The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
CISA Discloses 2025 ICS Vulnerabilities Impacting Critical Infrastructure
In October 2025, the Cybersecurity and Infrastructure Security Agency (CISA) disclosed 10 advisories detailing significant vulnerabilities found in a range of Industrial Control Systems (ICS) from leading manufacturers including Rockwell Automation, Siemens, Schneider Electric, and others. These advisories highlighted security flaws impacting critical operational technology components—such as PLCs, network devices, and cloud-enabled devices—potentially exposing vital infrastructure to remote code execution, unauthorized access, and disruption risks. Attackers leveraging these weaknesses could impact sectors like energy, manufacturing, and healthcare, posing threats to operational continuity and safety. This incident underscores the escalating threat landscape for operational technology and ICS environments as attackers increasingly target critical infrastructure using both opportunistic exploits and sophisticated attack vectors. The wave of advisories reflects mounting urgency for organizations to prioritize OT security, driven by evolving regulatory requirements and the proliferation of targeted attacks on essential industrial sectors.
8 months ago
Kill Chain
CISA Unveils 2025 ICS Vulnerabilities: Critical Risks to Energy & Healthcare
In October 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released eight advisories highlighting multiple critical vulnerabilities in a range of Industrial Control Systems (ICS) products, including solutions from AutomationDirect, ASKI Energy, Veeder-Root, Delta Electronics, NIHON KOHDEN, Schneider Electric, and Hitachi Energy. These vulnerabilities could allow threat actors, including both cybercriminals and nation-state adversaries, to execute remote code, escalate privileges, disrupt control functionality, or access sensitive operational data. Although no confirmed exploits were publicly detailed at the time of disclosure, the affected systems are widely deployed in energy, healthcare, and manufacturing, raising concerns about both operational integrity and national infrastructure risk. The incident underscores an urgent trend of continuous vulnerability discovery within ICS and operational technology environments as attackers increasingly target these sectors. This rising cadence of disclosures highlights both the complexity of securing interconnected systems and the need for ongoing vigilance and layered defense measures in critical infrastructure.
8 months ago
Kill Chain
Delta Electronics ASDA-Soft 2025 Buffer Overflow: Securing Industrial Control Software
In October 2025, Delta Electronics disclosed critical buffer overflow vulnerabilities (CVE-2025-62579, CVE-2025-62580) affecting their ASDA-Soft automation software, widely used in the critical manufacturing sector. Identified by security researcher Guillaume Orlando via Trend Micro's Zero Day Initiative, the flaws allow attackers to execute code or corrupt memory by convincing users to open malicious project files, potentially leading to loss of control, data compromise, or disruption of industrial processes. Delta responded with a patched software release (v7.1.1.0+) and advisories to enhance network segmentation, firewall defenses, and conduct impact assessments. This incident highlights the ongoing exposure of operational technology (OT) in industrial environments to traditional software exploitation techniques. Regulatory scrutiny and the expansion of threat actor targeting of critical infrastructure elevate the urgency for timely patching, software supply chain validation, and segmented, zero-trust OT/IT network architectures.
8 months ago
Kill Chain
ASKI Energy ALS-mini IP Controllers: 2025 ICS Vulnerability Exposes Critical Infrastructure
In October 2025, a critical authentication vulnerability (CVE-2025-9574) was disclosed in ASKI Energy ALS-mini-S8 and ALS-mini-S4 IP controllers. Devices manufactured between serial numbers 2000 and 5166 were found to lack authentication on their embedded web servers, enabling attackers to remotely read and modify configuration parameters without restriction. Discovered by security researcher Souvik Kandar and reported to CISA, this flaw impacts devices predominantly used across the European energy and critical manufacturing sectors. With a CVSS v4 score of 9.9, exploitation could have allowed adversaries to take full administrative control of exposed devices. Though exploitation reports are absent as of publication, the lack of vendor support due to product end-of-life heightens risk; similar legacy device exposures have increasingly fueled supply chain and operational technology (OT) attacks. The incident underscores the importance of aggressive network segmentation, timely asset retirement, and compensating controls in managing outdated ICS infrastructure.
8 months ago
Kill Chain
Critical AutomationDirect PLC Vulnerabilities Expose Manufacturing to Cyber Risk in 2025
In October 2025, AutomationDirect disclosed multiple critical vulnerabilities affecting its Productivity Suite and a range of Productivity 1000, 2000, and 3000 PLC models, widely deployed in the manufacturing sector. Discovered by Nozomi Networks, the flaws—such as remote code execution, weak password recovery, and unrestricted file system access—could allow unauthenticated attackers to gain full control of affected devices, compromise sensitive project files, and disrupt industrial processes. The vulnerabilities could be exploited remotely with low attack complexity and no user interaction. This incident highlights rising risks posed by legacy and poorly segmented OT networks, as threat actors increasingly target industrial control systems. The sharp jump in the number and severity of disclosed PLC software vulnerabilities underscores the urgent need for enhanced segmentation, access controls, and monitoring in critical infrastructure environments.
8 months ago
Kill Chain
CISA Raises Alarm on Schneider Electric & Vertikal ICS Vulnerabilities (2025)
In October 2025, CISA released urgent advisories for three significant industrial control system (ICS) vulnerabilities affecting Schneider Electric EcoStruxure, Vertikal Systems Hospital Manager Backend Services, and Schneider Electric Modicon. The vulnerabilities, discovered through active monitoring and intelligence efforts, could allow unauthorized access, system manipulation, or disruption if exploited by threat actors. These issues expose critical infrastructure, including healthcare and industrial automation environments, to increased risk of cyberattacks that could impact operations, safety, and patient care. CISA highlighted immediate mitigations and urged organizations to review and apply them to safeguard their assets. The frequency of high-severity ICS vulnerabilities underscores an ongoing trend of targeting operational technology environments, in both healthcare and industrial sectors. These risks are magnified by legacy platforms, the rise of ransomware, and increasingly sophisticated attackers. Regulatory scrutiny and mandates for rapid patching, segmentation, and real-time detection are on the rise as a result.
8 months ago
Kill Chain
Hitachi Energy TropOS ICS Flaws Threaten Critical Infrastructure Security (2025)
In October 2025, Hitachi Energy disclosed multiple critical vulnerabilities in its TropOS 4th Generation firmware (versions 8.9.6.0 and prior), widely used in critical manufacturing and energy sectors. Three CVEs—CVE-2025-1036, CVE-2025-1037, and CVE-2025-1038—were identified, including OS command injection and improper privilege management flaws in the web-based configuration utility. Exploiting these, authenticated attackers could escalate privileges and obtain root SSH access to affected devices, substantially compromising network security and potentially disrupting critical infrastructure operations. The flaws were reported by Idaho National Laboratory’s CyTRICS program and carry CVSS v4 scores between 7.5 and 8.7. This incident highlights ongoing risks posed by authentication and privilege flaws in industrial control systems (ICS), especially as critical infrastructure devices increasingly attract remote exploitation attempts. It underscores the urgent need for regular firmware updates, network segmentation, and robust access controls amid tightening regulations and persistent adversarial interest in ICS environments.
8 months ago
Kill Chain
CISA Alert: Active Exploits Target Dassault DELMIA Apriso and XWiki in 2025
In October 2025, cybersecurity authorities including CISA confirmed active exploitation of critical vulnerabilities in Dassault Systèmes DELMIA Apriso and XWiki platforms. Threat actors leveraged flaws such as CVE-2025-6204—an 8.0 CVSS code injection bug—to gain unauthorized access and potential code execution on affected systems. The attackers exploited unpatched systems to facilitate lateral movement, data exfiltration, and possible disruption of manufacturing and enterprise workflows. Affected organizations faced immediate operational risk and the prospect of sensitive information compromise. This incident highlights a growing trend in rapid exploitation of recently disclosed enterprise software vulnerabilities. With increased attacker focus on supply chain and collaborative platforms, organizations must respond swiftly to new advisories and prioritize vulnerability management programs to reduce exposure to high-severity threats.
8 months ago
Kill Chain
Oracle EBS Zero-Day Attack Triggers Global Supply Chain Crisis in 2025
In early 2025, multiple organizations experienced cyberattacks stemming from the exploitation of a critical zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite (EBS). Threat actors leveraged this flaw to gain unauthorized access, deploy covert tools, and move laterally within victim environments. Notably, high-profile companies such as Schneider Electric may have been impacted, highlighting the sophistication and stealthiness of the attackers, who exploited encrypted and east-west traffic blind spots. The compromise of sensitive business data and disruption of enterprise resource planning systems underscore the far-reaching operational and financial consequences of this campaign. This incident sheds light on the escalating trend of supply chain attacks targeting widely used enterprise software through previously unknown vulnerabilities. The breadth of the campaign and the use of zero-day exploits signal a need for continuous vigilance, rapid patching, and advanced detection controls to defend critical systems against emerging threats.
8 months ago
Kill Chain
Active Exploitation of Dassault DELMIA Apriso Vulnerabilities Impacts Manufacturing Sector
In June 2024, CISA issued an alert highlighting active exploitation of two vulnerabilities (CVE-2024-22120 and CVE-2024-22121) within Dassault Systèmes’ DELMIA Apriso platform, a widely used manufacturing operations management solution. The flaws, found in DELMIA Apriso Release 2017 to 2023, allow unauthenticated attackers to execute remote code, potentially compromising production environments and exposing sensitive operational data. Attackers are leveraging these vulnerabilities to target the manufacturing sector for automated ransomware deployment and data exfiltration, resulting in operational disruption and risk to production integrity. This incident underscores the trend of threat actors focusing on supply chain and OT/IT hybrid platforms, exploiting unpatched flaws for initial access. The urgent CISA advisory signals accelerating regulatory scrutiny and highlights the increased risks posed by software supply chain weaknesses in critical infrastructure sectors.
8 months ago
Kill Chain
North Korea’s Lazarus Group Breaches Drone Developers in 2023 Cyber-Espionage Campaign
In March 2023, the Lazarus Group—an advanced persistent threat attributed to North Korea—successfully targeted three European companies in the defense sector involved in drone development. Leveraging Operation DreamJob, the attackers used social engineering tactics, including fraudulent job offers and a trojanized PDF reader, to gain initial access via phishing emails. The deployment of the ScoringMathTea remote access trojan enabled complete control over compromised systems, potentially allowing sensitive data exfiltration related to unmanned aerial vehicle (UAV) technology and manufacturing know-how. ESET researchers linked the attack to ongoing North Korean efforts to bolster domestic drone capabilities and noted the victims' support of military deployments in Ukraine. The incident exemplifies the persistent and adaptive nature of sophisticated state-linked cyber-espionage campaigns targeting high-value defense technologies. As strategic competition and armed conflicts persist, such tactics have become more prevalent against organizations with intellectual property critical to national security.
8 months ago
Kill Chain
Ransomware Attack on Asahi Disrupts Brewery Operations and Beer Supply in 2024
In early June 2024, the Japanese beverage giant Asahi Group was hit by a ransomware attack that significantly disrupted its domestic brewery operations. Threat actors targeted the company's IT systems, crippling order processing and distribution networks for several days, which led to product shortages and impacted supply chain partners and customers. Asahi confirmed that while immediate containment steps were taken and an investigation was launched, operational downtime and order backlogs persisted as recovery efforts continued, demonstrating the real-world impact of cyberattacks on manufacturing and logistics. This incident highlights the rising trend of ransomware gangs targeting critical sectors like manufacturing, exploiting supply chain dependencies to maximize business disruption and force rapid ransom demands. With attackers increasingly prioritizing operational technology and just-in-time industries, organizations must revisit segmentation, east-west controls, and rapid incident response capabilities to keep pace.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports