✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
CISA Exposes Multi-Vendor ICS Vulnerabilities: 2025 Critical Infrastructure Security Alert
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued six critical advisories revealing vulnerabilities across various Industrial Control Systems (ICS) devices, including those from Automated Logic, ICAM365, Opto 22, Festo, and Emerson. Attackers could exploit these flaws—ranging from weak authentication to remote code execution—potentially enabling unauthorized access, data exfiltration, or disruption of operational technology environments. ICS operators were urged to review technical details and partner with vendors for rapid mitigation to prevent lateral movement or credential compromise impacting essential infrastructure. This incident highlights the growing convergence of operational technology and IT risk, with threat actors increasingly targeting ICS environments. The regulatory and threat landscape is evolving, compelling organizations to strengthen segmentation, network monitoring, and zero trust security controls in light of rising attacks on critical infrastructure.
6 months ago
Kill Chain
Critical UPS Vulnerability: Emerson Appleton UPSMON-PRO Flaw Exposes ICS to Remote Attacks
In November 2025, a critical vulnerability (CVE-2024-3871) was disclosed affecting Emerson's Appleton UPSMON-PRO, a monitoring solution widely deployed in critical infrastructure sectors including manufacturing and healthcare. Security researchers found that remotely sent, specially crafted UDP packets could trigger a stack-based buffer overflow, granting attackers SYSTEM-level privileges and permitting remote code execution on unpatched systems. The product, which reached End of Life status prior to disclosure, is still in use across several organizations, amplifying the impact of the vulnerability on global operational technology environments. This incident underscores a growing pattern of legacy ICS software vulnerabilities being targeted via low-complexity, remote attacks. Increased regulatory scrutiny and the advancing sophistication of attackers elevate the importance of updating unsupported systems and implementing defense-in-depth strategies.
6 months ago
Kill Chain
Critical OS Command Injection Vulnerability Hits Opto 22 ICS Devices in 2025
In November 2025, Opto 22 announced a critical vulnerability (CVE-2025-13087) affecting its GRV-EPIC and groov RIO programmable logic controllers. Discovered by security researchers from Meta, the flaw resides in the Groov Manage REST API, allowing attackers with administrative access to exploit improper neutralization of special elements and execute arbitrary shell commands as root on affected devices. This vulnerability places manufacturing environments deploying these controllers at risk of remote code execution and potential full device compromise, particularly in critical infrastructure operations worldwide. The incident highlights the continued targeting of industrial control systems by security researchers and underscores the urgency for timely patching in operational technology (OT) environments. With attackers increasingly seeking entry via API abuse and elevated privileges, organizations must remain vigilant against growing threats to cloud-connected OT and IIoT assets.
6 months ago
Kill Chain
Critical Vulnerabilities in Railway Braking Systems Expose OT Security Gaps
In June 2024, security researchers discovered multiple vulnerabilities in the braking systems of modern trains, revealing that low-cost, readily available hardware could be used to exploit weaknesses in operational technology (OT) environments. Attackers demonstrated that by using items such as recycled cans and basic electronics sourced online, they could manipulate communication between the train conductor's controls and the braking systems. The lack of encrypted traffic and segmentation allowed malicious actors to reroute or interrupt braking commands, posing severe safety and operational risks to critical railway infrastructure. This incident underscores a broader trend of cyber-physical risk in OT systems, where traditional safety assumptions are being undermined by the exposure of legacy protocols and weak internal controls. As rail operators increasingly digitize and connect systems, adversaries have more opportunities to exploit gaps in lateral defenses and traffic security.
6 months ago
Kill Chain
Critical 2025 METZ CONNECT EWIO2 Vulnerabilities: Auth Bypass and RCE Expose Industrial Control Risks
In November 2025, multiple critical vulnerabilities were disclosed in METZ CONNECT EWIO2 industrial control devices, enabling remote attackers to bypass authentication and gain full control, execute arbitrary code, and read sensitive device information. The flaws include authentication bypass (CVE-2025-41733), PHP remote file inclusion (CVE-2025-41734), unrestricted file upload (CVE-2025-41735), path traversal (CVE-2025-41736), and improper access control (CVE-2025-41737), with CVSS v4 scores ranging from 8.7 to 9.3. Affected devices are used globally in critical manufacturing environments, and exploitation could trigger operational disruption or unauthorized control. This incident is highly relevant as it targets the operational technology (OT) sector—a high-value, often less-protected attack surface increasingly sought after by threat actors. As convergence between IT and OT grows, unpatched, internet-exposed devices in critical infrastructure remain susceptible to devastating attacks, underscoring urgent need for robust patching, segmentation, and proactive defense.
6 months ago
Kill Chain
CISA Releases Critical ICS Vulnerability Advisories: 2025 Update for Industrial Systems
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released six Industrial Control Systems (ICS) advisories addressing multiple critical vulnerabilities impacting popular ICS products, including Schneider Electric EcoStruxure and Pro-face BLUE Open Studio, Shelly Pro series, METZ CONNECT EWIO2, and PowerChute Serial Shutdown. These advisories alert asset owners, operators, and administrators about exploitation risks and provide detailed technical information and mitigation steps. The vulnerabilities, if left unaddressed, expose essential operational technology environments to risks such as unauthorized access, manipulation, and potential disruption of critical infrastructure services. This disclosure comes amidst a surge in attacks targeting industrial and OT environments, underscoring increased adversary focus on exploiting ICS vulnerabilities. With regulatory pressures mounting and recent attacks on critical infrastructure making headlines, organizations are urged to address these risks with urgency.
6 months ago
Kill Chain
Shelly Pro 4PM 2025 Vulnerability: Unchecked Resource Allocation Triggers Industrial DoS
In November 2025, a significant vulnerability (CVE-2025-11243) was disclosed in Shelly Pro 4PM, a smart DIN rail switch commonly used in critical manufacturing environments worldwide. The flaw, arising from improper resource allocation and lack of input bounds checking, allowed an attacker on the local network to trigger a denial-of-service condition by sending specially crafted RPC requests. This caused the device to overallocate memory and reboot, risking loss of control or downtime in industrial settings. No exploitation has been reported publicly, but affected firmware versions prior to 1.6 remain at risk until patched. This incident underscores the persistent risk of denial-of-service vulnerabilities in IoT and industrial devices, especially as connected manufacturing assets proliferate. The failure in secure resource management highlights the growing regulatory and operational focus on robust device security amid expanding threat surfaces.
6 months ago
Kill Chain
2025 Shelly Pro 3EM ICS Flaw Exposes Modbus Devices to DoS
In November 2025, a critical Out-of-Bounds Read vulnerability (CVE-2025-12056) was disclosed in the Shelly Pro 3EM, a smart DIN rail switch used in industrial control systems worldwide. Security researchers revealed that a specially crafted Modbus request allows attackers on the adjacent network to trigger an illegal memory access, causing a denial-of-service condition by repeatedly rebooting the device. All versions of the Pro 3EM are affected, including deployments across critical manufacturing sectors. Shelly did not issue an official response, leaving users to rely on CISA defensive guidance. This incident exemplifies the growing risk of targeted vulnerabilities in widely deployed OT (operational technology) and industrial IoT devices. As criminals and nation-state actors increasingly focus on ICS and critical infrastructure, maintaining robust segmentation, access controls, and secure outbound communications is more relevant than ever.
6 months ago
Kill Chain
AVEVA 2025: XSS Vulnerability in Application Server IDE Threatens Industrial Security
In November 2025, AVEVA disclosed a critical security vulnerability (CVE-2025-8386) in its Application Server IDE, exposing numerous organizations in the critical manufacturing sector worldwide. The flaw, classified as an Improper Neutralization of Script-Related HTML Tags (CWE-80), allows authenticated users with elevated permissions to tamper with application help files and persistently inject cross-site scripting (XSS) payloads. If exploited during configuration-time operations, malicious code can trigger upon subsequent access by other users, resulting in horizontal or vertical privilege escalation. While only affective at config-time and not impacting runtime components, the risk is heightened due to widespread industrial deployments. This incident underscores persistent challenges in securing industrial software, as XSS and privilege escalation vulnerabilities remain a significant vector for lateral attacker movement. The AVEVA disclosure demonstrates the urgency for robust privilege auditing and regular patching, especially as attackers increasingly target industrial environments for both espionage and disruption.
6 months ago
Kill Chain
CISA Flags 18 Critical ICS Vulnerabilities Across Major Vendors
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released 18 advisories highlighting critical vulnerabilities across a wide spectrum of Industrial Control Systems (ICS) products from vendors such as Mitsubishi Electric, AVEVA, Rockwell Automation, Siemens, and others. These advisories detailed security gaps including unencrypted communications, insufficient segmentation, lack of policy enforcement, and exploitable firmware flaws. Although no specific exploitation campaigns were publicly confirmed at the time, the breadth and technical depth of the advisories underscore the ICS sector’s wide attack surface and the urgent need for robust controls and timely patching to prevent downtime, data loss, or operational safety issues. This disclosure is especially relevant given the escalating sophistication of threat actors targeting operational technology and the convergence of IT/OT networks. The incident reflects a steady increase in supply chain exposures and nation-state attention on industrial sectors, amplifying risk to critical infrastructure worldwide.
6 months ago
Kill Chain
Critical Authorization Flaw Exposes Rockwell Automation Verve Asset Manager (2025)
In November 2025, Rockwell Automation disclosed a critical vulnerability (CVE-2025-11862) in multiple versions of its Verve Asset Manager platform, widely used in industrial control system cybersecurity. The flaw, present from versions 1.33 up to 1.41.3, arises from an incorrect authorization configuration that allows unauthorized read-only users to perform privileged API operations, such as reading, updating, and deleting user accounts. The vulnerability, which is remotely exploitable with low attack complexity, exposes critical manufacturing environments to potential data breaches or sabotage until properly patched. Rockwell addressed the issue in version 1.41.4 and subsequent releases, urging all customers to update immediately. This incident underscores the growing risk baseline facing operational technology (OT) and ICS environments as attackers increasingly target authorization misconfigurations and API exposures. Regulatory pressure and rising sophistication in adversary tactics make strong access controls and rapid patch management more essential than ever for organizations managing critical infrastructure.
6 months ago
Kill Chain
2025 Rockwell FactoryTalk Policy Manager DoS Vulnerability Exposes Critical Manufacturing
In November 2025, Rockwell Automation disclosed a critical vulnerability (CVE-2024-22019) affecting versions 6.51.00 and earlier of its FactoryTalk Policy Manager, a tool widely deployed in industrial and manufacturing environments for policy enforcement and network segmentation. The flaw—tied to improper resource shutdown or release in the Node.js HTTP server—enables remote attackers to send specially crafted chunked HTTP requests that exhaust CPU and network resources, resulting in denial-of-service (DoS) conditions. While no active exploitation was reported as of publication, the vulnerability posed operational risks to OT systems globally, especially in critical manufacturing sectors. The incident underscores the risks posed by third-party software dependencies in industrial control system environments, especially as attackers target resource exhaustion vectors that bypass conventional safeguards. The disclosure highlights the increasing urgency for proactive vulnerability management and defense-in-depth strategies, given the essential role of OT in critical infrastructure.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports