✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
Cyberattack on Polish Energy Plant via Private APN Highlights Infrastructure Vulnerabilities
In December 2025, a coordinated cyberattack targeted Poland's energy infrastructure, including a small combined heat and power (CHP) plant supplying heat to approximately 50,000 residents. The attackers exploited a misconfigured private Access Point Name (APN) to access the plant's operational technology (OT) network. By compromising a WAGO PFC200 programmable logic controller (PLC) with default credentials, they gained control over the plant's systems, leading to the shutdown of the steam turbine and water treatment system. The plant's staff managed to restore operations swiftly, preventing significant disruption to the population. This incident underscores the evolving tactics of nation-state actors in targeting critical infrastructure. The use of private APNs as attack vectors highlights the necessity for robust network segmentation, stringent access controls, and regular security assessments to mitigate such threats.
7 hours ago
Kill Chain
Cyberattacks Reveal Critical Vulnerabilities in U.S. Water Systems
In late July 2026, a series of cyberattacks targeted water and wastewater systems across at least 12 U.S. states, including Michigan, South Dakota, and Georgia. Attackers exploited internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), specifically the MicroLogix 1100 and 1400 models, to remotely alter configurations, leading to operational disruptions such as pressure loss and flooding. Despite prior federal warnings, over 4,000 such controllers remained accessible online, with 2,844 located in the United States. This incident underscores the persistent vulnerabilities in critical infrastructure due to inadequate cybersecurity measures. The exploitation of known vulnerabilities in widely used industrial equipment highlights the urgent need for enhanced security protocols and the removal of operational technology from direct internet exposure to prevent future attacks.
3 days ago
Kill Chain
Over 4,400 Rockwell PLCs Exposed Online: A Wake-Up Call for Critical Infrastructure Security
In August 2026, Forescout identified 4,407 internet-exposed Rockwell Automation programmable logic controllers (PLCs) worldwide, with 2,844 located in the United States. Notably, 22 of these exposed PLCs were found in cities recently targeted by cyberattacks on U.S. water utilities, with 19 utilizing the same mobile carrier network. Attackers exploited these vulnerabilities by altering IP addresses and setting passwords on accessible controllers, leading to operators losing visibility and control over connected equipment. This incident underscores the critical need for securing industrial control systems against unauthorized internet exposure. The prevalence of internet-exposed PLCs highlights a significant security gap in critical infrastructure, particularly within the water sector. The ease with which attackers can manipulate these systems without exploiting specific vulnerabilities emphasizes the urgency for organizations to implement robust network segmentation, remove unnecessary internet exposure, and enforce strong authentication measures to protect against potential disruptions and threats to public safety.
4 days ago
Kill Chain
CISA Issues Urgent Alert on Cyberattacks Targeting U.S. Water Utilities
In late July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert regarding a significant increase in cyberattacks targeting internet-exposed programmable logic controllers (PLCs) within the water and wastewater systems sector. These attacks, which began on July 26, 2026, involved hackers altering PLC configurations, changing passwords to lock operators out, and modifying IP addresses to disconnect devices from the internet, leading to operational disruptions. Over 30 community water systems in Minnesota were affected, with some utilities forced to switch to manual operations due to equipment malfunctions. This incident underscores the escalating cyber threats facing critical infrastructure, particularly in the water sector. The attackers' focus on internet-exposed PLCs highlights the urgent need for enhanced cybersecurity measures to protect operational technology from unauthorized access and potential sabotage.
1 week ago
Kill Chain
Critical Vulnerabilities Discovered in Open62541
In July 2026, multiple vulnerabilities were identified in o6 Automation GmbH's Open62541, an open-source OPC UA stack widely used in industrial automation. These vulnerabilities, including CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, and CVE-2026-63559, affect versions from 1.3.0 to 1.5.4 and the master branch. Exploitation could allow attackers to disclose sensitive information, cause denial-of-service conditions, or execute arbitrary code. ([aviatrix.ai](https://aviatrix.ai/threat-research-center/o6-automation-gmbh-open62541-vulnerability-2026/?utm_source=openai)) The discovery of these vulnerabilities underscores the critical importance of rigorous security practices in industrial automation software. Organizations utilizing Open62541 should promptly upgrade to the latest version to mitigate these risks. Additionally, implementing network segmentation and minimizing exposure of control systems to external networks are essential steps to enhance security posture.
1 week ago
Kill Chain
Critical Vulnerability in Rockwell Automation's ControlLogix and CompactLogix Controllers
In July 2026, Rockwell Automation disclosed a security vulnerability (CVE-2026-9636) affecting its CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR communication modules. The flaw involves improper handling of Certificate Revocation Lists (CRLs), allowing attackers to use revoked certificates to establish unauthorized connections, potentially bypassing CIP Security protections. This vulnerability impacts firmware versions V36 to V37 for the affected products. ([rockwellautomation.com](https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1788.html?utm_source=openai)) The incident underscores the critical importance of robust certificate validation processes in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize timely firmware updates and adhere to security best practices to mitigate potential risks.
1 week ago
Kill Chain
CISA Issues Alert on Iranian Cyber Actors Targeting U.S. Critical Infrastructure PLCs
In July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert regarding Iranian-affiliated cyber actors targeting internet-connected programmable logic controllers (PLCs) within U.S. critical infrastructure sectors, including water and wastewater systems. These actors exploited vulnerabilities in PLCs from manufacturers such as Rockwell Automation, Schneider Electric, and Siemens, leading to operational disruptions and financial losses. The attackers manipulated data on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) displays, causing outages and misleading operators about system statuses. This incident underscores the escalating threat landscape where state-sponsored actors are increasingly focusing on industrial control systems. The expansion of targeted PLC brands highlights the need for organizations to reassess and fortify their operational technology (OT) security measures to prevent potential disruptions to essential services.
1 week ago
Kill Chain
Schneider Electric IGSS Vulnerability CVE-2026-12927: Critical Update Required
In July 2026, Schneider Electric disclosed a high-severity out-of-bounds write vulnerability (CVE-2026-12927) in its IGSS Definition module, versions 18.0.0.26124 and prior. Exploitation of this flaw could allow attackers to execute arbitrary code by importing a malicious CGF file, potentially leading to data loss and loss of control over the SCADA system. The vulnerability was reported by Michael Heinzl and has been addressed in version 18.0.0.26125 of the IGSS Definition module. ([se.com](https://www.se.com/ww/en/work/support/cybersecurity/security-notifications/?utm_source=openai)) This incident underscores the critical importance of timely software updates in industrial control systems. As cyber threats targeting SCADA systems become more sophisticated, organizations must prioritize patch management and adhere to cybersecurity best practices to safeguard operational technology environments.
1 week ago
Kill Chain
Analog Devices 2026 Data Breach: ExfilSquad's Latest Target
In June 2026, Analog Devices, a leading semiconductor company, detected unauthorized access to certain company systems, resulting in the exfiltration of unspecified files. The company promptly activated its incident response protocols and engaged external cybersecurity experts to contain the breach. As of now, there is no evidence that the stolen data has been leaked online or used for fraudulent purposes. Business operations remain unaffected, and the company does not anticipate any material impact on its financial condition. This incident underscores the growing threat posed by data extortion groups like ExfilSquad, which claimed responsibility for the breach. Organizations must remain vigilant and enhance their cybersecurity measures to protect sensitive information from such emerging threats.
1 week ago
Kill Chain
Silver Fox Exploits Vulnerable Drivers to Deploy ValleyRAT in Japanese Manufacturing Sector
In July 2026, the Chinese cybercrime group Silver Fox executed a sophisticated Bring Your Own Vulnerable Driver (BYOVD) attack against a Japanese industrial manufacturing organization. By exploiting vulnerabilities in legitimate drivers, Silver Fox disabled endpoint protections and deployed ValleyRAT, a remote access trojan, to gain persistent control over the compromised systems. This attack underscores the group's evolving tactics and their ability to bypass traditional security measures. The incident highlights a concerning trend of advanced persistent threats leveraging BYOVD techniques to infiltrate critical infrastructure. Organizations must enhance their security protocols to detect and mitigate such sophisticated attacks, emphasizing the need for continuous monitoring and rapid response capabilities.
1 week ago
Kill Chain
Critical Vulnerability in Siemens SIMATIC S7-PLCSIM Advanced: CVE-2026-54429
In July 2026, Siemens disclosed a vulnerability (CVE-2026-54429) in its SIMATIC S7-PLCSIM Advanced software, affecting all versions. The flaw arises from improper handling of high-volume multicast network traffic, leading to memory exhaustion and a denial-of-service condition. An unauthenticated attacker on the local network can exploit this by sending excessive multicast traffic, rendering the application inaccessible until manually restarted. Notably, no project data is lost during this process. Exploitation requires a specific project configuration to be active on the targeted instance. This incident underscores the critical importance of securing industrial control systems against network-based attacks. As industrial environments become increasingly interconnected, vulnerabilities like this highlight the need for robust network segmentation, traffic monitoring, and timely application of security patches to prevent potential disruptions.
1 week ago
Kill Chain
Clop Ransomware Exploits Critical Vulnerability in PTC Windchill and FlexPLM
In July 2026, the Clop ransomware group exploited a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM systems, leading to unauthorized remote code execution. This flaw allowed attackers to deploy JSP webshells, facilitating the exfiltration of sensitive product data from compromised organizations. The exploitation of this vulnerability underscores the persistent threat posed by ransomware groups targeting critical infrastructure and intellectual property. Organizations utilizing PTC's Windchill and FlexPLM platforms are urged to apply the latest security patches and implement robust monitoring to detect and prevent such intrusions.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports