< ciso
brief />
Tag Banner

All news with #ics security tag

148 articles

Small generators expose critical infrastructure risk

๐Ÿ”’ A recent cyber incident that took a small UK electricity generator offline for days โ€” without causing national outages โ€” highlights a weakness across Western critical infrastructure: thousands of small, internet-exposed industrial control devices lack the security protections of larger utilities. Governments and security firms are investigating attribution and impacts while urging operators to remove PLCs from direct internet access, secure cellular modems, and test manual-operation procedures. The episodes mirror attacks on US water systems and underscore how modest targets can create disproportionate disruption.
read more โ†’

AI-Generated Exploits Target Siemens PLCs, Risking ICS Safety

๐Ÿ›ก๏ธ U.S. agencies warned of an active threat using AI-generated exploit scripts to target Siemens S7 Series PLCs and other industrial controllers, posing risks to Critical Manufacturing, Energy, Water, and related sectors. The campaign leverages internet scanning services to find exposed devices and uses custom Python tools integrating snap7.dll or python-snap7 to mimic legitimate monitoring utilities. Agencies urge patching, network isolation, strong access controls, and enhanced ICS monitoring to mitigate potential disruption, data compromise, and safety incidents.
read more โ†’

Minnesota water cyberattack exposes OT backup gaps

๐Ÿ”’ The July 26โ€“27 coordinated cyber activity against more than 30 Minnesota community water systems targeted operational technology, disrupting remote control and forcing manual operations in some places. Advisories from CISA and vendors document exfiltration of PLC project files and recovery procedures that assume operators possess current offline project backups. The article emphasizes immediate, low-cost countermeasures: verify offline, versioned project archives, reconcile SIM-equipped devices via carrier invoices, restrict integrator remote access, and test time-to-manual recovery.
read more โ†’

CISA warns of attacks on US water and wastewater systems

๐Ÿšจ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert after hackers disrupted over 30 Minnesota community water systems by targeting internet-exposed programmable logic controllers (PLCs). The attacks included password changes that locked operators out, IP alterations that severed internet connectivity, and other actions that impaired operations. CISA urges owners and operators to remove publicly exposed PLCs and OT from the internet, use VPNs or gateway devices for access, change default passwords, and implement IP allow-lists. Security vendor research from Censys found thousands of internet-reachable PLC hosts and highlighted undocumented cellular modems as a common blind spot.
read more โ†’

Coordinated cyberattack disrupts Minnesota water systems

๐Ÿ”’ A coordinated cyberattack targeted more than 30 Minnesota community water systems over July 26โ€“27, prompting temporary operational shutdowns and local emergency responses while officials reported drinking water remained safe. Security researchers link the campaign to a months-long surge in attacks on water infrastructure and note potential ties to exposed PLCs, including Rockwell Automation MicroLogix 1400 controllers. Federal agencies urged utilities to remove internet-exposed operational technology and follow mitigation guidance as investigations continue.
read more โ†’

UK updates National Risk Register with cyber scenarios

๐Ÿ”’ The UK government has expanded its National Risk Register to include several new cyber-related scenarios affecting digital infrastructure, water systems, policing, and a potential large-scale IT outage. The July 14 update also adds a section on interference in democratic processes, covering attacks on election infrastructure and online information operations. Likelihoods are generally assessed as low but impacts range from moderate to catastrophic, prompting plans for a national resilience campaign to boost household preparedness.
read more โ†’

Six U-Boot Vulnerabilities Enable Stealthy Firmware Attacks

๐Ÿ”’ Binarly disclosed six vulnerabilities in the widely used U-Boot bootloader's FIT signature verification that can lead to crashes or arbitrary code execution during device boot. These flaws, present in code dating back to U-Boot 2013.07, potentially affect many releases and vendor forks across BMCs, networking gear, industrial systems, and IoT devices. While patches have been accepted upstream, vendor firmware updates are required to protect devices, and unsupported hardware may remain vulnerable.
read more โ†’

AzeoTech DAQFactory Type Confusion Advisory

๐Ÿ”’ AzeoTech DAQFactory versions 21.1 and earlier contain a Type Confusion vulnerability that can be triggered by specially crafted .ctl files, potentially enabling arbitrary code execution. Users are advised to avoid opening documents from untrusted sources, store .ctl files in admin-only writable folders, operate in Safe Mode, and apply document editing passwords. CISA notes no known public exploitation and emphasizes network exposure minimization for control systems.
read more โ†’

Schneider Electric Products: Insufficient Entropy Fixes

๐Ÿ”’ Schneider Electric has identified a CWE-331 Insufficient Entropy vulnerability affecting multiple Easergy, EcoStruxure, PowerLogic, and Saitel products that could enable unauthorized access or session compromise. Vendor-supplied fixes and firmware updates are available for numerous models and versions; several updates require a reboot. For models without immediate fixes, Schneider recommends network segmentation and reduced session timeouts as mitigations, and provides general cybersecurity best practices.
read more โ†’

Mitsubishi MELSEC iQ-F EtherNet/IP DoS Fix

๐Ÿ”’ An integer overflow in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP modules can be exploited remotely to cause a denial-of-service by rapidly opening many TCP connections, leading to improper memory access. A vendor update (version 1.001 or later) is available from Mitsubishi Electric to remediate the issue. Until patched, the vendor recommends network restrictions such as firewalls, VPNs, IP filtering, LAN-only operation, and limiting physical and host access to reduce exposure.
read more โ†’

MELSEC iQ-F FX5-ENET/IP Denial-of-Service Risk

๐Ÿ›ก๏ธ Mitsubishi Electric reports an Expected Behavior Violation in the MELSEC iQ-F Series FX5-ENET/IP Ethernet Module that can be exploited to cause a denial-of-service by flooding the device's Ethernet port with packets. No patch is planned; vendors recommend network-level mitigations such as firewalls, VPNs, IP filtering, and restricting physical and network access to reduce exploitation risk.
read more โ†’

Path Traversal Vulnerability in Schneider Electric RTUs

๐Ÿ”’ Schneider Electric EasyLogic T150 and Saitel DP devices contain a CWE-22 Path Traversal vulnerability that can allow unauthorized access to sensitive files when server-side file path processing mishandles user input. Affected firmware versions include EasyLogic T150 <=11.06.31 and Saitel DP <=11.06.36. Remediations include firmware updates to 11.06.32 for EasyLogic T150 and 11.06.37 for Saitel DP; contact Schneider Electric Customer Care to obtain downloads and reboot devices after installing. CISA recommends network isolation, strict credential controls, and defensive measures for ICS devices.
read more โ†’

Multiple authentication and crash issues in industrial historian

๐Ÿ”’ Rockwell Automation's FactoryTalk Historian Site Edition and related AVEVA PI Data Archive components contain vulnerabilities that can allow authentication bypass, denial of service, or crashes. Race conditions (CWE-362) and uncaught exceptions (CWE-248) are cited; repeated login requests may yield valid tokens. Vendors provide mitigations and patches; CISA urges network segmentation, restricted access, and defensive best practices.
read more โ†’

Protecting Legacy OT Systems From Modern Threats

๐Ÿ”’ Manufacturing facilities often rely on long-running operational technology (OT) that was built for stability, not security. As IT and OT converge, previously isolated systems face increased exposure to internet-borne attacks, ransomware, and supply-chain disruption. Effective defenses start with asset visibility, careful deployment choices, network protections for agentless devices, and long-term vendor support to mitigate risks without disrupting production.
read more โ†’

PavilionX Missing Authorization Vulnerability Adviso

๐Ÿ”’ A security issue was identified in Rockwell Automation FactoryTalk Analytics PavilionX due to improper authorization enforcement in API endpoints, allowing unauthorized actors to perform privileged operations such as user and role management. Rockwell Automation recommends updating PavilionX to version 7.01 or later. CISA advises minimizing network exposure of control system devices, isolating them behind firewalls, and using secure remote access methods while performing impact analysis before defensive changes.
read more โ†’

Rockwell FLEX I/O EtherNet/IP Adapter Flaws Fixed

๐Ÿ”’ Rockwell Automation FLEX I/O EtherNet/IP adapters (1794-AENTR) contain vulnerabilities that could enable unauthorized access, account takeover, and denial-of-service. A memory-handling flaw in CIP request processing may cause adapter faults and loss of I/O connectivity, while an embedded web server issue allows unauthenticated password changes via a crafted HTTP GET. Rockwell recommends updating to firmware 2.013 to remediate these issues.
read more โ†’

Rockwell CompactLogix CIP Sequence and Info Leak

๐Ÿ”’ A security advisory details vulnerabilities in Rockwell Automation CompactLogix 1769 controllers where missing validation of CIP sequence numbers and source IPs and exposure of CIP Connection IDs on the device web diagnostics page can be abused to trigger denial-of-service conditions. Rockwell recommends updating affected devices to firmware V38.011 and refers users to advisory SD1776 for mitigation steps. CISA advises minimizing network exposure, placing control systems behind firewalls, using secure remote access like VPNs, and following standard ICS defensive practices and reporting procedures.
read more โ†’

Rockwell Logix 5370/5570 CIP Denial-of-Service Fixes

๐Ÿ›ก๏ธ A denial-of-service vulnerability in Rockwell Automation Logix 5370 and 5570 controllers can cause a major nonrecoverable fault (MNRF) when a crafted CIP message is processed, with devices having less memory at greater risk. Rockwell advises updating to specific firmware versions: CompactLogix 5370 (34.016+), Compact GuardLogix 5370 (35.015+), ControlLogix 5570 (36.012+), and GuardLogix 5570 (37.011+). CISA recommends minimizing network exposure, isolating control networks behind firewalls, using secure remote access methods such as VPNs, and following ICS defensive best practices to reduce exploitation risk.
read more โ†’

RSLinx Classic vulnerability advisory and mitigations

๐Ÿ”’ This advisory describes a stack-based buffer overflow and an out-of-bounds read in Rockwell Automation RSLinx Classic Third-Party components that can cause denial of service or enable remote code execution. Rockwell recommends upgrading to version 4.60.00 or later or applying patch BF31213 where upgrades are not possible. CISA urges minimizing network exposure, isolating control systems behind firewalls, and using secure remote access methods such as updated VPNs while performing impact analysis and risk assessments.
read more โ†’

KACO Blueplanet Inverters: Credential and SQL Injection Risk

๐Ÿ”’ KACO blueplanet inverters contain vulnerabilities that can expose service credentials and allow SQL injection against management components. Siemens and KACO new energy have released updates for some models and recommend updating to the latest firmware where fixes exist. Operators should minimize network exposure, segment control networks, and apply vendor security updates after validation and supervised deployment.
read more โ†’