The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Industrial Automation

Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.

265 threat reports
Page 2 of 23

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Industrial Automation Threat Reports

Showing 13–24 / 265 reports
Critical VPN Vulnerability CVE-2026-75925 Exposes Infrastructure to Remote Code Execution
Impact· HIGH

Critical VPN Vulnerability CVE-2026-75925 Exposes Infrastructure to Remote Code Execution

In August 2026, CISA disclosed CVE-2026-75925, a critical CRLF injection vulnerability in IXON VPN Client versions prior to 1.4.7 with a CVSS score of 9.6. The vulnerability allows remote attackers to execute commands with root or SYSTEM privileges by injecting malicious configuration directives through unvalidated line-ending sequences. The flaw stems from improper neutralization of CRLF sequences in configuration values written to files consumed by privileged subprocesses, combined with lack of authentication for configuration changes. IXON responded by automatically rejecting connections from vulnerable client versions and releasing patches, preventing exploitation on unpatched systems that cannot establish VPN connections. This incident highlights the growing sophistication of infrastructure-targeted attacks and the critical importance of secure coding practices in VPN solutions that organizations rely on for remote access security.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities Expose Rockwell Automation Industrial Control Systems to Remote Attacks
Impact· HIGH

Critical Vulnerabilities Expose Rockwell Automation Industrial Control Systems to Remote Attacks

CISA disclosed two critical vulnerabilities (CVE-2026-19471, CVE-2026-19472) affecting Rockwell Automation's ArmorStart LT motor protection devices version 2.001 and earlier. CVE-2026-19471 involves stored cross-site scripting (XSS) vulnerabilities that allow attackers to inject malicious scripts executed when users access affected web pages. CVE-2026-19472 is a denial-of-service vulnerability triggered by crafted HTTP PUT requests that can disable the embedded web server. Both vulnerabilities require no authentication and can be exploited remotely, potentially compromising industrial control systems used in critical manufacturing worldwide. These vulnerabilities highlight the growing attack surface of industrial IoT devices and the critical need for secure-by-design principles in operational technology environments, especially as industrial systems become increasingly connected to enterprise networks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical OT Vulnerability Exposes Industrial Control Systems to Code Execution Attacks
Impact· HIGH

Critical OT Vulnerability Exposes Industrial Control Systems to Code Execution Attacks

Rockwell Automation's ControlFLASH software versions 15.07 and earlier contain a critical vulnerability (CVE-2026-12663) that grants write permissions to the 'Everyone' group on installation directories. This security flaw allows attackers to execute arbitrary code at the logged-in user's permission level, potentially compromising industrial control systems across critical infrastructure sectors including manufacturing, energy, and water systems. The vulnerability stems from missing authentication for critical functions and affects installations worldwide. Rockwell has released version 15.08 to address this issue and provided manual mitigation steps for systems that cannot immediately upgrade. This incident highlights the growing cybersecurity risks facing operational technology (OT) environments as industrial systems become increasingly connected and targeted by threat actors seeking to disrupt critical infrastructure operations.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Tycon Systems Industrial Monitoring Devices Threaten Infrastructure Security
Impact· HIGH

Critical Vulnerabilities in Tycon Systems Industrial Monitoring Devices Threaten Infrastructure Security

In September 2026, CISA disclosed three critical vulnerabilities (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) affecting Tycon Systems TPDIN-Monitor-WEB3 industrial control system devices version 2.2.9 and prior. These vulnerabilities include hard-coded credentials, cross-site request forgery, and missing authorization controls that could enable attackers to perform man-in-the-middle attacks, extract system credentials, cause factory resets, or retrieve sensitive operational data from critical infrastructure systems deployed worldwide in energy and manufacturing sectors. These vulnerabilities highlight the ongoing security challenges in operational technology environments where legacy authentication models and insufficient access controls create attack vectors that could disrupt critical infrastructure operations and expose sensitive industrial data.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Configuration Flaw Exposed in Inductive Automation Ignition SCADA Platform
Impact· MEDIUM

Critical Configuration Flaw Exposed in Inductive Automation Ignition SCADA Platform

In September 2026, CISA disclosed CVE-2026-77393 affecting Inductive Automation's Ignition SCADA platform versions 8.1.53 and earlier. The vulnerability stems from incorrect default permissions where the Gateway's 'Create Project Role(s)' setting shipped blank, allowing any authenticated user to create projects if they could execute gateway scripts. This configuration flaw exposed industrial control systems to potential unauthorized project creation and manipulation. Inductive Automation addressed the issue in version 8.1.54 by restricting project creation to Designer sessions and eliminating reliance on the problematic setting. This incident highlights the growing security challenges facing industrial control systems as they become increasingly connected and targeted by threat actors. With critical infrastructure under constant threat and new regulations emphasizing OT security, even seemingly minor configuration vulnerabilities can create significant exposure points for manufacturing and energy sector organizations.

3 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
AI Weaponizes PLC Exploits: How Claude Ported Critical Infrastructure Attacks
Impact· CRITICAL

AI Weaponizes PLC Exploits: How Claude Ported Critical Infrastructure Attacks

In September 2026, Forescout's Vedere Labs demonstrated how Anthropic's Claude AI successfully ported a pre-authentication remote code execution exploit targeting CVE-2021-31886 from one WAGO programmable logic controller model to another. The research consumed $535.74 in API costs over 8.5 hours to adapt an existing 750-852 exploit for the 750-831 controller, exploiting a stack-based buffer overflow in the Nucleus FTP server with a CVSS score of 9.8. The AI-assisted exploit development achieved code execution by sending network packets, though a subsequent attempt to create a command-and-control implant permanently bricked the target PLC by writing to flash memory. This research highlights the evolving threat landscape where AI tools are lowering the technical barriers for developing industrial control system exploits, coinciding with recent warnings from NSA, CISA, and FBI about AI-generated scripts targeting Siemens PLCs and ongoing attacks against water utility infrastructure.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Privilege Escalation Flaw Exposes Industrial Control Systems to Complete Compromise
Impact· HIGH

Critical Privilege Escalation Flaw Exposes Industrial Control Systems to Complete Compromise

A critical privilege escalation vulnerability (CVE-2026-16675) was discovered in Rockwell Automation's FactoryTalk Activation Manager V5.02 and below, affecting industrial control systems worldwide. The vulnerability allows authenticated attackers to hijack console windows during installation or repair operations, escalating from standard user privileges to SYSTEM-level access with complete control over affected systems. This poses significant risks to critical manufacturing infrastructure, as attackers can access all files, processes, and system resources once exploited. This vulnerability highlights the ongoing security challenges facing industrial control systems as manufacturing environments become increasingly digitized and interconnected, making them attractive targets for cybercriminals and nation-state actors seeking to disrupt critical infrastructure operations.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Privilege Escalation Vulnerabilities Discovered in Rockwell Automation Industrial Systems
Impact· HIGH

Critical Privilege Escalation Vulnerabilities Discovered in Rockwell Automation Industrial Systems

In September 2026, CISA disclosed two critical privilege escalation vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in Rockwell Automation's Redundancy Module Configuration Tool affecting versions 9.00.00 through 10.00.00. The vulnerabilities stem from incorrect default permissions that allow the tool's executables to search for required DLLs in directories writable by standard users. If exploited, local attackers can place malicious DLLs in these directories, which are then loaded with Administrator/SYSTEM privileges when the tool is run by an administrator. Rockwell Automation has released version 10.01.00 to address these issues, affecting critical manufacturing infrastructure worldwide. This incident highlights the persistent threat of DLL hijacking attacks in industrial control systems, particularly as organizations modernize their operational technology environments. With increasing convergence of IT and OT networks, such privilege escalation vulnerabilities pose significant risks to critical infrastructure security and operational continuity.

3 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Denial of Service Vulnerability Exposes Rockwell Automation Industrial Controllers
Impact· HIGH

Critical Denial of Service Vulnerability Exposes Rockwell Automation Industrial Controllers

Rockwell Automation disclosed CVE-2021-42260, a high-severity denial of service vulnerability affecting ControlLogix, CompactLogix, GuardLogix, and Compact GuardLogix controllers. The vulnerability, with a CVSS score of 7.5, allows attackers to trigger an infinite loop condition through corrupt crafted data, causing major nonrecoverable faults (MNRF) in safety controllers and requiring program downloads for recovery. The flaw impacts multiple firmware versions across the 34.x, 35.x, 36.x, and 37.x series, affecting critical manufacturing infrastructure deployed worldwide. This vulnerability highlights the ongoing risks to operational technology environments where denial of service attacks can cause significant operational disruption. As industrial control systems become increasingly connected and targeted by threat actors, vulnerabilities like CVE-2021-42260 demonstrate the critical need for robust OT security measures and timely patch management in manufacturing environments.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical DOS Vulnerabilities Threaten Rockwell Automation RSLinx Classic Industrial Systems
Impact· CRITICAL

Critical DOS Vulnerabilities Threaten Rockwell Automation RSLinx Classic Industrial Systems

Four critical denial-of-service vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) were discovered in Rockwell Automation's RSLinx Classic versions 4.50 and earlier. These vulnerabilities allow attackers to crash the RSLinx Classic service by sending specially crafted CIP packets, exploiting integer overflow, integer underflow, and buffer overflow conditions. The vulnerabilities affect critical manufacturing infrastructure worldwide and require service restarts to recover, potentially disrupting industrial operations and production systems. These vulnerabilities highlight the growing threat landscape facing industrial control systems as cybercriminals increasingly target critical infrastructure. With the rise of nation-state actors and ransomware groups focusing on OT environments, securing industrial communication protocols like CIP has become paramount for operational resilience.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Vulnerabilities Expose Rockwell Automation Industrial Systems to Remote Attacks
Impact· HIGH

Critical Vulnerabilities Expose Rockwell Automation Industrial Systems to Remote Attacks

In September 2026, CISA disclosed critical vulnerabilities in Rockwell Automation's FactoryTalk Historian Machine Edition affecting Series B 5.202 and Series C 7.101. CVE-2025-12768, with a CVSS score of 8.0, enables remote code execution through an out-of-bounds write condition exploitable by attackers with low-level authentication. CVE-2026-12661 allows denial-of-service attacks via stack-based buffer overflows when crafted requests are sent to the web interface, potentially crashing industrial systems. These vulnerabilities impact critical infrastructure sectors including chemical manufacturing, healthcare, and water systems worldwide. The disclosure emphasizes the growing threat landscape targeting industrial control systems and operational technology environments. Similar buffer overflow vulnerabilities in ICS components have been increasingly exploited by nation-state actors and ransomware groups to disrupt critical infrastructure operations.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Flaws in Ebyte Industrial Gateways Expose Global Infrastructure to Remote Attacks
Impact· CRITICAL

Critical Flaws in Ebyte Industrial Gateways Expose Global Infrastructure to Remote Attacks

In August 2026, CISA disclosed thirteen critical vulnerabilities in the Ebyte NA111-M industrial control system device, a Chinese-manufactured gateway used worldwide in critical infrastructure. The vulnerabilities include missing authentication, cleartext transmission of sensitive data, client-side authentication bypass, and weak cryptographic implementations. With CVSS scores up to 9.8, these flaws allow complete device compromise through remote exploitation, enabling attackers to access sensitive configurations, modify device settings, intercept MQTT credentials, and disrupt industrial operations. This disclosure highlights the persistent challenge of securing legacy industrial control systems that lack fundamental security controls, as nation-state actors and cybercriminals increasingly target critical infrastructure through vulnerable ICS devices for espionage and operational disruption.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports