< ciso
brief />
Tag Banner

All news with #ics security tag

148 articles · page 2 of 8

EcoStruxure Panel Server insecure default credentials

🔒 Schneider Electric disclosed a CWE-1188 vulnerability in EcoStruxure Panel Server products that may cause credentials to revert to insecure defaults in rare circumstances, permitting unauthorized authentication and disclosure of sensitive information. A vendor firmware update (version 002.006.000) is available for affected PAS400/PAS600/PAS800 and V2 variants and requires a reboot. Users are advised to apply the update and follow recommended ICS segmentation and hardening best practices.
read more →

RADIUS Message Integrity Flaw in Modicon Switches

🔒 Schneider Electric disclosed a RADIUS protocol vulnerability (CVE-2024-3596) affecting Modicon Network Managed Switches when the RADIUS Server Message Authenticator option is disabled. The flaw can allow forged RADIUS responses, potentially causing denial of service and loss of confidentiality or integrity for devices connected to the switch. Default configurations are not vulnerable; vendors provide CLI and MIB guidance to ensure msgauth remains enabled. CISA republished the advisory to increase visibility and recommends standard ICS network hardening practices.
read more →

Malware threats imperil automated tank gauges

🔒 CISA warns that ongoing cyber-attacks on automated tank gauges (ATGs) could allow attackers to drain fuel tanks or hide theft and leaks, affecting gas stations, military bases, hospitals, and industrial sites. The attacks exploit authentication bypasses, hardcoded credentials, OS command execution, SQL injection, and privilege escalation to gain full control. Administrators are urged to remove public serial connections, change default passwords, apply patches, report incidents to CISA, and push supply-chain partners to adopt defenses.
read more →

Hitachi Energy RTU500: Multiple Denial‑of‑Service Flaws

🔒 Hitachi Energy has disclosed multiple vulnerabilities affecting RTU500 devices that primarily enable Denial of Service, with potential secondary impacts to confidentiality and integrity. Affected components include PKCS#12 handling, libexpat, and IEC protocol implementations, with issues such as NULL pointer dereferences, integer overflows, and infinite loops. Vendor fixes are available in CMU Firmware versions 13.7.9/13.8.2 (13.7.9 when available), and CISA recommends minimizing network exposure and applying vendor updates and standard mitigations.
read more →

B&R PPT30 OPC‑UA Resource Exhaustion Fix

🔒 B&R has identified a resource exhaustion vulnerability in the OPC‑UA Server used in PPT30 Operating System versions before 1.8.0 that can render the OPC‑UA service inaccessible. The vendor corrected the issue in PPT30 Operating System 1.8.0 and notes the OPC‑UA server is not enabled by default. B&R and CISA recommend updating affected devices, restricting OPC‑UA activation to required systems, and segmenting and firewalling networks to limit access.
read more →

Hitachi Energy ITT600 Explorer DoS Vulnerabilities

🛡️ Hitachi Energy disclosed vulnerabilities in the ITT600 Explorer that can enable Denial of Service (DoS) via crafted IEC61850 messages when IEC61850 server simulation is used. A stack overflow in the libexpat library and uncontrolled recursion/resource allocation issues are identified; affected versions should be updated to 2.1 SP6 HF1 or later and plan for 2.2. CISA republishes the vendor advisory and recommends standard ICS network protections and patching.
read more →

Kaspersky on Safety-Aware Automotive Security

🔒 This article outlines Kaspersky’s approach to securing modern connected and autonomous vehicles, emphasizing the need to combine functional safety with cybersecurity. It highlights standards such as ISO/SAE 21434, UNECE R155/R156, and China’s GB 44495-2024, and explains the role of security gateways and SecOC for CAN bus protection. The piece also discusses distributed IDS monitoring, fleet-wide SIEM integration, and Kaspersky’s KASG and Unified Monitoring and Analysis Platform as implementations.
read more →

Monthly security roundup: May 2026 highlights

🎥 ESET Chief Security Evangelist Tony Anscombe reviews major cybersecurity stories from May 2026, focusing on industrial control system intrusions, an AI-directed data theft, a Google-reported AI-developed zero-day, and crypto kiosk scams. He outlines attack vectors such as weak passwords and internet-exposed systems, notes the partial failure of an IT-to-OT escalation, and previews mitigation advice for defenders. Watch Tony’s video for practical recommendations and refer to the April edition for additional context.
read more →

ABB Busch‑Welcome Door Opener: Debug Code Risk

🔒 ABB has identified an authentication bypass in specific Busch‑Welcome 2 Wire Door Opener Actuator versions due to active debug code and a compatibility mode enabled by default. Exploitation could allow unauthorized physical access to buildings where the device is installed. ABB provides an on‑site mitigation: toggle the product mode from "Door‑Open" to "Light" and back, then perform a mains power restart to force recalibration. CISA republishes the vendor advisory and recommends network isolation, minimized exposure, and use of secure remote access methods such as updated VPNs while encouraging organizations to follow ICS security best practices.
read more →

CP Plus NVR Stored XSS Advisory and Mitigation

📣 A stored Cross-Site Scripting (XSS) vulnerability affects certain CP Plus 8-channel NVR 1xxx series devices due to insufficient input sanitization. Successful exploitation can execute malicious scripts in the browsers of authenticated users and administrators, risking session hijacking, unauthorized actions, and data exposure. CP Plus recommends updating device firmware to the listed version and contacting support for upgrade assistance. CISA also advises network isolation, limiting internet exposure, and following established ICS defensive practices.
read more →

ABB B&R Automation Runtime SDM Denial of Service

🔒 An Improper Resource Locking vulnerability in the System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network attacker to delete data and cause denial of service. The vendor corrected the issue in Automation Runtime 6.3 and Q4.93 and notes SDM is disabled by default in AR 6. B&R recommends applying updates, restricting SDM access, using TLS/mutual TLS, and limiting webserver access to trusted IPs.
read more →

ABB AC500 V2 Modbus Buffer Over-read Advisory

🛡️ The advisory details a buffer over-read vulnerability in ABB AC500 V2 devices that can cause Modbus server responses to include fragments of earlier telegrams. Affected devices running older firmware may return invalid or appended data when presented with unsupported Modbus function codes. ABB issued a fix in AC500 V2 firmware version 2.5.3 (2016) and later; operators are urged to update and minimize network exposure. CISA republished the vendor advisory to raise visibility and recommends isolating control networks and using secure remote access.
read more →

Schneider Electric EcoStruxure HVAC Sensitive Data Risk

🔒 Schneider Electric has identified a CWE-312 vulnerability in EcoStruxure Machine Expert HVAC, a programming tool for Modicon M171-M172 controllers, that can expose sensitive information including protected source code. Version 1.10.0 includes a vendor-provided fix and users are urged to update. The advisory also reiterates standard ICS security best practices to isolate control networks and limit exposure.
read more →

Tracking demo.pdb BadIIS: Commodity IIS Malware Toolset

🔍 Since 2024, Talos has tracked a BadIIS variant identified by consistent "demo.pdb" PDB paths across the Asia‑Pacific region and isolated cases elsewhere. The PDB path patterns—including Chinese folder names, Administrator\Desktop build artifacts, and date‑based versioning—provide a reliable fingerprint for clustering and attribution. Talos recovered a 2022 builder that produces configured 32/64‑bit payloads, uses a unique 'lwxat' C2 authentication check and XOR 0x3 obfuscation, and supports modular SEO‑fraud and proxy features. Evidence shows active development from Sept. 2021 through Jan. 2026.
read more →

Fuji Electric Tellus Privilege Escalation Advisory

🔒 CISA published an advisory describing a privilege-escalation vulnerability in Fuji Electric Tellus arising from a kernel driver that grants all users read and write permissions. Successful exploitation could elevate a user to system privileges and may enable temporary denial of service, file opening, or file deletion. The vendor recommends installing Tellus only with administrator privileges; CISA notes the issue is not remotely exploitable and no public exploitation has been reported. CISA advises implementing ICS defensive measures and following established reporting procedures.
read more →

Guide to Accelerate Zero Trust for Operational Technology

🔐 CISA and U.S. government partners published Adapting Zero Trust Principles to Operational Technology, a practical guide for OT owners, operators, and Zero Trust practitioners. The guidance explains how to apply Zero Trust in OT environments while minimizing risk to mission-critical systems and accommodating legacy constraints and safety requirements. It highlights establishing zones and conduits, addressing supply chain risks, and implementing robust identity and access management to reduce exposure and strengthen resilience.
read more →

NSA GRASSMARLIN XML External Entity Vulnerability Advisory

⚠️ A vulnerability in NSA GRASSMARLIN allows crafted session data to trigger improper XML parsing that may disclose sensitive information. Tracked as CVE-2026-6807 and classified under CWE-611, the issue affects GRASSMARLIN v3.2.1 and carries a CVSS 3.1 base score of 5.5 (MEDIUM). The GRASSMARLIN project reached end-of-life in 2017 and is archived, so no vendor patches are planned; CISA recommends compensating controls, network isolation, and following published ICS defensive guidance.
read more →

Siemens Industrial Edge Management Authentication Bypass

🔒 Siemens has disclosed an authorization bypass vulnerability in Industrial Edge Management that may allow an unauthenticated remote attacker to circumvent authentication and access connected devices using the product's remote connection feature. Tracked as CVE-2026-33892, the flaw has a CVSS v3.1 base score of 7.1 (High). Siemens released patched versions and urges operators to update immediately and restrict network access to affected systems.
read more →

Siemens TPM 2.0 Vulnerability (CVE-2025-2884) Advisory

🔒 The Siemens TPM 2.0 reference implementation contains a vulnerability (CVE-2025-2884) in the CryptHmacSign helper that can perform an out‑of‑bounds read because it does not validate the signature scheme against the signature key algorithm. Successful exploitation could result in information disclosure or denial of service of the TPM. Siemens ProductCERT has published fixes for many affected SIMATIC and IPC models and is preparing additional updates; where fixes are not yet available, CISA and Siemens recommend network isolation and other mitigations.
read more →

Siemens SINEC NMS UMC Authentication Bypass Vulnerability

⚠️ A vulnerability in Siemens SINEC NMS when used with the User Management Component (UMC) allows an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the application. Tracked as CVE-2026-24032 and scored CVSS v3.1 7.3 (High), the flaw stems from insufficient validation of user identity in the UMC. Siemens released an update; operators should upgrade to V4.0 SP3 or later. Limit network exposure, isolate control networks behind firewalls, and follow Siemens' industrial security guidance when applying fixes.
read more →