✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Critical Manufacturing
Breach intelligence, attack campaigns, and threat reports targeting the Critical Manufacturing sector.
Explore Other Sectors
Critical Manufacturing Threat Reports
Rockwell Automation 2025 ICS Vulnerabilities: Studio 5000 Path Traversal & SSRF Risks
In November 2025, Rockwell Automation disclosed critical vulnerabilities affecting its Studio 5000 Simulation Interface used across chemical and manufacturing sectors. The issues—Improper Limitation of a Pathname to a Restricted Directory (CVE-2025-11696) and Server-Side Request Forgery (CVE-2025-11697)—allowed local attackers to execute arbitrary scripts with administrator privileges and capture NTLM hashes via outbound SMB requests. The vulnerabilities impacted versions 2.02 and earlier, and, if exploited, could grant attackers lateral movement or privileged control within industrial environments, threatening operational integrity and sensitive data. These vulnerabilities highlight ongoing threats to industrial control systems (ICS) and the continued focus of adversaries on exploiting misconfigurations and overlooked APIs. With increasing regulatory pressure for critical infrastructure resilience and the evolution of ICS-specific ransomware and supply chain attacks, such vulnerabilities remain a potent risk requiring constant attention and timely remediation.
6 months ago
Kill Chain
Brightpick ICS Flaws Expose Critical Automation Functions and Credentials Globally
In November 2025, vulnerabilities were discovered in Brightpick AI's Mission Control and Internal Logic Control, software used for warehouse automation globally. Security researcher Souvik Kandar disclosed that all product versions lacked authentication for critical functions and exposed sensitive credentials via unencrypted channels, including WebSocket traffic accessible without prior authentication. If exploited, attackers could manipulate robot controls or intercept sensitive information, posing operational and confidentiality risks to organizations in sectors such as manufacturing, healthcare, and logistics. Brightpick AI had not issued a response or patch at the time of the initial disclosure. This incident stands out due to its impact on operational technology and industrial control systems, highlighting the widespread risk of exposed critical functions and hardcoded credentials in automation platforms. With growing connectivity in ICS environments, such vulnerabilities reflect an urgent need for organizations to bolster segmentation, credential management, and network security controls.
6 months ago
Kill Chain
Critical Flaws in General Industrial Controls Lynx+ Gateway Threaten Manufacturing Security (2025)
In November 2025, critical vulnerabilities were discovered in General Industrial Controls' Lynx+ Gateway devices deployed worldwide across the critical manufacturing sector. The exposed flaws—included weak password requirements, missing authentication for critical functions, and cleartext transmission of sensitive information—allowed attackers to remotely access devices, obtain sensitive information, and, in some cases, potentially cause denial-of-service conditions. Multiple CVEs (CVE-2025-55034, CVE-2025-58083, CVE-2025-59780, CVE-2025-62765) were assigned, with the highest CVSS v4 base score reaching 9.2. Despite coordinated disclosure efforts, the vendor did not respond, leaving organizations reliant on their own layered defense measures. This incident is highly relevant as it highlights persistent challenges in secure authentication and encrypted traffic within operational technology environments. The surge in attacks exploiting similar unauthenticated remote access and cleartext weaknesses continues to drive regulatory pressure for zero trust and encryption controls within industrial networks.
6 months ago
Kill Chain
Siemens Altair Grid Engine 2025: Local Privilege Escalation and OT Vulnerability Risks
In November 2025, Siemens disclosed two local privilege escalation vulnerabilities affecting all versions of Altair Grid Engine prior to V2026.0.0. These flaws, identified as CVE-2025-40760 (Generation of Error Message Containing Sensitive Information) and CVE-2025-40763 (Uncontrolled Search Path Element), could allow attackers with local access to extract password hashes or execute arbitrary code with superuser permissions by manipulating environment variables or error handling processes. Although there has been no evidence of exploitation in the wild, the vulnerabilities required only low attack complexity and affected critical manufacturing environments globally. This incident highlights ongoing risks posed by improper input validation and error handling in operational technology (OT) environments, especially as attackers increasingly target privilege escalation vectors. Regulatory bodies emphasize swift detection, patching, and IT/OT segmentation to reduce attack surface, as local escalation flaws remain a persistent threat vector in critical infrastructure.
6 months ago
Kill Chain
Siemens 2025: Critical DLL Hijacking Flaw Exposes Manufacturing Software
In November 2025, Siemens disclosed a vulnerability (CVE-2025-40827) in its Software Center and Solid Edge products, affecting versions prior to 3.5 and V225.0 Update 10, respectively. The flaw, rooted in uncontrolled search path element (CWE-427), allows local attackers to execute arbitrary code via DLL hijacking—placing crafted DLLs on vulnerable systems. Although exploitation requires local access and some user interaction, compromise could lead to full system takeover in manufacturing environments globally. Siemens responded by advising immediate updates and enhanced network protections. This incident underscores the ongoing risks posed by software supply chain vulnerabilities and underscores the importance of timely patching in industrial environments. It highlights how attackers continue targeting widely deployed engineering software with low-complexity, high-impact exploits, especially as operational technology environments see increased convergence with IT infrastructures.
6 months ago
Kill Chain
Siemens COMOS 2025: Critical Software Vulnerabilities in Industrial Control Systems
In November 2025, Siemens disclosed critical software vulnerabilities affecting its COMOS platform, widely used in the industrial and critical manufacturing sectors. The flaws—specifically, an incomplete list of disallowed inputs and cleartext transmission of sensitive information—enabled remote attackers with low attack complexity to execute arbitrary code or intercept data. The affected versions were COMOS releases prior to 10.4.5, with potential for unauthorized access, data infiltration, or broader operational disruptions across global deployments. Siemens ProductCERT identified and reported the vulnerabilities, issuing patches and urging immediate upgrades and network protections. This incident is highly relevant given the increasing threats to industrial control systems and the persistent exploitation of software supply chain vulnerabilities. The convergence of IT and OT environments means that unresolved vulnerabilities like these present heightened risks in critical infrastructure, drawing attention from regulators and advanced cyber attackers alike.
6 months ago
Kill Chain
Delta Electronics 2025 ICS Vulnerability: Buffer Overflow in CNCSoft-G2 Threatens Industrial Operations
In November 2025, Delta Electronics publicly disclosed a critical vulnerability in its CNCSoft-G2 software (version 2.1.0.27 and prior), used widely across critical manufacturing and energy sectors. The stack-based buffer overflow vulnerability (CVE-2025-58317) could be exploited by attackers using a malicious file to achieve arbitrary code execution with the privileges of the target process. Although no public exploitation has been reported yet and remote exploitation is not possible, the flaw poses significant risks to organizations controlling industrial networks, potentially undermining operational continuity and safety systems. Mitigations and patches have been released, with recommendations for further defense-in-depth and updated secure remote access. This case highlights the ongoing challenges in securing industrial control software as threat actors frequently target poorly validated file handling and legacy code. The need for robust patch management and segmentation is paramount—especially as ransomware groups and nation-state actors increasingly pursue industrial targets for disruption or extortion.
6 months ago
Kill Chain
Siemens 2025: Type Confusion RCE Threatens HyperLynx & Industrial Edge Security
In October 2025, Siemens disclosed a critical vulnerability (CVE-2025-6554) affecting HyperLynx and Industrial Edge App Publisher products. The flaw, rooted in type confusion within the V8 JavaScript engine (Google Chrome), enables remote attackers to execute arbitrary code via malicious HTML, particularly impacting vulnerable product versions used in worldwide critical manufacturing environments. For HyperLynx, exploitation requires local access, while Industrial Edge App Publisher is exploitable remotely with low complexity, posing a substantial risk to integrity and confidentiality. Siemens and CISA jointly advised immediate updates and best-practice mitigations. This incident highlights a growing trend of supply chain and third-party component vulnerabilities impacting industrial control systems, particularly as attackers increasingly target embedded web technologies. The Siemens disclosure underlines ongoing regulatory and operational pressure to address software dependencies and enforce proactive patch management in critical infrastructure.
6 months ago
Kill Chain
Critical Siemens RUGGEDCOM ROS Vulnerabilities Expose Industrial Control Systems in 2025
In October 2025, Siemens disclosed several critical vulnerabilities in its RUGGEDCOM ROS industrial control system devices used globally in critical manufacturing sectors. The flaws include the use of weak cryptographic algorithms, improper handling of exceptional conditions, and protection mechanism failures, making affected devices susceptible to man-in-the-middle attacks, denial-of-service, and potential unauthorized access until device reboot. Exploitation is possible remotely with low complexity, allowing attackers to compromise encrypted communications or persist on non-management interfaces. This incident is especially relevant as supply chains and critical infrastructure increasingly adopt ICS/OT devices that, if not properly secured, expose entire operations to disruption. The persistence of cryptographic weaknesses and the growing sophistication of adversaries underscore the urgent need for robust, up-to-date security controls across the ICS ecosystem.
6 months ago
Kill Chain
Schneider Electric OPC UA DoS Flaw Threatens Global OT Operations
In October 2025, Schneider Electric disclosed a critical vulnerability (CVE-2024-10085) affecting its EcoStruxure OPC UA Server Expert and Modicon Communication Server. The flaw, identified as improper allocation of resources without limits or throttling, allows a remote attacker to overwhelm the targeted server with excessive OPC UA requests, resulting in a denial-of-service (DoS) and loss of real-time process data. The vulnerability, scored at CVSS v4 8.2, threatens industrial operations worldwide, particularly in critical sectors like energy and manufacturing, if not promptly mitigated. This incident underscores the increasing risk to industrial control systems (ICS) from remote, low-complexity attacks exploiting resource exhaustion bugs. It highlights ongoing attacker interest in operational technology environments and the urgent need for robust ICS security best practices and timely patch management.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports