< ciso
brief />
Tag Banner

All news with #ot security tag

363 articles

AI-Generated Exploits Target Siemens PLCs, Risking ICS Safety

πŸ›‘οΈ U.S. agencies warned of an active threat using AI-generated exploit scripts to target Siemens S7 Series PLCs and other industrial controllers, posing risks to Critical Manufacturing, Energy, Water, and related sectors. The campaign leverages internet scanning services to find exposed devices and uses custom Python tools integrating snap7.dll or python-snap7 to mimic legitimate monitoring utilities. Agencies urge patching, network isolation, strong access controls, and enhanced ICS monitoring to mitigate potential disruption, data compromise, and safety incidents.
read more β†’

AI-assisted attacks target Siemens S7 PLCs

🚨 A joint US government advisory warns that threat actors are using AI to generate exploitation scripts and tools targeting Siemens S7 Series programmable logic controllers (PLCs), placing critical sectors such as water, energy and manufacturing at heightened risk. The agencies say attackers are leveraging public scanning services to find internet-exposed PLCs, using AI to assist lateral movement and to craft tools that mimic legitimate OT monitoring, enabling read/write access via the S7comm protocol. Operators are urged to inventory systems, patch devices, block internet access to PLCs, segregate OT/IT networks, restrict remote access with MFA, disable unused services and engage with vendors for model-specific hardening to mitigate disruption, safety incidents and data compromise.
read more β†’

U.S. warns of AI-driven attacks on Siemens PLCs

πŸ”’ U.S. cybersecurity agencies issued a joint advisory warning that threat actors are using AI-generated Python scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) within U.S. critical infrastructure. The agenciesβ€”NSA, CISA, FBI, DOE, and EPAβ€”noted ongoing activity that targets exposed PLCs by abusing vulnerabilities, outdated software, and weak authentication to gain read/write access and disguise tools as legitimate OT monitoring software. Operators are urged to inventory devices, apply updates, block internet access, and strengthen monitoring and access controls to reduce risk.
read more β†’

Over 4,400 Rockwell PLCs Exposed on Internet

πŸ” Forescout's August 3 scan found 4,407 internet-exposed Rockwell Automation PLCs worldwide, including 2,844 in the US; 22 were in cities hit by recent water utility attacks. The firm noted attackers can alter IPs and set passwords on reachable controllers without exploiting a vulnerability, and 19 of 22 in affected cities used the same mobile carrier network. The FBI and EPA urge strong authentication, firmware updates and isolation of remote access to reduce public exposure.
read more β†’

FortiOS v7.6.x Achieves IEC 62443-4-2 SL4

πŸ”’ Fortinet announces that FortiOS v7.6.x has achieved IEC 62443-4-2 Security Level 4 (SL4) certification, the highest component assurance level for industrial automation and control systems. This complements the company’s IEC 62443-4-1 ML2 accreditation for secure product development and validates FortiOS technical capabilities across identification, integrity, confidentiality, availability, and response requirements. The certification applies across FortiGate platforms running v7.6.x, reinforcing operational resilience for OT and critical infrastructure environments.
read more β†’

Minnesota water cyberattack exposes OT backup gaps

πŸ”’ The July 26–27 coordinated cyber activity against more than 30 Minnesota community water systems targeted operational technology, disrupting remote control and forcing manual operations in some places. Advisories from CISA and vendors document exfiltration of PLC project files and recovery procedures that assume operators possess current offline project backups. The article emphasizes immediate, low-cost countermeasures: verify offline, versioned project archives, reconcile SIM-equipped devices via carrier invoices, restrict integrator remote access, and test time-to-manual recovery.
read more β†’

Six hard truths from CI Fortify guidance

πŸ”’ The Five Eyes’ CI Fortify guidance urges critical infrastructure operators to be able to isolate operational technology deliberately and sustain services during a crisis. The advisory rates VLANs and MPLS as insufficient long-term segregation and cautions against trusting carrier services or native OT encryption. It warns that software-defined controls are convenient but not equivalent to physical separation, and that isolation introduces its own operational risks requiring planning and testing.
read more β†’

CISA warns of attacks on US water and wastewater systems

🚨 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert after hackers disrupted over 30 Minnesota community water systems by targeting internet-exposed programmable logic controllers (PLCs). The attacks included password changes that locked operators out, IP alterations that severed internet connectivity, and other actions that impaired operations. CISA urges owners and operators to remove publicly exposed PLCs and OT from the internet, use VPNs or gateway devices for access, change default passwords, and implement IP allow-lists. Security vendor research from Censys found thousands of internet-reachable PLC hosts and highlighted undocumented cellular modems as a common blind spot.
read more β†’

Coordinated cyberattack disrupts Minnesota water systems

πŸ”’ A coordinated cyberattack targeted more than 30 Minnesota community water systems over July 26–27, prompting temporary operational shutdowns and local emergency responses while officials reported drinking water remained safe. Security researchers link the campaign to a months-long surge in attacks on water infrastructure and note potential ties to exposed PLCs, including Rockwell Automation MicroLogix 1400 controllers. Federal agencies urged utilities to remove internet-exposed operational technology and follow mitigation guidance as investigations continue.
read more β†’

Coordinated cyberattack hits 30+ Minnesota water systems

πŸ”’ A coordinated cyberattack impacted operational technology at more than 30 Minnesota community water systems on July 26–27, prompting a statewide cybersecurity response. Several municipalities, including Braham, Plymouth, South St. Paul and Maple Plain, reported outages, communications failures or affected automated controls, with Maple Plain declaring a local emergency. Minnesota IT Services (MNIT) and federal partners are investigating, sharing intelligence and working to contain and recover systems while attribution and technical details remain under investigation.
read more β†’

Guidance for isolating critical infrastructure OT

πŸ”’ New joint guidance from U.S. and Australian cybersecurity agencies, including CISA and the ACSC, advises critical infrastructure operators to prepare to isolate vital operational technology systems during cyber incidents. The document defines concepts like vital systems, isolation points, and graduated versus physical isolation, and stresses planning, documentation, and regular testing. It highlights trade-offs, operational impacts, and the need to maintain manual operations and secure offline plans.
read more β†’

Chained Zero-Day Flaws in Siemens ROX II Switches

πŸ›‘οΈ This Unit 42 advisory, developed in partnership with Siemens, describes a chained exploit of three zero-day vulnerabilities in Siemens ROX II OT switches. The chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) enables arbitrary file disclosure, root privilege escalation and persistent root execution, risking full device compromise. Siemens has issued advisories and a firmware update V2.17.1; Palo Alto Networks provides virtual patching and OT device protections.
read more β†’

Monthly security roundup β€” June 2026 highlights

πŸ” ESET Chief Security Evangelist Tony Anscombe reviews key cybersecurity stories from June 2026, assessing implications for defenders. He covers new CISA vulnerability patching rules, attacks on Internet-exposed automatic tank gauge (ATG) systems, rising imposter-scam losses reported by the FTC, and proposed UK and Canada social media bans for under-16s. Tony outlines lessons for organizations beyond federal agencies and practical steps to reduce risk.
read more β†’

Practical Zero Trust Plan for OT: 90‑Day Roadmap

πŸ”’ The article reframes zero trust for operational technology (OT) by focusing on practical, non‑disruptive steps that align with regulatory requirements and operational realities. It proposes a 90‑day plan: Days 1–30 prioritize mapping assets and identities at IT/OT boundaries; Days 31–60 contain vendor remote access to gain early wins; Days 61–90 build a simple maturity scorecard and narrative. The approach emphasizes targeted controls, governance alignment, and measurable progress rather than abstract architectures.
read more β†’

Canada’s Spy Agency Uses Court Warrant to Disrupt Botnets

πŸ›‘οΈ The Federal Court authorized the Canadian Security Intelligence Service to reach into infected servers, SOHO routers, and IoT devices on Canadian soil to neutralize two foreign-run botnets. The public ruling, released June 15, confirms CSIS used its threat reduction warrant powers for the first time to alter, degrade, and destroy botnet data while ensuring the operation targeted devices rather than people. The court found the threat imminent and proportional, but redactions leave the precise foreign actor(s) unidentified.
read more β†’

AzeoTech DAQFactory Type Confusion Advisory

πŸ”’ AzeoTech DAQFactory versions 21.1 and earlier contain a Type Confusion vulnerability that can be triggered by specially crafted .ctl files, potentially enabling arbitrary code execution. Users are advised to avoid opening documents from untrusted sources, store .ctl files in admin-only writable folders, operate in Safe Mode, and apply document editing passwords. CISA notes no known public exploitation and emphasizes network exposure minimization for control systems.
read more β†’

Schneider Electric Products: Insufficient Entropy Fixes

πŸ”’ Schneider Electric has identified a CWE-331 Insufficient Entropy vulnerability affecting multiple Easergy, EcoStruxure, PowerLogic, and Saitel products that could enable unauthorized access or session compromise. Vendor-supplied fixes and firmware updates are available for numerous models and versions; several updates require a reboot. For models without immediate fixes, Schneider recommends network segmentation and reduced session timeouts as mitigations, and provides general cybersecurity best practices.
read more β†’

MELSEC iQ-F FX5-ENET/IP Denial-of-Service Risk

πŸ›‘οΈ Mitsubishi Electric reports an Expected Behavior Violation in the MELSEC iQ-F Series FX5-ENET/IP Ethernet Module that can be exploited to cause a denial-of-service by flooding the device's Ethernet port with packets. No patch is planned; vendors recommend network-level mitigations such as firewalls, VPNs, IP filtering, and restricting physical and network access to reduce exploitation risk.
read more β†’

Path Traversal Vulnerability in Schneider Electric RTUs

πŸ”’ Schneider Electric EasyLogic T150 and Saitel DP devices contain a CWE-22 Path Traversal vulnerability that can allow unauthorized access to sensitive files when server-side file path processing mishandles user input. Affected firmware versions include EasyLogic T150 <=11.06.31 and Saitel DP <=11.06.36. Remediations include firmware updates to 11.06.32 for EasyLogic T150 and 11.06.37 for Saitel DP; contact Schneider Electric Customer Care to obtain downloads and reboot devices after installing. CISA recommends network isolation, strict credential controls, and defensive measures for ICS devices.
read more β†’

Protecting Legacy OT Systems From Modern Threats

πŸ”’ Manufacturing facilities often rely on long-running operational technology (OT) that was built for stability, not security. As IT and OT converge, previously isolated systems face increased exposure to internet-borne attacks, ransomware, and supply-chain disruption. Effective defenses start with asset visibility, careful deployment choices, network protections for agentless devices, and long-term vendor support to mitigate risks without disrupting production.
read more β†’