The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
Critical Vulnerabilities in Siemens Solid Edge: Immediate Update Required
In May 2026, Siemens disclosed multiple vulnerabilities in its Solid Edge SE2026 software, specifically affecting versions prior to Update 5. These vulnerabilities, identified as CVE-2026-44411 and CVE-2026-44412, involve uninitialized pointer access and stack-based buffer overflow issues that can be exploited through specially crafted PAR files. Successful exploitation could allow attackers to execute arbitrary code within the context of the current process. Siemens has released Update 5 to address these issues and strongly recommends users to upgrade to this latest version. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-921111.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and vigilance against file-based attack vectors. As attackers increasingly target vulnerabilities in widely used design software, organizations must prioritize patch management and implement robust security measures to mitigate such risks.
1 month ago
Kill Chain
Critical Vulnerabilities in ANDRITZ HIPASE-250 Devices: Immediate Action Required
In August 2026, multiple vulnerabilities were identified in ANDRITZ HIPASE-250 and 250 SCALA devices, including storing passwords in a recoverable format, missing authentication for critical functions, and the use of hard-coded credentials. These flaws could allow attackers to read sensitive data or gain unauthorized access to affected workstations. ANDRITZ has released updates to address these issues and recommends users upgrade to version V8.15.00. The discovery of these vulnerabilities underscores the critical importance of securing industrial control systems, especially in the energy sector. Organizations must prioritize timely updates and robust security measures to protect against potential exploits targeting such weaknesses.
1 month ago
Kill Chain
Critical Vulnerabilities in Siemens LOGO! Soft Comfort Software
In August 2026, Siemens disclosed multiple vulnerabilities in its LOGO! Soft Comfort software, specifically CVE-2026-57262 and CVE-2026-57263. These flaws involve the use of a hard-coded cryptographic key and unsalted password hashes, respectively. Exploitation could allow local attackers to decrypt project files or perform efficient offline attacks against password hashes, leading to unauthorized access or modification of sensitive project configurations. Siemens has released version 9 to address these issues and recommends users update promptly. This incident underscores the critical importance of robust cryptographic practices in industrial control systems. The vulnerabilities highlight the need for organizations to regularly review and update their security measures to protect against evolving threats, especially in software managing sensitive operational data.
1 month ago
Kill Chain
Critical Vulnerability in Siemens Parasolid: CVE-2026-64629
In August 2026, Siemens disclosed a critical out-of-bounds read vulnerability (CVE-2026-64629) in its Parasolid software, specifically affecting versions V38.0 prior to V38.0.235 and V38.1 prior to V38.1.230. This flaw could be exploited when the application processes specially crafted X_T files, potentially allowing attackers to crash the application or execute arbitrary code within the context of the current process. Siemens promptly released updates to address this vulnerability and strongly recommends users upgrade to the latest versions to mitigate potential risks. This incident underscores the persistent threat posed by file parsing vulnerabilities in widely used industrial software. Organizations relying on Siemens Parasolid should prioritize applying the provided patches to safeguard their systems against potential exploitation. Additionally, this serves as a reminder of the importance of maintaining up-to-date software and implementing robust security measures to protect against emerging threats.
1 month ago
Kill Chain
Cyberattack on Polish Power Plant via Private Cellular Network - 2025
In December 2025, a coordinated cyberattack targeted Poland's energy infrastructure, including over 30 renewable energy farms and a major combined heat and power (CHP) plant supplying heat to nearly 500,000 residents. Attackers exploited vulnerabilities in private cellular networks, gaining unauthorized access to industrial control systems (ICS) and deploying wiper malware aimed at sabotaging operations. Despite the sophisticated nature of the attack, prompt response measures prevented significant service disruptions. This incident underscores the escalating threat landscape facing critical infrastructure, highlighting the need for robust cybersecurity measures in industrial environments. The attack's timing, during severe winter conditions, emphasizes the potential human and economic impact of such cyber threats.
1 month ago
Kill Chain
Cyberattack on Polish Energy Plant via Private APN Highlights Infrastructure Vulnerabilities
In December 2025, a coordinated cyberattack targeted Poland's energy infrastructure, including a small combined heat and power (CHP) plant supplying heat to approximately 50,000 residents. The attackers exploited a misconfigured private Access Point Name (APN) to access the plant's operational technology (OT) network. By compromising a WAGO PFC200 programmable logic controller (PLC) with default credentials, they gained control over the plant's systems, leading to the shutdown of the steam turbine and water treatment system. The plant's staff managed to restore operations swiftly, preventing significant disruption to the population. This incident underscores the evolving tactics of nation-state actors in targeting critical infrastructure. The use of private APNs as attack vectors highlights the necessity for robust network segmentation, stringent access controls, and regular security assessments to mitigate such threats.
1 month ago
Kill Chain
Cyberattacks Reveal Critical Vulnerabilities in U.S. Water Systems
In late July 2026, a series of cyberattacks targeted water and wastewater systems across at least 12 U.S. states, including Michigan, South Dakota, and Georgia. Attackers exploited internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), specifically the MicroLogix 1100 and 1400 models, to remotely alter configurations, leading to operational disruptions such as pressure loss and flooding. Despite prior federal warnings, over 4,000 such controllers remained accessible online, with 2,844 located in the United States. This incident underscores the persistent vulnerabilities in critical infrastructure due to inadequate cybersecurity measures. The exploitation of known vulnerabilities in widely used industrial equipment highlights the urgent need for enhanced security protocols and the removal of operational technology from direct internet exposure to prevent future attacks.
1 month ago
Kill Chain
Over 4,400 Rockwell PLCs Exposed Online: A Wake-Up Call for Critical Infrastructure Security
In August 2026, Forescout identified 4,407 internet-exposed Rockwell Automation programmable logic controllers (PLCs) worldwide, with 2,844 located in the United States. Notably, 22 of these exposed PLCs were found in cities recently targeted by cyberattacks on U.S. water utilities, with 19 utilizing the same mobile carrier network. Attackers exploited these vulnerabilities by altering IP addresses and setting passwords on accessible controllers, leading to operators losing visibility and control over connected equipment. This incident underscores the critical need for securing industrial control systems against unauthorized internet exposure. The prevalence of internet-exposed PLCs highlights a significant security gap in critical infrastructure, particularly within the water sector. The ease with which attackers can manipulate these systems without exploiting specific vulnerabilities emphasizes the urgency for organizations to implement robust network segmentation, remove unnecessary internet exposure, and enforce strong authentication measures to protect against potential disruptions and threats to public safety.
1 month ago
Kill Chain
CISA Issues Urgent Alert on Cyberattacks Targeting U.S. Water Utilities
In late July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert regarding a significant increase in cyberattacks targeting internet-exposed programmable logic controllers (PLCs) within the water and wastewater systems sector. These attacks, which began on July 26, 2026, involved hackers altering PLC configurations, changing passwords to lock operators out, and modifying IP addresses to disconnect devices from the internet, leading to operational disruptions. Over 30 community water systems in Minnesota were affected, with some utilities forced to switch to manual operations due to equipment malfunctions. This incident underscores the escalating cyber threats facing critical infrastructure, particularly in the water sector. The attackers' focus on internet-exposed PLCs highlights the urgent need for enhanced cybersecurity measures to protect operational technology from unauthorized access and potential sabotage.
1 month ago
Kill Chain
Critical Vulnerabilities Discovered in Open62541
In July 2026, multiple vulnerabilities were identified in o6 Automation GmbH's Open62541, an open-source OPC UA stack widely used in industrial automation. These vulnerabilities, including CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, and CVE-2026-63559, affect versions from 1.3.0 to 1.5.4 and the master branch. Exploitation could allow attackers to disclose sensitive information, cause denial-of-service conditions, or execute arbitrary code. ([aviatrix.ai](https://aviatrix.ai/threat-research-center/o6-automation-gmbh-open62541-vulnerability-2026/?utm_source=openai)) The discovery of these vulnerabilities underscores the critical importance of rigorous security practices in industrial automation software. Organizations utilizing Open62541 should promptly upgrade to the latest version to mitigate these risks. Additionally, implementing network segmentation and minimizing exposure of control systems to external networks are essential steps to enhance security posture.
1 month ago
Kill Chain
Critical Vulnerability in Rockwell Automation's ControlLogix and CompactLogix Controllers
In July 2026, Rockwell Automation disclosed a security vulnerability (CVE-2026-9636) affecting its CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR communication modules. The flaw involves improper handling of Certificate Revocation Lists (CRLs), allowing attackers to use revoked certificates to establish unauthorized connections, potentially bypassing CIP Security protections. This vulnerability impacts firmware versions V36 to V37 for the affected products. ([rockwellautomation.com](https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1788.html?utm_source=openai)) The incident underscores the critical importance of robust certificate validation processes in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize timely firmware updates and adhere to security best practices to mitigate potential risks.
1 month ago
Kill Chain
CISA Issues Alert on Iranian Cyber Actors Targeting U.S. Critical Infrastructure PLCs
In July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert regarding Iranian-affiliated cyber actors targeting internet-connected programmable logic controllers (PLCs) within U.S. critical infrastructure sectors, including water and wastewater systems. These actors exploited vulnerabilities in PLCs from manufacturers such as Rockwell Automation, Schneider Electric, and Siemens, leading to operational disruptions and financial losses. The attackers manipulated data on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) displays, causing outages and misleading operators about system statuses. This incident underscores the escalating threat landscape where state-sponsored actors are increasingly focusing on industrial control systems. The expansion of targeted PLC brands highlights the need for organizations to reassess and fortify their operational technology (OT) security measures to prevent potential disruptions to essential services.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports