments. The convergence of IT and OT risks, as well as heightened regulatory expectations, make robust security controls for IoT and camera systems more critical than ever.
6 months ago
Kill Chain
Critical LabVIEW 2025 Vulnerabilities Expose Industrial Control Systems to Code Execution Risk
In December 2025, multiple critical vulnerabilities (CVE-2025-64461 through CVE-2025-64469) were disclosed in National Instruments LabVIEW, a widely used industrial control software. The flaws, which include out-of-bounds write, out-of-bounds read, use-after-free, and stack-based buffer overflow, enable attackers to execute arbitrary code or exfiltrate information when a user opens a specially crafted VI file. Impacted versions span from LabVIEW 2021 up to 2025 Q3, affecting sectors such as critical manufacturing, defense, IT, and transportation globally. National Instruments released patches addressing these flaws, with older versions receiving limited or no support. Though there have been no reports of active exploitation, this incident highlights the persistent risk of supply chain and software vulnerabilities in critical ICS environments. Recent trends show a rise in sophisticated attacks leveraging user interaction and file-based exploits, emphasizing the growing need for robust patch management and secure software usage.
6 months ago
Kill Chain
Critical Siemens 2025 IAM Client TLS Flaw Exposes Industrial Environments
In December 2025, Siemens disclosed a critical vulnerability (CVE-2025-40800) in the IAM Client component used across key products such as COMOS, NX, Simcenter, and Solid Edge. The flaw stemmed from improper validation of server certificates during TLS sessions, exposing organizations to potential Man-in-the-Middle (MitM) attacks by unauthenticated remote attackers. Impacting deployments globally within the critical manufacturing sector, the vulnerability received a CVSS v4 base score of 9.1, reflecting its high risk. While patches are available for most products, a fix for COMOS V10.6 was unavailable at disclosure. This incident highlights ongoing risks from certificate handling errors, which remain common initial access vectors. As industrial networks become more interconnected, failures in basic cryptographic hygiene, especially in authentication mechanisms, are increasingly targeted by sophisticated attackers leveraging supply chain or network-layer attacks.
6 months ago
Kill Chain
Critical Vulnerabilities in Siemens SINEMA Remote Connect Server Expose Manufacturing Networks
In December 2025, Siemens disclosed two vulnerabilities impacting SINEMA Remote Connect Server versions prior to V3.2 SP4, designated as CVE-2025-40818 and CVE-2025-40819. The flaws involved incorrect permission assignments for SSL/TLS private keys and improper authorization controls over license management within the server's database. An authenticated attacker could exploit these weaknesses to impersonate trusted servers, decrypt or intercept sensitive communications, and bypass licensing restrictions, exposing critical manufacturing environments worldwide to unauthorized access and operational risk. This incident underscores the persistent importance of robust permission management and encryption key protection in industrial control systems. With increased targeting of operational technology environments, organizations must prioritize patching, secure configurations, and risk assessments to maintain both compliance and resilience against escalating threats.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports