The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
Critical Vulnerabilities Discovered in Serial-to-IP Converters: A Wake-Up Call for OT Security
In April 2026, Forescout Technologies identified 22 new vulnerabilities in serial-to-IP converters from Lantronix and Silex, devices integral to connecting legacy industrial equipment to modern networks. These vulnerabilities, including remote code execution and authentication bypass, could allow attackers to disrupt operations, move laterally across networks, and tamper with sensitive data. Notably, tens of thousands of these devices are exposed online, increasing the risk to critical infrastructure sectors such as utilities, manufacturing, and healthcare. This discovery underscores the persistent security challenges in operational technology environments, particularly concerning devices that bridge legacy systems with modern networks. The prevalence of outdated components and inadequate security measures in these converters highlights the urgent need for organizations to assess and fortify their OT security postures to prevent potential exploitation.
5 months ago
Kill Chain
BRIDGE:BREAK Vulnerabilities Threaten Critical Infrastructure Security
In April 2026, Forescout Technologies identified 22 vulnerabilities in serial-to-IP converters from Lantronix and Silex, devices integral to connecting legacy industrial equipment to modern networks. These vulnerabilities, collectively named BRIDGE:BREAK, could allow attackers to disrupt operations, move laterally across networks, tamper with sensitive data, or take control of affected devices. The flaws include remote code execution, authentication bypass, firmware manipulation, denial of service, and exposure of confidential information. Notably, tens of thousands of these devices are accessible over the internet, significantly broadening the attack surface for potential cyberattacks. This discovery underscores the persistent security challenges in operational technology environments, especially concerning devices that bridge legacy systems with modern infrastructure. The prevalence of these vulnerabilities highlights the need for organizations to reassess their security postures, particularly in sectors like utilities, manufacturing, and healthcare, where such devices are commonly deployed.
5 months ago
Kill Chain
ZionSiphon Malware: A New Threat to Israeli Water Infrastructure
In April 2026, cybersecurity researchers identified a new malware strain named ZionSiphon, specifically engineered to target Israeli water treatment and desalination systems. The malware exhibits capabilities such as establishing persistence, modifying local configuration files, and scanning for operational technology (OT) services within local networks. Notably, ZionSiphon is designed to operate exclusively within Israeli IP address ranges and targets processes associated with water treatment operations, including chlorine dosing and pressure control systems. While the current version contains a flaw that prevents full execution, its architecture indicates a significant advancement in OT-targeted cyber threats. ([thehackernews.com](https://thehackernews.com/2026/04/researchers-detect-zionsiphon-malware.html?utm_source=openai)) This discovery underscores a growing trend of politically motivated cyberattacks aimed at critical infrastructure. The emergence of ZionSiphon highlights the increasing sophistication of threats targeting OT environments, emphasizing the need for enhanced security measures to protect essential services from potential sabotage.
5 months ago
Kill Chain
Dragon Boss Solutions' 2025 Adware Supply Chain Attack: A Wake-Up Call for Cybersecurity
In March 2025, Dragon Boss Solutions LLC, a company based in the United Arab Emirates, distributed adware that exploited an unsecured software update mechanism to disable antivirus programs on over 25,000 systems globally. The adware utilized Advanced Installer's update tool to deploy malicious payloads with SYSTEM privileges, effectively neutralizing security defenses and establishing persistence through scheduled tasks and Windows Management Instrumentation (WMI) event subscriptions. This left numerous high-value networks, including educational institutions, government entities, and critical infrastructure, vulnerable to further exploitation. ([huntress.com](https://www.huntress.com/blog/pups-grow-fangs?utm_source=openai)) This incident underscores the evolving threat landscape where seemingly benign software can transform into significant security risks. The exploitation of legitimate update mechanisms highlights the necessity for organizations to scrutinize software supply chains and implement robust monitoring to detect and mitigate such sophisticated attacks. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/harmless-global-adware-av-killer/?utm_source=openai))
5 months ago
Kill Chain
Critical Authorization Flaw in AVEVA Pipeline Simulation: CVE-2026-5387
In April 2026, a critical vulnerability (CVE-2026-5387) was identified in AVEVA Pipeline Simulation software, affecting versions up to 2025 SP1 build 7.1.9497.6351. This flaw allows unauthenticated attackers to perform operations reserved for high-privilege roles, such as modifying simulation parameters and training records, leading to potential privilege escalation. ([cvefeed.io](https://cvefeed.io/vuln/detail/CVE-2026-5387?utm_source=openai)) The incident underscores the importance of robust authorization mechanisms in industrial control systems. Organizations are urged to upgrade to AVEVA Pipeline Simulation 2025 SP1 P01 (build 7.1.9580.8513) or higher and implement network access restrictions to mitigate this risk. ([aveva.com](https://www.aveva.com/en/support-and-success/cyber-security-updates/?utm_source=openai))
5 months ago
Kill Chain
ZionSiphon Malware: A New Threat to Water Treatment Facilities
In April 2026, cybersecurity researchers identified 'ZionSiphon,' a malware specifically designed to target operational technology within water treatment and desalination facilities in Israel. The malware aims to manipulate industrial control systems by increasing chlorine levels and adjusting hydraulic pressures to hazardous levels. Although the current version contains a flawed encryption logic that renders it non-functional, future iterations could rectify this issue, posing significant risks to critical infrastructure. This incident underscores the escalating threat landscape facing critical infrastructure sectors, particularly water treatment facilities. The emergence of specialized malware like ZionSiphon highlights the need for enhanced cybersecurity measures and vigilance to protect essential services from potential sabotage and disruption.
5 months ago
Kill Chain
Backdoor.MSIL.XWorm Phishing Campaign Compromises ICS Globally in Q4 2025
In Q4 2025, a significant phishing campaign known as "Curriculum-vitae-catalina" targeted HR personnel globally. Attackers sent emails disguised as job applications, with subjects like "Resume" or "Attached Resume," containing malicious attachments named "Curriculum Vitae-Catalina.exe." When executed, these files installed the Backdoor.MSIL.XWorm malware, granting remote control over infected systems. The campaign unfolded in two waves: the first in October affecting regions including Russia, Western Europe, South America, and Canada; the second in November impacting other areas. The attack subsided by December. Regions with historically high email threat rates, such as Southern Europe, South America, and the Middle East, reported the highest infection rates. In Africa, the malware also spread via USB devices connected to ICS computers. ([securelist.com](https://securelist.com/industrial-threat-report-q4-2025/119392/?utm_source=openai)) This incident underscores the evolving sophistication of phishing attacks targeting industrial control systems (ICS). The widespread distribution and rapid propagation of Backdoor.MSIL.XWorm highlight the critical need for enhanced email security measures and user awareness training to mitigate such threats.
5 months ago
Kill Chain
Volt Typhoon 2023: Unveiling the Chinese Cyber Threat to U.S. Infrastructure
In May 2023, Microsoft and U.S. intelligence agencies identified a Chinese state-sponsored cyber group, Volt Typhoon, infiltrating critical infrastructure sectors in the United States, including communications, manufacturing, utilities, and transportation. Active since mid-2021, Volt Typhoon employed 'living-off-the-land' techniques, utilizing legitimate system tools to evade detection, and targeted systems in Guam, a strategic U.S. military hub. The group's activities aimed to gather intelligence and potentially disrupt critical communications between the U.S. and Asia during future crises. ([techspot.com](https://www.techspot.com/news/98826-microsoft-global-intelligence-agencies-warn-chinese-hackers-infecting.html?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors to national security. The use of stealthy techniques by Volt Typhoon highlights the need for enhanced detection and response capabilities within critical infrastructure sectors to mitigate potential disruptions and safeguard sensitive information.
5 months ago
Kill Chain
Critical Vulnerability in wolfSSL: CVE-2026-5194 Allows ECDSA Certificate Authentication Bypass
In April 2026, a critical vulnerability identified as CVE-2026-5194 was discovered in the wolfSSL library, a widely used SSL/TLS implementation designed for embedded systems and IoT devices. This flaw arises from missing hash/digest size and Object Identifier (OID) checks during the verification of ECDSA certificates, allowing the acceptance of improperly small digests. Consequently, attackers could exploit this weakness to bypass ECDSA certificate-based authentication, potentially leading to unauthorized access and man-in-the-middle attacks. The issue affects configurations where both ECC and EdDSA or ML-DSA are enabled. wolfSSL addressed this vulnerability in version 5.9.1, released on April 8, 2026. The discovery of CVE-2026-5194 underscores the critical importance of rigorous certificate validation processes in cryptographic libraries. As wolfSSL is utilized in over 5 billion devices across various sectors, including industrial control systems, automotive, and aerospace, the potential impact of this vulnerability is extensive. Organizations relying on wolfSSL are urged to promptly update to the patched version to mitigate security risks.
5 months ago
Kill Chain
Iranian Cyberattack on U.S. Industrial Devices in 2026
In March 2026, Iranian state-sponsored hackers targeted U.S. critical infrastructure by exploiting internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). These attacks led to operational disruptions and financial losses across sectors including government services, water and wastewater systems, and energy. The attackers extracted device project files and manipulated human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, compromising industrial processes. ([techcrunch.com](https://techcrunch.com/2026/04/07/iranian-hackers-are-targeting-american-critical-infrastructure-u-s-agencies-warn/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure. The exploitation of industrial control systems highlights the urgent need for enhanced cybersecurity measures, including network segmentation, regular patching, and the implementation of multifactor authentication to protect against such sophisticated attacks.
5 months ago
Kill Chain
Critical Vulnerability in GPL Odorizers GPL750 Devices (CVE-2026-4436)
In April 2026, a critical vulnerability (CVE-2026-4436) was identified in GPL Odorizers' GPL750 devices, which are used for odorant injection in natural gas pipelines. This flaw allows low-privileged remote attackers to manipulate register values via Modbus packets, potentially leading to incorrect odorant levels being injected into gas lines. Affected versions include GPL750 (XL4) >=v1.0, GPL750 (XL4 Prime) >=v4.0, GPL750 (XL7) >=v13.0, and GPL750 (XL7 Prime) >=v18.4. The vulnerability has a CVSS v3 base score of 8.6, indicating high severity. ([gasodorizer.com](https://www.gasodorizer.com/odorization/gpl-750-odorant-injection/?utm_source=openai)) The exploitation of this vulnerability could result in significant safety hazards due to improper odorization of natural gas, which is essential for leak detection. Organizations using these devices are urged to update to the latest software versions and implement recommended mitigations to prevent potential exploitation. ([gasodorizer.com](https://www.gasodorizer.com/odorization/gpl-750-odorant-injection/?utm_source=openai))
5 months ago
Kill Chain
Iran-Linked Hackers Target U.S. Critical Infrastructure in 2026
In early April 2026, Iran-affiliated cyber actors targeted internet-facing operational technology (OT) devices across U.S. critical infrastructure sectors, including programmable logic controllers (PLCs) manufactured by Rockwell Automation. These attacks led to diminished PLC functionality, manipulation of display data, and, in some cases, operational disruption and financial loss. The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI and NSA, issued warnings about these threats, emphasizing the need for immediate action to secure vulnerable OT assets. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure. The exploitation of internet-exposed PLCs highlights the urgent need for organizations to implement robust cybersecurity measures, including network segmentation, regular software updates, and the use of strong, unique passwords to protect against such sophisticated attacks.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports