✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
Critical Vulnerabilities in WAGO Industrial Managed Switches Expose Systems to Remote Attacks
In early 2026, multiple critical vulnerabilities were discovered in WAGO GmbH & Co. KG's Industrial Managed Switches, notably models 852-1322 and 852-1328. These flaws, including stack buffer overflows and authentication bypasses, allowed unauthenticated remote attackers to execute arbitrary code, potentially leading to full system compromise. The vulnerabilities stemmed from unsafe input handling in the devices' web-based management interfaces, which utilized modified lighttpd servers and custom CGI binaries. Exploitation could result in denial-of-service conditions and unauthorized access to sensitive configurations. ([certvde.com](https://certvde.com/en/advisories/VDE-2026-004/?utm_source=openai)) This incident underscores the persistent risks associated with industrial control systems (ICS) and the critical need for robust security measures. The vulnerabilities highlight the importance of regular firmware updates, secure coding practices, and comprehensive network segmentation to protect against unauthorized access and potential operational disruptions.
4 months ago
Kill Chain
Kaspersky's 2026 Security Bulletin: Navigating Persistent and Emerging Cyber Threats in Telecommunications
In December 2025, Kaspersky released its Security Bulletin highlighting persistent and emerging cybersecurity threats in the telecommunications sector. The report identifies four primary threat categories: Advanced Persistent Threats (APTs) aiming for long-term espionage, supply chain vulnerabilities exploiting interconnected vendor ecosystems, Distributed Denial-of-Service (DDoS) attacks affecting service availability, and SIM-enabled fraud targeting mobile networks. Additionally, the integration of new technologies such as AI-driven network management, post-quantum cryptography, and 5G-to-satellite connectivity introduces new operational risks. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-warns-telecom-threats-from-2025-will-carry-into-2026-as-new-technology-adds-new-risk?utm_source=openai)) The relevance of this report is underscored by the continuous evolution of cyber threats in the telecom industry. As operators adopt advanced technologies, they must address both existing and emerging risks to maintain network security and service reliability. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-warns-telecom-threats-from-2025-will-carry-into-2026-as-new-technology-adds-new-risk?utm_source=openai))
4 months ago
Kill Chain
Aurora Generator Test 2007: A Cybersecurity Wake-Up Call for Critical Infrastructure
In March 2007, the Aurora Generator Test conducted by the Idaho National Laboratory demonstrated the potential for cyberattacks to physically destroy critical infrastructure. By exploiting vulnerabilities in industrial control systems, researchers remotely manipulated a diesel generator's circuit breakers, causing it to operate out of phase and ultimately leading to its destruction. This experiment highlighted the susceptibility of power grids to cyber threats, especially due to the use of legacy communication protocols lacking security measures. The Aurora Generator Test remains relevant today as it underscores the ongoing risks associated with outdated industrial control systems. Despite advancements in cybersecurity, many critical infrastructures still rely on legacy systems, making them vulnerable to similar attacks. This incident serves as a cautionary tale, emphasizing the need for continuous assessment and upgrading of security protocols in industrial environments.
4 months ago
Kill Chain
Critical Vulnerability in Inductive Automation's Ignition Software: CVE-2025-13911
In December 2025, a vulnerability (CVE-2025-13911) was identified in Inductive Automation's Ignition SCADA software versions 8.1.x and 8.3.x. This flaw allows authenticated administrators to upload malicious project files containing Python scripts, which execute with SYSTEM-level privileges on Windows systems. The vulnerability arises from insufficient restrictions on Python library imports within the scripting environment, combined with the Ignition service account possessing excessive system permissions. Exploitation could lead to full system compromise, enabling attackers to manipulate automation processes, disrupt operations, exfiltrate sensitive data, or deploy ransomware. ([support.inductiveautomation.com](https://support.inductiveautomation.com/hc/en-us/articles/41992057776397-Script-Resource-Import-Vulnerability-for-Windows-CVE-2025-13911?utm_source=openai)) This incident underscores the critical importance of implementing the principle of least privilege and enforcing strict validation of imported project files in industrial control systems. Organizations must prioritize mitigating such vulnerabilities to safeguard against potential operational disruptions and security breaches.
4 months ago
Kill Chain
US Authorities Dismantle SocksEscort Proxy Network Exploiting Linux Malware
In March 2026, U.S. and European law enforcement agencies, in collaboration with private partners, dismantled the SocksEscort cybercrime proxy network, which had been operational for over a decade. This network utilized the AVRecon malware to compromise approximately 70,000 small office/home office (SOHO) routers, creating a botnet that offered cybercriminals access to 'clean' residential IP addresses from major ISPs. The service facilitated various illicit activities, including cryptocurrency thefts and financial frauds, resulting in significant monetary losses. ([securityaffairs.com](https://securityaffairs.com/149007/hacking/avrecon-bot-socksescort.html?utm_source=openai)) The disruption of SocksEscort underscores the persistent threat posed by malware targeting SOHO routers, which often lack regular security updates and monitoring. This incident highlights the critical need for enhanced security measures and vigilance in protecting network infrastructure to prevent similar exploitations in the future.
4 months ago
Kill Chain
CISA Adds Five Known Exploited Vulnerabilities to Catalog
On March 5, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities include: CVE-2017-7921 (Hikvision Multiple Products Improper Authentication), CVE-2021-22681 (Rockwell Multiple Products Insufficient Protected Credentials), CVE-2021-30952 (Apple Multiple Products Integer Overflow or Wraparound), CVE-2023-41974 (Apple iOS and iPadOS Use-After-Free), and CVE-2023-43000 (Apple Multiple Products Use-After-Free). These vulnerabilities are commonly targeted by malicious actors and pose significant risks to federal enterprises. The inclusion of these vulnerabilities underscores the persistent threat landscape and the importance of timely remediation. Organizations are urged to prioritize addressing these vulnerabilities to mitigate potential cyberattacks and protect their networks against active threats.
4 months ago
Kill Chain
Delta Electronics CNCSoft-G2 2026 Out-of-Bounds Write Vulnerability
In March 2026, Delta Electronics identified a critical vulnerability (CVE-2026-3094) in its CNCSoft-G2 software, specifically an out-of-bounds write issue in the DOPSoft component's DPAX file parsing. This flaw allows attackers to execute arbitrary code if a user opens a maliciously crafted file, potentially compromising system integrity. The vulnerability affects CNCSoft-G2 versions prior to V2.1.0.39. Delta Electronics has released version 2.1.0.39 to address this issue and recommends users update promptly. This incident underscores the persistent risks associated with file parsing vulnerabilities in industrial control systems, emphasizing the need for regular software updates and vigilant cybersecurity practices to protect critical infrastructure.
4 months ago
Kill Chain
Critical Vulnerabilities in Hitachi Energy's Relion REB500: Immediate Action Required
In February 2026, Hitachi Energy disclosed two significant vulnerabilities in its Relion REB500 product, identified as CVE-2026-2459 and CVE-2026-2460. These flaws allow authenticated users with specific roles to access and modify unauthorized directories, potentially compromising system integrity. The vulnerabilities affect versions up to and including 8.3.3.0. Hitachi Energy has released version 8.3.3.1 to address these issues and recommends users update promptly. ([cve.qwiksec.com](https://cve.qwiksec.com/cve/CVE-2026-2460?utm_source=openai)) This incident underscores the critical importance of stringent access controls and timely software updates in industrial control systems, especially within the energy sector. Organizations must remain vigilant against privilege escalation vulnerabilities to safeguard operational technology environments.
4 months ago
Kill Chain
Critical Vulnerability in Portwell Engineering Toolkits Poses Risks to Industrial Control Systems
In March 2026, a critical vulnerability (CVE-2026-3437) was identified in Portwell Engineering Toolkits version 4.8.2, widely used in industrial control systems. This flaw allows local authenticated attackers to read and write arbitrary kernel memory via the toolkit's driver, potentially leading to privilege escalation or denial-of-service conditions. The vulnerability has a CVSS v3.1 base score of 8.8, indicating high severity. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-3437?utm_source=openai)) The vulnerability underscores the importance of securing engineering workstations in industrial environments, as exploitation could compromise critical manufacturing and energy sectors. Organizations are advised to implement defense-in-depth strategies, restrict access to engineering systems, and monitor for unauthorized activities to mitigate potential risks. ([therealistjuggernaut.com](https://therealistjuggernaut.com/2026/03/03/portwell-engineering-toolkits-vulnerability-raises-privilege-escalation-risks-in-industrial-development-environments/?utm_source=openai))
4 months ago
Kill Chain
Critical Vulnerabilities in Hitachi Energy RTU500 Series Require Immediate Attention
In February 2026, Hitachi Energy disclosed multiple vulnerabilities affecting its RTU500 series products, including CVE-2026-1772, CVE-2026-1773, CVE-2024-8176, and CVE-2025-59375. These vulnerabilities, if exploited, could lead to unauthorized access to user management information and potential device outages. The affected firmware versions range from 12.7.1 to 13.8.1. Hitachi Energy has released firmware updates to address these issues and recommends users implement the provided mitigations to secure their systems. This incident underscores the critical importance of timely vulnerability management in industrial control systems, especially within the energy sector. Organizations are urged to stay vigilant and apply security patches promptly to mitigate potential risks associated with such vulnerabilities.
4 months ago
Kill Chain
UFP Technologies Cyberattack: A 2026 Data Theft Incident
In February 2026, UFP Technologies, a leading medical device manufacturer, detected unauthorized access to its IT systems. The breach, identified on February 14, led to the theft and potential destruction of company data, impacting critical functions such as billing and label creation for customer deliveries. Immediate containment measures were implemented, and external cybersecurity experts were engaged to investigate and remediate the incident. The company has since restored access to the affected information and believes the threat actor has been removed from its systems. This incident underscores the escalating cyber threats targeting the healthcare sector, emphasizing the need for robust cybersecurity measures. Organizations must remain vigilant against sophisticated attacks that can disrupt operations and compromise sensitive data, highlighting the importance of proactive defense strategies and incident response planning.
5 months ago
Kill Chain
Critical Vulnerabilities Discovered in Jinan USR IOT's USR-W610 Device
In February 2026, multiple critical vulnerabilities were identified in Jinan USR IOT Technology Limited's USR-W610 serial device server, affecting firmware versions up to and including 3.1.1.0. These vulnerabilities include weak password requirements, cleartext transmission of sensitive information, insufficiently protected credentials, and missing authentication for critical functions. Exploitation could lead to authentication bypass, denial-of-service conditions, or unauthorized access to user credentials, including administrative accounts. ([windowsforum.com](https://windowsforum.com/threads/high-severity-ics-advisory-hits-usr-w610-serial-gateway-cve-2026-25715-to-cve-2026-26048.402628/post-959899?utm_source=openai)) The USR-W610 is widely deployed in industrial environments to bridge legacy serial devices with IP-based networks. Given the device's role in critical manufacturing sectors, these vulnerabilities pose significant risks, including potential unauthorized process changes, production downtime, and safety incidents. ([windowsforum.com](https://windowsforum.com/threads/high-severity-ics-advisory-hits-usr-w610-serial-gateway-cve-2026-25715-to-cve-2026-26048.402628/post-959899?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports