The Containment Era is here. →Explore

Industry Category

Industrial Automation

Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.

213 threat reports
Page 3 of 18

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Industrial Automation Threat Reports

Showing 2536 / 213 reports
OpenPLC v3 Vulnerability CVE-2026-14480: A Critical Threat to Industrial Control Systems
Impact· HIGH

OpenPLC v3 Vulnerability CVE-2026-14480: A Critical Threat to Industrial Control Systems

In July 2026, a critical vulnerability (CVE-2026-14480) was identified in OpenPLC v3, an open-source programmable logic controller widely used in industrial control systems. This flaw allows authenticated attackers to write arbitrary files to the filesystem, potentially leading to remote code execution with the privileges of the OpenPLC runtime user. Exploitation could result in unauthorized control over industrial processes, posing significant risks to critical infrastructure sectors such as manufacturing, energy, transportation, and water systems. The discovery of this vulnerability underscores the ongoing challenges in securing industrial control systems, especially those relying on open-source solutions. As cyber threats targeting critical infrastructure continue to evolve, it is imperative for organizations to proactively assess and mitigate vulnerabilities to prevent potential disruptions and ensure operational resilience.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities Discovered in Digi International's PortServer TS and Digi One SP IA Devices
Impact· CRITICAL

Critical Vulnerabilities Discovered in Digi International's PortServer TS and Digi One SP IA Devices

In July 2026, Digi International disclosed two significant vulnerabilities affecting their PortServer TS and Digi One SP IA devices. The first, CVE-2026-12352, allows unauthenticated attackers to bypass authentication mechanisms, granting unauthorized access to restricted resources. The second, CVE-2026-12948, is a stored cross-site scripting (XSS) vulnerability that enables authenticated administrators to inject malicious scripts into system configuration fields, which execute in the browsers of users viewing the affected pages. These vulnerabilities pose risks of unauthorized access, credential theft, and potential system compromise. The disclosure of these vulnerabilities underscores the critical importance of securing networked devices, especially those integral to industrial control systems. Organizations must prioritize timely firmware updates and implement robust network segmentation to mitigate such risks. This incident highlights the ongoing challenges in maintaining the security of legacy systems and the necessity for continuous monitoring and proactive defense strategies.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Vulnerability in Hitachi Energy e-mesh EMS: CVE-2026-42945
Impact· HIGH

Critical Vulnerability in Hitachi Energy e-mesh EMS: CVE-2026-42945

In July 2026, Hitachi Energy disclosed a critical vulnerability (CVE-2026-42945) in its e-mesh EMS versions 4.1.6, 4.4.2, and 4.7.0. This heap-based buffer overflow in the NGINX component's ngx_http_rewrite_module allows unauthenticated attackers to send crafted HTTP requests, potentially leading to application crashes and arbitrary code execution. The vulnerability arises when specific rewrite directives are used with unnamed PCRE captures and replacement strings containing a question mark. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-42945-nginx-heap-overflow-hits-hitachi-energy-e-mesh-ems.435597/?utm_source=openai)) This incident underscores the risks of integrating widely-used web components like NGINX into critical infrastructure systems. Organizations must prioritize patching affected systems and reviewing configurations to mitigate potential exploitation, especially in environments where operational technology intersects with standard web technologies.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Iranian Hackers Target U.S. Industrial Control Systems in 2026
Impact· HIGH

Iranian Hackers Target U.S. Industrial Control Systems in 2026

In early 2026, Iranian state-sponsored hackers launched a series of cyberattacks targeting U.S. critical infrastructure, focusing on industrial control systems (ICS) such as Rockwell Automation's Allen-Bradley programmable logic controllers (PLCs). These attacks exploited vulnerabilities in internet-exposed devices, leading to operational disruptions and potential safety hazards across sectors like water treatment and energy. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?oref=ng-homepage-river&utm_source=openai)) This incident underscores the escalating threat landscape for ICS environments, highlighting the urgent need for organizations to secure operational technology assets against sophisticated nation-state actors. ([cybersecuritydive.com](https://www.cybersecuritydive.com/news/critical-infrastucture-plcs-iran-hacking-censys/817209/?utm_source=openai))

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Schneider Electric's License Manager Poses Risks to Industrial Systems
Impact· HIGH

Critical Vulnerability in Schneider Electric's License Manager Poses Risks to Industrial Systems

In 2024, a critical vulnerability identified as CVE-2024-2658 was discovered in Schneider Electric's Floating License Manager, specifically within the FlexNet Publisher component. This flaw, classified under CWE-427: Uncontrolled Search Path Element, allows local non-administrative users to manipulate the OpenSSL configuration file, leading to the execution of arbitrary code with elevated privileges. Exploitation of this vulnerability can result in full control over the affected system, including access to sensitive data and potential lateral movement within industrial networks. The urgency to address this vulnerability is heightened by the increasing targeting of industrial control systems by cyber adversaries. Organizations utilizing Schneider Electric's software are advised to implement the recommended mitigations promptly to prevent potential exploitation and safeguard critical infrastructure.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Kubota Data Breach 2026: A Wake-Up Call for Industrial Cybersecurity
Impact· HIGH

Kubota Data Breach 2026: A Wake-Up Call for Industrial Cybersecurity

In early 2026, Kubota North America Corporation experienced a significant data breach where unauthorized actors accessed its network systems from March 16 to April 20. The intrusion led to the exposure of sensitive personal information belonging to employees and their dependents, including full names, Social Security numbers, dates of birth, taxpayer IDs, driver's license numbers, direct deposit bank account details, corporate payment card information, and benefits enrollment data. Kubota has since notified affected individuals and offered identity protection services to mitigate potential risks. This incident underscores the escalating threat landscape targeting industrial manufacturers, emphasizing the critical need for robust cybersecurity measures. The breach highlights the importance of proactive security protocols and continuous monitoring to safeguard sensitive employee data against unauthorized access and potential misuse.

3 weeks ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Vulnerabilities in Delta Electronics DVP12SE PLCs: CVE-2026-12819 and CVE-2026-12818
Impact· CRITICAL

Critical Vulnerabilities in Delta Electronics DVP12SE PLCs: CVE-2026-12819 and CVE-2026-12818

In June 2026, critical vulnerabilities were identified in Delta Electronics DVP12SE Programmable Logic Controllers (PLCs), specifically CVE-2026-12819 and CVE-2026-12818. These flaws allow remote attackers to issue commands, modify operational values, and interfere with control logic without authentication. The vulnerabilities affect all versions of the DVP12SE PLC, potentially enabling unauthorized access to sensitive control functions and causing resource exhaustion through flooding attacks. The discovery of these vulnerabilities underscores the increasing risks associated with industrial control systems (ICS) and the necessity for robust security measures. Organizations utilizing Delta Electronics DVP12SE PLCs should implement recommended mitigations, such as enabling IP filtering, setting up password protection, and ensuring network isolation, to safeguard against potential exploitation.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical XZ Utils Vulnerability Affects B&R Products (CVE-2025-31115)
Impact· HIGH

Critical XZ Utils Vulnerability Affects B&R Products (CVE-2025-31115)

In June 2026, B&R Industrial Automation GmbH disclosed a critical vulnerability (CVE-2025-31115) in their products due to a flaw in XZ Utils versions 5.3.3alpha to 5.8.0. This race condition within the multithreaded .xz decoder in liblzma could allow attackers to crash the system or corrupt memory data. Affected products include PPC3100, C50, C80, FT50, MT50, T30, T80, and T50, with specific versions listed in the advisory. The vulnerability has a CVSS v3 base score of 7.5, indicating high severity. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai)) This incident underscores the importance of promptly addressing vulnerabilities in widely used open-source libraries. Organizations are advised to update to XZ Utils version 5.8.1 or apply the provided patches to mitigate potential risks. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Authentication Bypass in Frangoteam FUXA SCADA/HMI Software (CVE-2026-13207)
Impact· HIGH

Critical Authentication Bypass in Frangoteam FUXA SCADA/HMI Software (CVE-2026-13207)

In June 2026, a critical authentication bypass vulnerability (CVE-2026-13207) was identified in Frangoteam's FUXA SCADA/HMI software versions 1.3.1 and earlier. This flaw allows unauthenticated remote attackers to access sensitive user and role data by exploiting improper path normalization in the REST API. By manipulating URL paths with dot-segment sequences, attackers can bypass authentication checks and retrieve confidential information without credentials. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-13207?utm_source=openai)) This incident underscores the persistent risks associated with authentication bypass vulnerabilities in industrial control systems. As SCADA environments increasingly integrate web-based interfaces, ensuring robust authentication mechanisms becomes paramount to prevent unauthorized access and potential operational disruptions.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities Discovered in Mitsubishi Electric's MELSOFT Update Manager
Impact· HIGH

Critical Vulnerabilities Discovered in Mitsubishi Electric's MELSOFT Update Manager

In June 2026, Mitsubishi Electric disclosed multiple vulnerabilities in its MELSOFT Update Manager SW1DND-UDM-M software, specifically versions 1.000A through 1.014Q. These vulnerabilities, identified as CVE-2025-53816, CVE-2025-53817, CVE-2025-55188, and CVE-2025-11001, stem from issues within the bundled 7-Zip component. Exploitation could allow local attackers to execute arbitrary code, cause denial-of-service conditions, or tamper with information by convincing users to decompress specially crafted archive files. The affected software is widely used in critical manufacturing sectors globally. ([knutmichael.com](https://knutmichael.com/radar/2026-06-30-mitsubishi-electric-melsoft-update-manager-sw1dnd-udm-m?utm_source=openai)) The disclosure underscores the persistent risks associated with third-party components in industrial control systems. Organizations are urged to promptly update to version 1.015R or later and implement recommended security measures to mitigate potential threats. ([knutmichael.com](https://knutmichael.com/radar/2026-06-30-mitsubishi-electric-melsoft-update-manager-sw1dnd-udm-m?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTUs
Impact· HIGH

Critical Vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTUs

In June 2026, Schneider Electric disclosed two critical vulnerabilities affecting their EasyLogic T150 and Saitel DP Remote Terminal Units (RTUs). The first, CVE-2026-9650, involves insufficiently protected credentials, allowing unauthenticated attackers to access sensitive information stored within firmware or system files. The second, CVE-2026-9651, pertains to incorrect permission assignments for critical resources, enabling attackers with privileged local access to read improperly protected system files, potentially leading to account compromise. These vulnerabilities pose significant risks to critical infrastructure sectors, including manufacturing and energy, as they could lead to unauthorized access and control over essential systems. The disclosure of these vulnerabilities underscores the ongoing challenges in securing industrial control systems (ICS). As cyber threats targeting ICS continue to evolve, organizations must remain vigilant, regularly updating and patching their systems to mitigate potential risks. This incident highlights the importance of proactive cybersecurity measures and the need for continuous monitoring to protect critical infrastructure from emerging threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Blackfield Ransomware Targets Nidec Corporation with $2 Million Demand
Impact· HIGH

Blackfield Ransomware Targets Nidec Corporation with $2 Million Demand

In June 2026, Nidec Corporation, a leading Japanese manufacturer of electronic components, disclosed a ransomware attack on its Taiwanese subsidiary, Nidec Chaun Choung Technology. The Blackfield ransomware group demanded a $2 million ransom, threatening to publish or sell stolen data if the payment was not made. Nidec implemented emergency measures, including shutting down affected servers and networks, to contain the damage. The company is assessing the impact on its operations but does not anticipate significant effects on other subsidiaries. This incident underscores the persistent threat of ransomware attacks targeting critical manufacturing sectors. Organizations must remain vigilant, as threat actors continue to evolve their tactics, employing double extortion methods that combine data encryption with the threat of data exposure to pressure victims into paying ransoms.

3 weeks ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports