The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
Malicious NuGet Packages Drop Sabotage Time Bombs in 2024 Supply Chain Attack
In early June 2024, security researchers uncovered a targeted supply-chain attack involving several malicious NuGet packages. These packages, posing as legitimate software dependencies, contained 'time bomb' sabotage payloads programmed to activate years in the future—specifically in 2027 and 2028. The malicious code was designed to disrupt database operations and potentially target Siemens S7 industrial control systems, representing a novel form of delayed-detonation supply chain attack. The technique leverages trust in package ecosystems, making detection difficult and threatening both IT and operational technology environments with considerable disruption. This incident highlights an emerging trend where attackers plant long-term, stealthy threats within software supply chains to evade short-term detection and maximize impact. With the increasing adoption of open-source components and growing regulatory scrutiny, organizations must urgently reassess their software sourcing and supply-chain risk controls.
8 months ago
Kill Chain
Time-Bomb Malware Hidden in NuGet Packages Signals Alarming Supply Chain Threat
In 2023 and 2024, a set of nine malicious NuGet packages, attributed to the user 'shanhai666', were found to infect software supply chains by deploying time-delayed logic bombs. These packages, available through the official NuGet repository, hid code designed to execute malicious activities—such as sabotaging database operations and corrupting industrial control systems—on predefined future dates starting in August 2027. The sophisticated campaign leveraged delayed payload triggers, allowing attackers to infiltrate developer environments undetected for years before activation, thus maximizing potential operational and business disruption. This incident highlights the ongoing risks facing software supply chains, where attackers increasingly employ delayed and concealed attack mechanisms to evade early detection. Businesses across all sectors relying on third-party code repositories must reinforce supply chain security practices and continuously monitor for latent threats that could surface well after initial compromise.
8 months ago
Kill Chain
Advantech DeviceOn/iEdge 2025: Multiple Path Traversal and XSS Vulnerabilities Threaten IoT Security
In November 2025, security researchers disclosed multiple critical vulnerabilities in Advantech’s DeviceOn/iEdge IoT management platform, affecting version 2.0.2 and earlier. Among the vulnerabilities were improper input handling flaws including cross-site scripting (CVE-2025-64302) and several variants of path traversal (CVE-2025-62630, CVE-2025-59171, CVE-2025-58423), which could allow remote attackers to gain unauthorized access, execute arbitrary code, trigger denial-of-service conditions, or read sensitive files. No public exploitation has been reported, but the potential risks span information leakage and remote code execution, with system-level impact possible from authenticated and unauthenticated attackers. This incident is particularly relevant as IoT management and industrial control environments remain popular targets for exploitation of legacy systems, which often lack timely security updates. With operational continuity and data integrity at risk, organizations face mounting regulatory and business pressure to retire end-of-life products and implement robust remediation strategies.
8 months ago
Kill Chain
ABB FLXeon 2025 ICS Vulnerabilities: Protecting Critical Infrastructure from Remote Threats
In November 2025, ABB disclosed critical vulnerabilities affecting their FLXeon industrial control system (ICS) controllers, including the FBXi, FBVi, FBTi, and CBXi product lines. Security researcher Gjoko Krstikj of Zero Science Lab identified flaws such as the use of hard-coded credentials (CVE-2024-48842), improper input validation (CVE-2024-48851, CVE-2025-10207), and weak password hashing practices (CVE-2025-10205) that could allow remote attackers to gain control, execute arbitrary code, or cause system crashes. While exploitation requires some privileges and network access, the flaws impact ICS deployments globally, exposing critical infrastructure sectors to risk until patches are applied. This incident highlights the continued trend of vulnerabilities in operational technology and industrial systems, reinforcing fears that ICS environments remain attractive targets for cyber threat actors. As regulatory and industry pressure mounts for robust ICS security and segmentation, organizations must accelerate adoption of defense-in-depth strategies to protect essential infrastructure.
8 months ago
Kill Chain
Delta Electronics 2025 ICS Vulnerability: Buffer Overflow in CNCSoft-G2 Threatens Industrial Operations
In November 2025, Delta Electronics publicly disclosed a critical vulnerability in its CNCSoft-G2 software (version 2.1.0.27 and prior), used widely across critical manufacturing and energy sectors. The stack-based buffer overflow vulnerability (CVE-2025-58317) could be exploited by attackers using a malicious file to achieve arbitrary code execution with the privileges of the target process. Although no public exploitation has been reported yet and remote exploitation is not possible, the flaw poses significant risks to organizations controlling industrial networks, potentially undermining operational continuity and safety systems. Mitigations and patches have been released, with recommendations for further defense-in-depth and updated secure remote access. This case highlights the ongoing challenges in securing industrial control software as threat actors frequently target poorly validated file handling and legacy code. The need for robust patch management and segmentation is paramount—especially as ransomware groups and nation-state actors increasingly pursue industrial targets for disruption or extortion.
8 months ago
Kill Chain
Fuji Electric HMI 2025: Buffer Overflow Exposes Critical Manufacturing Risks
In November 2025, vulnerabilities were disclosed in the Fuji Electric Monitouch V-SFT-6 HMI software (version 6.2.7.0), exposing critical manufacturing environments worldwide to potential compromise. Security researchers discovered both heap-based and stack-based buffer overflow flaws, which could allow a malicious user, via specially crafted project files, to crash targeted devices or execute arbitrary code. While there has been no evidence of active exploitation or remote attacks reported, these vulnerabilities highlight the exposed attack surface for industrial control system (ICS) operators. Following responsible disclosure, Fuji Electric addressed the issues in the October update, urging all users to upgrade immediately. This incident underscores the growing risk posed by supply chain and software vulnerabilities in critical infrastructure. With attackers increasingly targeting ICS and operational technology (OT) environments, prompt patching and layered defense strategies are more important than ever.
8 months ago
Kill Chain
CISA Discloses 2025 ICS Vulnerabilities Affecting Critical Infrastructure
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five Industrial Control Systems (ICS) Advisories highlighting significant vulnerabilities impacting multiple vendors: Fuji Electric, Survision, Delta Electronics, Radiometrics, and IDIS. These advisories detail newly identified security issues, including unencrypted communication, improper authentication, and exploitable flaws exposing critical industrial and manufacturing systems to potential attack vectors. While no active exploitation has been publicly reported yet, the disclosed vulnerabilities could allow remote attackers to gain unauthorized access, disrupt operations, or compromise sensitive operational technology environments if left unaddressed. This incident underscores the ongoing and urgent need for proactive vulnerability management and timely patching within ICS environments. With an uptick in vulnerability disclosures and the rising convergence of IT and operational technology, threat actors continue to target unpatched systems in critical infrastructure, amplifying regulatory and business risk for operators in energy, manufacturing, and transportation sectors.
8 months ago
Kill Chain
Claroty Authentication Bypass Threatens OT Security in 2025
In early 2025, a critical vulnerability tracked as CVE-2025-54603 was discovered in Claroty’s industrial cybersecurity products, exposing operational technology (OT) networks and critical infrastructure to potential attacks and data theft. The flaw allowed threat actors to bypass authentication mechanisms, granting unauthorized access to sensitive network segments. Attackers leveraging this security gap could disrupt essential services, compromise confidential process data, and pose significant operational and safety risks. Claroty responded by issuing urgent patches to contain the exposure and mitigate ongoing threats. This incident highlights the increasing risk of authentication bypass exploits in OT environments, as threat actors target weak points in security architectures to gain privileged access. The event underscores an urgent need for robust, zero trust security frameworks and rapid vulnerability management in critical infrastructure sectors.
8 months ago
Kill Chain
CISA 2025 ICS Advisories Expose Widespread Industrial Control System Risks
In October 2025, CISA released thirteen industrial control systems (ICS) advisories highlighting critical security vulnerabilities across various products from leading vendors such as Rockwell Automation, Siemens, Hitachi Energy, Schneider Electric, and Delta Electronics. The disclosed vulnerabilities affected solutions commonly used in industrial environments, including HMIs, SCADA software, network management systems, and control processors. These weaknesses, if left unaddressed, could be leveraged by malicious actors for unauthorized access, lateral movement, or disruption of industrial processes, posing significant operational and safety risks to organizations dependent on ICS infrastructure. This mass vulnerability disclosure arrives amid an intensifying regulatory focus on the security of ICS and OT environments, paralleling a broader trend of increased adversary attention to unpatched operational technologies. Organizations must prioritize timely patching and hardened network segmentation to mitigate rapidly evolving threats and prevent cascading impacts across critical infrastructure.
8 months ago
Kill Chain
Siemens 2025 ICS Vulnerabilities Expose Critical Manufacturing to Remote Disruption
In October 2025, Siemens disclosed high-severity vulnerabilities in its SIMATIC S7-1200 CPU V1/V2 Devices, a critical component used in manufacturing automation worldwide. Security researchers found that improper input validation and authentication bypass by capture-replay allowed unauthenticated remote attackers to either cause a denial-of-service state or remotely execute recorded engineering commands on exposed controllers, regardless of security passwords. The vulnerabilities, affecting devices shipped globally, could let on-path attackers disrupt operations or halt production lines if exploited. Siemens and CISA issued urgent advisories and released patches to mitigate risks. This incident highlights the ongoing vulnerability of industrial control systems (ICS) to remote exploits and session replay attacks. As critical infrastructure faces increasing threats from both sophisticated threat actors and opportunistic attacks, organizations operating legacy or unpatched automation hardware must rapidly recalibrate their cyber defenses in light of persistent risks and global attack surface expansion.
8 months ago
Kill Chain
Critical DoS Vulnerability in Rockwell Compact GuardLogix 5370 Exposes Manufacturing Operations
In October 2025, Rockwell Automation disclosed a critical remotely exploitable vulnerability (CVE-2025-9124) affecting Compact GuardLogix 5370 industrial controllers, stemming from an uncaught exception flaw. Attackers could trigger a denial-of-service by sending crafted CIP unconnected explicit messages, resulting in a major, non-recoverable device fault. The vulnerability, reported by Rockwell itself, exposes impacted controllers to significant operational disruptions, particularly concerning for organizations within critical manufacturing sectors worldwide. Immediate device upgrades and network segmentation were recommended to mitigate risk. This vulnerability highlights persistent gaps in OT security as attackers increase their focus on industrial control systems. The incident underscores the urgency surrounding real-time vulnerability management and emphasizes the rising threat surface presented by remotely accessible critical infrastructure.
8 months ago
Kill Chain
Critical Vulnerabilities in Rockwell Automation 1783-NATR Threaten Global Industrial Operations
In October 2025, Rockwell Automation disclosed three critical vulnerabilities in its 1783-NATR network address translation devices, primarily affecting industrial environments worldwide. The flaws included missing authentication checks on critical functions, a stored cross-site scripting (XSS) vulnerability, and a cross-site request forgery (CSRF) flaw. Remote attackers could exploit these to compromise administrative accounts, alter device configurations, and disrupt network traffic flow, potentially causing denial-of-service or the exposure of sensitive data vital to manufacturing operations. The vulnerabilities impacted all devices running firmware version 1.006 and earlier, with no public exploitation reported at the time of disclosure. This incident highlights the persistent security risks in operational technology (OT) and industrial control systems, particularly as threat actors increasingly target publicly exposed or poorly segmented infrastructure. The disclosure underscores the need for continuous patch management, robust network segmentation, and diligent monitoring to prevent widespread operational disruptions stemming from remote exploitation of critical vulnerabilities.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports