The Containment Era is here. →Explore

Industry Category

Industrial Automation

Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.

213 threat reports
Page 12 of 18

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Industrial Automation Threat Reports

Showing 133144 / 213 reports
Schneider Electric 2025: Critical WSUS Flaw Threatens Global Industrial Networks
Impact· low

Schneider Electric 2025: Critical WSUS Flaw Threatens Global Industrial Networks

In December 2025, Schneider Electric disclosed a critical vulnerability—CVE-2025-59287—in its EcoStruxure Foxboro DCS Advisor, an industrial automation component used worldwide across critical manufacturing and energy sectors. The vulnerability, rooted in untrusted data deserialization within Microsoft WSUS, could allow unauthenticated remote code execution with system-level privileges if exploited, threatening core operational networks. The exposure prompted Schneider Electric and CISA to issue urgent advisories urging immediate patching via provided Microsoft updates and to isolate control networks from business operations to prevent exploitation. Despite official advisories, any systems running unpatched software remain at high risk. The incident highlights the persistent challenges in securing dependencies within operational technology (OT) environments. With critical infrastructure increasingly targeted by sophisticated threat actors leveraging software supply chain and remote execution flaws, this case underscores the importance for organizations to proactively patch, segment networks, and reinforce incident response capabilities tailored for industrial control systems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Inductive Automation Ignition Vulnerability Exposes Critical Infrastructure to Privilege Escalation in 2025
Impact· medium

Inductive Automation Ignition Vulnerability Exposes Critical Infrastructure to Privilege Escalation in 2025

In December 2025, Inductive Automation disclosed a privilege escalation vulnerability (CVE-2025-13911) in its Ignition SCADA platform widely used across critical manufacturing, energy, and IT sectors. The flaw arises from inadequate controls in the Python scripting environment, enabling authenticated administrators to execute arbitrary code with SYSTEM-level privileges on affected Windows hosts. Attackers can upload malicious project files to the Ignition Gateway, potentially leading to complete host compromise if exploited. Although there are currently no reports of public exploitation, this issue underscores growing risks associated with misconfigured automation platforms and the importance of adhering to least-privilege principles. Recent trends in supply chain and ICS-targeted attacks have increased regulatory pressure on critical infrastructure operators to address privilege escalation vectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Advantech WebAccess/SCADA 2025: Critical Vulnerabilities Threaten Industrial Control Systems
Impact· medium

Advantech WebAccess/SCADA 2025: Critical Vulnerabilities Threaten Industrial Control Systems

In December 2025, critical vulnerabilities were disclosed in Advantech WebAccess/SCADA software (version 9.2.1), widely used across critical manufacturing, energy, and water infrastructure worldwide. Discovered by Pellera Technologies, the weaknesses included multiple instances of path traversal (CVE-2025-14850, CVE-2025-67653, CVE-2025-14848), unrestricted file upload (CVE-2025-14849), and SQL injection (CVE-2025-46268). Exploitation could enable a remote, authenticated attacker to read or modify sensitive database content, delete files, or execute arbitrary code on impacted systems, significantly increasing cyber-physical risk for operations. Advantech advised immediate upgrades to v9.2.2 to remediate these flaws. This incident underscores ongoing challenges in the security of industrial control systems amid rising cyber threats targeting critical infrastructure. With no current evidence of public exploitation, practitioners must remain vigilant due to the highly impactful nature of the vulnerabilities and their corresponding attack surface across essential industries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical RADIUS MD5 Vulnerability Exposes Hitachi Energy Infrastructure — 2025 Analysis
Impact· medium

Critical RADIUS MD5 Vulnerability Exposes Hitachi Energy Infrastructure — 2025 Analysis

In December 2025, Hitachi Energy disclosed a critical vulnerability (CVE-2024-3596) impacting their AFS, AFR, and AFF series infrastructure hardware, widely deployed in the global energy sector. The issue centers on improper enforcement of message integrity in RADIUS communications, allowing attackers in a local network to exploit a chosen-prefix collision attack against the MD5 response authenticator. This could let a malicious actor forge RADIUS authentication responses — potentially leading to unauthorized network access, disruption of critical systems, or exfiltration of sensitive data. The flaw carries a CVSS score of 9.0 (critical), but exploitation requires high attack complexity. This case highlights the continued risks posed by legacy authentication protocols and cryptographic weaknesses within operational technology environments. As adversaries increasingly target energy and critical infrastructure supply chains, prioritizing secure authentication and traffic integrity mechanisms is vital to maintaining resilience and regulatory compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Mitsubishi Electric's GT Designer3 Vulnerability (2025): Cleartext Credentials Endanger Industrial Systems
Impact· medium

Mitsubishi Electric's GT Designer3 Vulnerability (2025): Cleartext Credentials Endanger Industrial Systems

In December 2025, Mitsubishi Electric disclosed a vulnerability (CVE-2025-11009) impacting their GT Designer3 software, widely used in industrial control panel applications. Security researchers at Red Alert Lab discovered that plaintext credentials were being stored in project files, exposing critical manufacturing assets worldwide to potential unauthorized access. Although successful exploitation requires local access and has a high attack complexity, an attacker could obtain plaintext credentials to operate GOT2000 or GOT1000 series devices maliciously, raising risks for organizations with misconfigured networks or insufficient access controls. This incident highlights the persistent risk of cleartext credential exposures in operational technology, an issue often underestimated in critical infrastructure. With incidents involving credential theft and unauthorized device control on the rise, compliance frameworks and supply chain partners are placing increased urgency on eliminating weak storage practices in industrial environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
CISA Issues 2025 Industrial Control System Vulnerability Advisories
Impact· medium

CISA Issues 2025 Industrial Control System Vulnerability Advisories

In December 2025, CISA disclosed six critical advisories highlighting a series of vulnerabilities across multiple industrial control system (ICS) products, including those from Güralp Systems, Johnson Controls, Hitachi Energy, Mitsubishi Electric, and Fuji Electric. The advisories detail software and firmware flaws that could allow unauthorized access, remote code execution, or complete system compromise in essential ICS devices. Exploitation could give attackers the means to disrupt critical infrastructure operations. Security teams are urged to apply mitigations, restrict network exposure, and follow vendor instructions to reduce risk. This incident underscores the growing frequency and severity of cybersecurity threats targeting ICS environments. With the expanding attack surface in operational technology (OT) networks, attackers increasingly focus on exploiting ICS vulnerabilities to disrupt important sectors. Regulators and asset owners are under pressure to implement robust, up-to-date defenses.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How Zigbee Protocol Flaws Exposed Industrial IoT Networks in 2024
Impact· high

How Zigbee Protocol Flaws Exposed Industrial IoT Networks in 2024

In early 2024, security researchers uncovered critical vulnerabilities affecting Zigbee-based industrial IoT and automation environments. By assessing real-world installations, attackers demonstrated how both spoofed packet injection and coordinator impersonation attacks could exploit application-layer protocol weaknesses and misconfigurations. Notably, exposed or hard-coded keys, absence of end-to-end encryption, and insecure default settings enabled adversaries to hijack communications, control relay devices, and ultimately compromise entire sensor networks. The attack techniques bypassed traditional network segmentation and leveraged custom wireless tools to overcome timing and profile mismatches. This incident highlights urgent gaps in IoT and industrial security — especially the risks posed by legacy or proprietary protocol deployments lagging on best-practice cryptographic implementation. With industrial sectors increasingly reliant on automated sensor networks, attackers are expanding TTPs to target low-power wireless protocols like Zigbee, making advanced monitoring and zero trust approaches more critical than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
AzeoTech DAQFactory 2025: Critical ICS Memory Flaws Open Path to Code Execution
Impact· low

AzeoTech DAQFactory 2025: Critical ICS Memory Flaws Open Path to Code Execution

In December 2025, critical memory corruption vulnerabilities were disclosed in AzeoTech DAQFactory, an industrial control system platform widely used in critical manufacturing. Attackers leveraging these flaws—such as out-of-bounds write, use-after-free, heap and stack buffer overflows, and type confusion—could upload malicious .ctl files, leading to potential arbitrary code execution or data disclosure. No remote exploitation was reported, but the flaws affect DAQFactory versions 20.7 (Build 2555) and earlier, impacting deployments worldwide. The incident underscores the persistent risk that memory-based vulnerabilities pose to ICS platforms, amplifying concerns about supply chain and file-based attacks in operational environments. Given ICS’s expanding attack surface and recent regulatory scrutiny, addressing patch management and limiting untrusted file handling remain crucial for minimizing operational risk.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
CSRF Flaw in OpenPLC_V3 Sheds Light on ICS Software Security Risks
Impact· medium

CSRF Flaw in OpenPLC_V3 Sheds Light on ICS Software Security Risks

In December 2025, a significant cybersecurity vulnerability was disclosed in OpenPLC_V3, an open-source programmable logic controller widely deployed in critical infrastructure sectors such as manufacturing, energy, transportation, and water systems. Researchers identified a Cross-Site Request Forgery (CSRF) flaw (CVE-2025-13970) that allowed remote, unauthenticated attackers to exploit absent CSRF protections, potentially tricking logged-in administrators into modifying PLC settings or uploading malicious code. This could have caused disruptive or destructive changes to industrial processes. A patch was promptly released via pull request #310, and no evidence of public exploitation has been reported to date. The incident underscores growing threats to industrial control system (ICS) environments, as attackers increasingly target device management interfaces. Regulatory and industry attention remains high, amplifying requirements for strong authentication, network segmentation, and timely vulnerability management for ICS software.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Siemens Discloses Physical Access Flaw in 2025 G5DFR Devices
Impact· medium

Siemens Discloses Physical Access Flaw in 2025 G5DFR Devices

In December 2025, Siemens Energy Services disclosed a critical vulnerability in all G5DFR versions of its Elspec G5 devices, affecting industrial control systems worldwide. Attackers with physical access could reset the Admin password by inserting a USB drive containing a public reset string, effectively bypassing authentication (CVE-2025-59392, CVSS 7.0). While exploitation required direct device access, successful attacks would allow unauthorized changes to critical system configurations, risking operational integrity within the energy sector. Siemens and CISA advised urgent firmware updates and robust network isolation to mitigate the risk. This incident highlights the persistent risk of physical-layer threats in critical infrastructure environments, even as digital attack surfaces expand. The availability of public reset procedures underscores the urgency in securing endpoints and the importance of layered, defense-in-depth strategies, especially given the evolving regulatory landscape and increased scrutiny on energy sector cybersecurity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Authentication Bypass Exposes Siemens Gridscale X Prepay ICS: 2025 Breach Analysis
Impact· low

Authentication Bypass Exposes Siemens Gridscale X Prepay ICS: 2025 Breach Analysis

In December 2025, Siemens disclosed critical vulnerabilities impacting its Gridscale X Prepay solution, widely used in energy infrastructure. The flaws—an observable response discrepancy (CVE-2025-40806) and authentication bypass via capture-replay (CVE-2025-40807)—could allow remote attackers to enumerate valid user names and circumvent lockouts, compromising operational security. Discovered by Kira of The Raven Security and coordinated via Siemens ProductCERT and CISA, these issues placed globally deployed ICS systems at risk of unauthorized access by leveraging predictable system responses and token replay, potentially impacting sensitive control environments. This incident highlights an ongoing trend of attackers exploiting authentication weaknesses in industrial control systems, underscoring the need for strict access management and timely vulnerability mitigation. With ICS assets increasingly targeted and regulatory scrutiny rising, implementing robust segmentation and monitoring is more crucial than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
CISA Warns of Multiple ICS Vulnerabilities in U-Boot, Festo LX, and CCTV Devices (2025)
Impact· medium

CISA Warns of Multiple ICS Vulnerabilities in U-Boot, Festo LX, and CCTV Devices (2025)

In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released advisories on three newly discovered vulnerabilities affecting critical components in industrial environments: Universal Boot Loader (U-Boot), Festo LX Appliances, and multiple India-based CCTV cameras. These advisories highlight exploitable weaknesses that could allow threat actors to compromise device integrity, execute unauthorized commands, or pivot deeper into industrial networks, potentially disrupting operations or stealing sensitive data. The vulnerabilities impact a broad range of operational technology (OT) deployments and may require urgent patching or mitigation to prevent exploitation. This incident underscores the increasing volume and diversity of attacks targeting industrial control systems and OT environments. As digital transformation deepens, threat actors continue to capitalize on unpatched systems and weak security controls in critical infrastructure, raising the risks for sectors reliant on ICS technology.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports