The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
Critical Password Hash Vulnerability Exposes Rockwell Automation Fleet Management Systems
Rockwell Automation's OTTO Fleet Manager versions 2.36.2 and earlier contain a critical vulnerability (CVE-2026-75112) involving insufficient computational effort in bcrypt password hashing implementation. This weakness reduces the computational cost for attackers to perform offline brute-force attacks against stored password hashes if they gain access to unencrypted system backups. The vulnerability affects industrial fleet management systems used worldwide in critical manufacturing and transportation sectors, with Rockwell Automation releasing version 2.36.3 to address the issue. This incident highlights the growing threat to industrial control systems and the critical importance of proper cryptographic implementations in operational technology environments, particularly as threat actors increasingly target industrial infrastructure with sophisticated attack techniques.
4 weeks ago
Kill Chain
Critical Security Flaws Expose Unitree Humanoid Robots to Remote Takeover
Security researcher Olivier Laflamme disclosed two critical root remote code execution vulnerabilities affecting Unitree G1 EDU humanoid robots in August 2026. CVE-2026-76639 exploits a path traversal flaw in the chat_go component to reach bashrunner, while CVE-2026-76640 enables Bluetooth Low Energy attacks that can compromise the robot's Locomotion PC without pairing. The vulnerabilities allowed attackers to gain root access through network-adjacent attacks or proximity-based Bluetooth exploitation, with Unitree partially addressing cloud authorization issues in July 2026 but leaving firmware patches unconfirmed. This incident highlights the growing security risks in autonomous robotics and IoT devices as they become more prevalent in industrial and consumer environments. The combination of wireless attack vectors and critical system access demonstrates the urgent need for robust security frameworks in next-generation robotic platforms.
4 weeks ago
Kill Chain
Industrial Automation Under Siege: Q2 2026 Threat Landscape Analysis
In Q2 2026, Kaspersky's industrial threat landscape report revealed a significant shift in cybersecurity threats targeting industrial control systems (ICS), with malicious objects blocked on 19.15% of ICS computers—the lowest level since 2022. The report identified 10,904 different malware families affecting industrial automation systems, with malicious scripts and phishing pages leading threat categories at 5.42% globally. Notable regional variations emerged, with Africa showing the highest attack rates at 27.9% while Northern Europe recorded the lowest at 8.1%. The biometrics sector faced the most severe threats at 26.44%, experiencing increases across multiple threat vectors including ransomware, spyware, and malicious documents. This trend reflects the evolving sophistication of threat actors targeting critical infrastructure, coinciding with increased adoption of cloud-native industrial systems and the expansion of attack surfaces through IoT integration. The data highlights growing concerns around industrial cybersecurity as nation-state actors and cybercriminal groups increasingly focus on operational technology environments.
4 weeks ago
Kill Chain
CVE-2025-3511 Exposes Critical Flaws in Industrial Network Security
In May 2025, CISA disclosed CVE-2025-3511, a critical denial-of-service vulnerability affecting over 45 Mitsubishi Electric factory automation (FA) products including CC-Link IE TSN modules, MELSEC iQ-R/iQ-F series controllers, and Ethernet interface modules. The vulnerability stems from improper validation of UDP packet quantities, allowing remote attackers to send specially crafted UDP packets that cause system crashes, communication delays, or timeout errors requiring manual system resets for recovery. This vulnerability highlights the growing threat surface in industrial control systems as manufacturers increasingly adopt networked automation technologies. With a CVSS score of 7.5, the flaw demonstrates how input validation failures in industrial protocols can create significant operational disruptions in critical manufacturing environments.
4 weeks ago
Kill Chain
Critical Vulnerabilities in Ebyte Industrial IoT Gateways Expose Manufacturing and Energy Infrastructure
The Ebyte NE2-D11 industrial IoT gateway contains 12 critical and high-severity vulnerabilities (ICSA-26-237-06) that enable complete device compromise through multiple attack vectors. These flaws include missing authentication for critical functions, cleartext transmission of sensitive data, client-side authentication bypass, CSRF attacks, and insufficient credential protection. The vulnerabilities affect firmware version FW-9167-0-11 deployed worldwide in critical manufacturing and energy sectors, allowing remote attackers to gain administrative access, intercept communications, modify configurations, and disrupt operations without authentication. This advisory highlights the persistent security challenges in industrial IoT devices as critical infrastructure increasingly relies on connected systems. With Ebyte's limited response to coordination efforts and no confirmed patch timeline, organizations face immediate risks from devices that lack basic security controls essential for industrial environments.
1 month ago
Kill Chain
Critical Siemens SIMATIC IoT2050 Vulnerability Exposes Industrial Systems to Remote Takeover
In August 2026, CISA disclosed a critical vulnerability (CVE-2026-58115) in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed. The vulnerability stems from missing authentication on the Node-RED HTTP interface, allowing unauthenticated remote attackers to create malicious flows and execute arbitrary code with maximum privileges. With a CVSS score of 10.0, this vulnerability affects industrial control systems deployed globally across chemical, manufacturing, energy, and transportation sectors. Siemens has released version 4.3.4.1 to address the issue and strongly recommends immediate updates. This disclosure highlights the growing security risks in Industrial IoT environments as operational technology increasingly integrates with network-accessible programming interfaces. The vulnerability represents a broader trend of critical authentication bypasses in industrial control systems that could enable devastating attacks on critical infrastructure.
1 month ago
Kill Chain
AI-Powered Cyber Attacks Target Critical Infrastructure PLCs
In August 2026, U.S. government agencies warned of active threat actors using AI to generate exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors including water, energy, and manufacturing. Attackers leverage legitimate scanning services like Censys and ZoomEye to identify vulnerable PLCs, then deploy AI-generated scripts masquerading as monitoring tools to find exploits. The threat actors are systematically testing exploitation techniques against specific PLC models and using read access to understand target environments in preparation for future write operations that could cause operational disruption, safety incidents, equipment damage, and compliance violations. This incident marks a significant escalation in AI-enabled cyber threats against operational technology, demonstrating how artificial intelligence is lowering the barrier for sophisticated industrial control system attacks and compressing the timeline from vulnerability discovery to weaponization.
1 month ago
Kill Chain
Critical TSN Protocol Flaws Expose Industrial Control Systems to Manipulation
In August 2026, cybersecurity researchers from Nozomi Networks disclosed critical vulnerabilities in Time-Sensitive Networking (TSN) protocols, specifically targeting Mitsubishi Electric's CC-Link IE TSN implementation. The research demonstrated how attackers could exploit Layer 2 security weaknesses and TSN switch management interface flaws to inject malicious traffic into industrial control systems. Successful exploitation allows complete manipulation of operational technology processes, including starting and stopping robotic arms, tampering with synchronization clocks, and disrupting safety-critical communications in manufacturing environments. This research highlights the growing security challenges as industrial automation increasingly adopts TSN protocols for deterministic communication. With nation-state actors targeting critical infrastructure and the convergence of IT and OT networks accelerating, these vulnerabilities expose fundamental weaknesses in emerging industrial protocols that prioritize availability over security.
1 month ago
Kill Chain
Critical Exploits Target MLflow and FUXA Vulnerabilities in August 2026
In August 2026, two critical vulnerabilities were actively exploited: CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA. The MLflow vulnerability allowed unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks, enabling access to internal cloud metadata endpoints and extraction of sensitive data. The FUXA vulnerability permitted unauthenticated remote attackers to write arbitrary files to the server filesystem, potentially leading to remote code execution. Both vulnerabilities were promptly patched in subsequent software releases. The exploitation of these vulnerabilities underscores the persistent targeting of open-source platforms by threat actors. Organizations are urged to prioritize timely patching, conduct thorough audits for signs of compromise, and implement robust security measures to protect against similar threats.
1 month ago
Kill Chain
Critical Vulnerabilities in Siemens RUGGEDCOM APE1808 Devices with Fortinet FortiOS
In August 2026, Siemens disclosed multiple vulnerabilities in its RUGGEDCOM APE1808 devices, specifically those integrated with Fortinet's FortiOS. The identified vulnerabilities include CVE-2026-23573, an improper neutralization of input during web page generation (cross-site scripting), and CVE-2026-59839, an improper limitation of a pathname to a restricted directory (path traversal). These flaws could allow authenticated remote users to execute arbitrary code or commands and enable privileged authenticated attackers with physical access to delete the file system via crafted CLI commands. Siemens has released updates to address these issues and recommends users update to the latest versions to mitigate potential risks. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-975644.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and vigilant monitoring of industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize the implementation of robust security measures and maintain awareness of emerging vulnerabilities to safeguard operational integrity.
1 month ago
Kill Chain
Critical Vulnerabilities in Hitachi Energy APM Edge: CVE-2026-43284 and CVE-2026-43500
In July 2026, Hitachi Energy disclosed two critical vulnerabilities in its APM Edge product, identified as CVE-2026-43284 and CVE-2026-43500. These flaws, present in versions up to and including 6.10, could allow local unprivileged users to escalate privileges to root by exploiting weaknesses in the Linux kernel's IPsec ESP subsystem and RxRPC protocol implementation. Successful exploitation could compromise the confidentiality, integrity, and availability of the affected systems. The disclosure underscores the persistent risks associated with kernel-level vulnerabilities in critical infrastructure components. Organizations relying on Hitachi Energy's APM Edge should prioritize applying the recommended mitigations, such as disabling the esp4, esp6, and rxrpc modules, to safeguard their systems against potential exploitation.
1 month ago
Kill Chain
Critical Vulnerability in Haiwell IoT Cloud HMI Gateway: CVE-2026-19188
In August 2026, a critical OS command injection vulnerability (CVE-2026-19188) was identified in Haiwell's IoT Cloud HMI Gateway version 3.40.1.12. This flaw resides in the Net Check feature accessible via the /setting endpoint, where the cmdPing Socket.io event fails to properly sanitize user input, allowing attackers to execute arbitrary OS commands with root privileges. Exploitation of this vulnerability could lead to full system compromise, data exfiltration, and disruption of industrial operations. ([secportal.io](https://secportal.io/vulnerabilities/command-injection?utm_source=openai)) This incident underscores the persistent threat of command injection vulnerabilities in industrial control systems (ICS). As ICS devices become increasingly interconnected, the attack surface expands, necessitating rigorous input validation and secure coding practices to prevent such critical flaws. ([immuniweb.com](https://www.immuniweb.com/vulnerability/os-command-injection.html?utm_source=openai))
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports