✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Critical Manufacturing
Breach intelligence, attack campaigns, and threat reports targeting the Critical Manufacturing sector.
Explore Other Sectors
Critical Manufacturing Threat Reports
Critical Vulnerabilities in Johnson Controls iSTAR Devices Expose Critical Infrastructure—What You Need to Know
In December 2025, Johnson Controls disclosed two critical vulnerabilities (CVE-2025-43875, CVE-2025-43876) affecting its iSTAR Ultra and Edge G2 access control devices worldwide. These vulnerabilities—improper neutralization of special elements used in OS commands (CWE-78)—can be exploited remotely with low complexity and limited privileges, potentially granting attackers unauthorized access to devices deployed across critical sectors, including commercial facilities, manufacturing, energy, transportation, and government. There are currently no reports of active exploitation, but if leveraged, these flaws could compromise physical security and facility operations. This incident underscores the persistent cybersecurity challenges in operational technology and building automation environments. The disclosure highlights an urgent need for regular patching, segregation of critical controls, and adoption of defensive measures, especially as threat actors increasingly target industrial and physical security systems with potentially far-reaching consequences.
6 months ago
Kill Chain
Siemens Building X Firmware Supply Chain Flaw: Risks and Mitigation
In December 2025, Siemens disclosed a critical vulnerability in its Building X - Security Manager Edge Controller (ACC-AP), affecting all firmware versions. The flaw, tracked as CVE-2022-31807, is an improper verification of cryptographic signature that enables a local—or, in some cases, remote—attacker to upload maliciously altered firmware to the device. This could be exploited by an individual with physical access or by intercepting firmware updates, introducing risks to device integrity and broadening the attack surface in critical manufacturing environments. Siemens has issued operational mitigations but no permanent patch is planned. This incident highlights increasing attention on firmware supply chain vulnerabilities across operational technology (OT) in critical infrastructure. Insecure update mechanisms are a prime target for actors seeking persistent access or sabotage, echoing a trend that is prompting regulators and organizations to strengthen controls—especially amid rising regulatory scrutiny and high-profile supply chain breaches.
6 months ago
Kill Chain
Johnson Controls iSTAR Ultra Vulnerabilities: 2025 Exposure of OT Systems
In December 2025, Johnson Controls publicly disclosed critical vulnerabilities (CVE-2025-43873 and CVE-2025-43874) affecting several versions of its iSTAR Ultra and Edge G2 door controllers used in building automation across critical infrastructure sectors worldwide. These OS Command Injection flaws, exploitable remotely with low attack complexity and minimal user interaction, could allow attackers to gain full control of vulnerable devices, modify firmware, and potentially disrupt or compromise secure building environments. The vulnerabilities were responsibly reported by Reid Wightman of Dragos, and patches have been made available for affected products. This incident highlights increasing threats targeting operational technology (OT) in critical sectors, as cybercriminals and nation-state actors leverage software supply chain and device-level weaknesses for initial access. The prevalence of command injection vulnerabilities, coupled with rising demands for segmentation and zero trust architectures, elevates the urgency for organizations to update OT and IoT assets and enforce proactive defense strategies.
6 months ago
Kill Chain
Siemens SALT Toolkit Flaw Leaves Industrial Systems Exposed to MITM Attacks
In December 2025, Siemens disclosed a critical vulnerability (CVE-2025-40801) in its Advanced Licensing (SALT) Toolkit, affecting multiple industrial software products such as COMOS, NX, Simcenter, and Tecnomatix. The flaw—improper certificate validation in the SALT SDK when establishing TLS connections—could enable unauthenticated remote attackers to launch man-in-the-middle attacks. With a CVSS v4 score of 9.2, exploitation risk is high, potentially allowing attackers to intercept or manipulate sensitive industrial data and processes in critical manufacturing environments globally. Patches have been released for some products, but others remain without a fix. This incident is significant as it highlights ongoing challenges in implementing secure communication protocols within the industrial sector. The vulnerability underscores a wider trend of attackers exploiting flaws in authentication and encryption controls, emphasizing the urgent need for robust zero trust segmentation, encrypted traffic policies, and active vulnerability management as industries modernize.
6 months ago
Kill Chain
Festo LX Appliance Security Alert: 2025 Cross-Site Scripting Vulnerability Exposes ICS Risks
In December 2025, Festo SE & Co. KG disclosed a cross-site scripting (XSS) vulnerability (CVE-2021-23414) affecting the Festo LX Appliance, impacting versions released before June 2023. Malicious actors could exploit improper input neutralization in the 'track' tag's 'src' attribute to execute arbitrary code by crafting a malicious course, potentially compromising highly privileged user accounts. Though no public exploitation has been reported, the vulnerability posed risks to organizations in critical sectors globally, with a CVSS v3.1 base score of 6.1 indicating a moderate threat profile. This incident underscores the persistent risks posed by web application vulnerabilities in ICS and OT environments. With the increased digitization of operational systems and ongoing cyberattacks targeting critical infrastructure, rapid identification, patching, and monitoring of such flaws remain crucial to protect sensitive assets and maintain compliance with evolving regulatory standards.
6 months ago
Kill Chain
Johnson Controls iSTAR Certificate Expiry Flaw: 2025 ICS Vulnerability Explained
In December 2025, Johnson Controls disclosed a critical vulnerability (CVE-2025-61736) affecting its iSTAR series access control panels. The flaw, classified as improper validation of certificate expiration, could cause affected devices to lose communication with their C•CURE Server once the default certificate expires. This disruption, impacting multiple critical infrastructure sectors worldwide, stems from older panel versions utilizing TLS versions prior to 1.2, thereby exposing systems to operational risk and service interruptions. While no public exploitation has been reported, timely mitigation is necessary to prevent outages. This incident highlights the ongoing importance of robust certificate management and timely upgrades in the face of tightening compliance demands and evolving threat landscapes. With operational technology environments increasingly targeted, companies must address outdated encryption protocols to maintain business continuity and regulatory alignment.
6 months ago
Kill Chain
Advantech iView 2025 SQL Injection Flaw: Immediate Risks for OT Environments
In December 2025, Advantech disclosed a critical SQL injection vulnerability (CVE-2025-13373) affecting its iView network management product (version 5.7.05.7057 and earlier). Security researchers found that attackers could send specially-crafted SNMP v1 trap requests that were not properly sanitized, enabling remote exploitation without authentication. If exploited, the flaw could allow threat actors to access, modify, or delete sensitive information, posing significant operational and business risks to industrial control systems globally. Although no known public exploitation has been reported, the vulnerability exposes organizations across critical manufacturing and information technology sectors to serious threats. This incident underscores the persistent risk of unpatched input validation flaws in widely-deployed operational technology (OT) products. The increasing convergence of IT and OT systems—as well as the expanding attack surfaces in critical infrastructure—make immediate patching, network isolation, and robust segmentation essential in mitigating future high-impact vulnerabilities.
6 months ago
Kill Chain
Critical Buffer Overflow Flaws in Ashlar-Vellum Software Threaten Industrial Security
In November 2025, Ashlar-Vellum disclosed two critical software vulnerabilities—an Out-of-Bounds Write (CVE-2025-65084) and a Heap-based Buffer Overflow (CVE-2025-65085)—impacting its Cobalt, Xenon, Argon, Lithium, and Cobalt Share products (version 12.6.1204.207 and prior). Identified by security researcher Michael Heinzl and published via CISA, these flaws could allow local attackers to gain information disclosure or execute arbitrary code on affected engineering systems, primarily used in the Critical Manufacturing sector worldwide. The vulnerabilities are rated high (CVSS v4 score 8.4), but no exploitation has been reported to date. This incident reinforces the urgent need for robust vulnerability management and regular software patching within industrial control environments. Manufacturers and operators face increasing regulatory and operational pressure to proactively address new threats in their digital supply chains and critical OT infrastructure.
6 months ago
Kill Chain
PowerChute ICS Flaws: Schneider Electric 2025 Vulnerabilities Expose Critical Manufacturing
In November 2025, Schneider Electric disclosed multiple vulnerabilities affecting PowerChute Serial Shutdown version 1.3 and earlier, widely deployed in critical manufacturing. The flaws, reported by security researcher Aleksandar Djurdjevic, include a path traversal (CVE-2025-11565), improper authentication attempt controls (CVE-2025-11566), and insecure default permissions (CVE-2025-11567). Successful exploitation could allow attackers on the local network to gain user or system access, potentially compromising operational technology environments. Immediate mitigation involved updating to version 1.4, securing folder permissions, and implementing network isolation practices to reduce exposure. This incident highlights growing risks to industrial control systems amid increasing convergence of IT/OT and heightened attacker focus on supply chain and infrastructure software weaknesses. Regulatory and business pressures mount as organizations strive to bolster segmentation, logging, and zero trust practices to avoid costly operational disruptions and compliance failures.
6 months ago
Kill Chain
Critical 2025 METZ CONNECT EWIO2 Vulnerabilities: Auth Bypass and RCE Expose Industrial Control Risks
In November 2025, multiple critical vulnerabilities were disclosed in METZ CONNECT EWIO2 industrial control devices, enabling remote attackers to bypass authentication and gain full control, execute arbitrary code, and read sensitive device information. The flaws include authentication bypass (CVE-2025-41733), PHP remote file inclusion (CVE-2025-41734), unrestricted file upload (CVE-2025-41735), path traversal (CVE-2025-41736), and improper access control (CVE-2025-41737), with CVSS v4 scores ranging from 8.7 to 9.3. Affected devices are used globally in critical manufacturing environments, and exploitation could trigger operational disruption or unauthorized control. This incident is highly relevant as it targets the operational technology (OT) sector—a high-value, often less-protected attack surface increasingly sought after by threat actors. As convergence between IT and OT grows, unpatched, internet-exposed devices in critical infrastructure remain susceptible to devastating attacks, underscoring urgent need for robust patching, segmentation, and proactive defense.
6 months ago
Kill Chain
Schneider Electric 2025 SCADA Cryptography Flaw: What It Means for Industrial Cybersecurity
In November 2025, Schneider Electric disclosed a critical vulnerability (CVE-2025-9317) in its EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio platforms, widely used across energy, manufacturing, and commercial sectors. The flaw involved the use of a broken or risky cryptographic algorithm within an AVEVA-supplied component, allowing local attackers with read access to project or cache files to reverse-engineer user passwords by brute-forcing weak password hashes. This could result in loss of confidentiality and integrity within impacted environments. No remote exploitation was identified, and there are no public reports of in-the-wild attacks as of the advisory date. This incident underscores persistent risks in ICS/OT software supply chains, where cryptographic weaknesses can enable privilege escalation and lateral movement by adversaries. With global regulators increasingly pressuring critical infrastructure providers on cyber hygiene and segmentation, this advisory highlights the urgency for supply chain and password management reforms.
6 months ago
Kill Chain
Shelly Pro 4PM 2025 Vulnerability: Unchecked Resource Allocation Triggers Industrial DoS
In November 2025, a significant vulnerability (CVE-2025-11243) was disclosed in Shelly Pro 4PM, a smart DIN rail switch commonly used in critical manufacturing environments worldwide. The flaw, arising from improper resource allocation and lack of input bounds checking, allowed an attacker on the local network to trigger a denial-of-service condition by sending specially crafted RPC requests. This caused the device to overallocate memory and reboot, risking loss of control or downtime in industrial settings. No exploitation has been reported publicly, but affected firmware versions prior to 1.6 remain at risk until patched. This incident underscores the persistent risk of denial-of-service vulnerabilities in IoT and industrial devices, especially as connected manufacturing assets proliferate. The failure in secure resource management highlights the growing regulatory and operational focus on robust device security amid expanding threat surfaces.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports