Threats Tagged 'ics'
View all threats tagged with 'ics'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ics'
Click on any threat for detailed analysis and mitigation recommendations
NIST has released a draft update to its Operational Technology (OT) Security Guide (Special Publication 800-82 Revision 4) for public comment, expanding coverage to additional sectors and aligning with the NIST Cybersecurity Framework 2.0. Concurrently, CISA and the FBI issued guidance warning critical infrastructure operators about risks associated with third-party ICS integrators, emphasizing the principle of least privilege and recommending contractual cybersecurity requirements. The agencies highlighted a 2025 intrusion where foreign actors accessed an industrial automation company's network, potentially enabling disruptive downstream attacks. The guidance advises monitoring remote access, minimizing exposure, and incorporating cybersecurity controls in service agreements. Join the discussion | SecurityWeek | 09/24/2026, 11:05:16 UTC Added: 09/24/2026, 11:17:47 UTC |
AI advancements are accelerating the discovery of vulnerabilities, leaving many operational technology (OT) systems unpatchable and at risk. These OT systems often run on legacy or bespoke software that cannot be easily updated or patched. Ignoring these vulnerabilities is not a viable defense. Instead, network-based protections such as micro-segmentation, next-generation firewalls (NGFW), and intrusion prevention systems (IPS) can provide compensatory controls by filtering and blocking exploit attempts. The concept of air-gapping is often ineffective in practice due to operational shortcuts. While patching remains the best defense, these layered network protections help mitigate risks where patching is impossible. Join the discussion | Cisco Talos | 09/16/2026, 10:00:36 UTC Added: 09/16/2026, 10:10:48 UTC |
The Australian Signals Directorate (ASD) is transitioning from the Essential Eight cybersecurity framework to a new outcomes-based Essentials series starting mid-2027, with full retirement of the Essential Eight expected around mid-2028. This shift moves organizations away from periodic, checklist-style compliance assessments toward continuous validation of security posture across enterprise IT, cloud, operational technology (OT), and potentially agentic AI environments. The new framework emphasizes demonstrating ongoing achievement of security outcomes rather than merely implementing specific controls. Compliance with the Essential Eight remains mandatory only for certain Commonwealth entities, while private-sector adoption is voluntary but often expected by insurers and government contractors. The Essentials series introduces chapters tailored to different environments, reflecting their unique security challenges and dynamic nature. Exposure management tools are highlighted as a means to continuously identify and prioritize security exposures and provide real-time evidence of security posture. Join the discussion | Tenable Research | 09/15/2026, 13:32:00 UTC Added: 09/15/2026, 13:42:37 UTC |
Multiple critical and high-severity vulnerabilities affecting industrial control system (ICS) products from Schneider Electric, Siemens, Aveva, and Rockwell Automation were disclosed and patched in the September 2026 Patch Tuesday cycle. Notably, Schneider Electric fixed a critical authentication vulnerability in Modicon M580 controllers (CVE-2026-3869, CVSS 9.2), and Siemens addressed critical flaws in several products including Reyrolle 7SR5 and Industrial Edge Management. Aveva and Rockwell Automation also released patches for high-severity issues in their ICS components. These vulnerabilities could impact the security of critical industrial infrastructure if left unpatched. Join the discussion | SecurityWeek | 09/09/2026, 10:49:30 UTC Added: 09/09/2026, 10:52:16 UTC |
Tenable is integrating Anthropic's Claude Mythos 5 AI model into its Tenable One Exposure Management Platform. This integration, starting with the new Adversary View feature, aims to enhance security teams' ability to identify complex vulnerability chains by reasoning across scattered low-signal data that traditional rules engines miss. Adversary View uses advanced adversarial reasoning to analyze raw scan data and prioritize defensive actions that disrupt attacker progression. This approach helps defenders see their environments from an attacker's perspective and focus remediation efforts more effectively. The offering is positioned as an AI-powered enhancement to exposure management rather than a vulnerability or exploit. Join the discussion | Tenable Research | 09/08/2026, 17:21:00 UTC Added: 09/08/2026, 17:35:27 UTC |
0 Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:19:13 UTC Added: 09/08/2026, 17:27:15 UTC |
The ICS Cybersecurity Conference will feature a hands-on Cyber Attack Methods (CAM) training course focused on cyber-physical systems. This course places participants in a virtual environment to simulate adversary tactics against industrial control systems, helping defenders and engineers understand attack processes and improve system resilience. The training is designed for a broad audience including engineers and developers, not just security professionals. It aims to enhance practical knowledge of how cyber-physical attacks unfold and how to mitigate them. The course is US citizen-only and requires an Intel-based laptop to run the virtual machine environment. Join the discussion | SecurityWeek | 08/25/2026, 12:57:59 UTC Added: 08/25/2026, 13:07:12 UTC |
Multiple U.S. government agencies have issued a joint advisory warning of active threat actors targeting Siemens S7 Series programmable logic controllers (PLCs) exposed to the internet or insufficiently segmented. These actors use AI-generated exploitation scripts disguised as legitimate OT monitoring tools to conduct reconnaissance and build capabilities for potential future disruptive attacks. The threat affects all CPU variants of the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series. There is no single patch because the threat exploits multiple known weaknesses and exposure issues. Mitigation focuses on removing direct internet exposure, segmenting OT from IT networks, and hardening access controls. The advisory emphasizes that all PLC operators, regardless of vendor, should apply relevant mitigations. The threat is distinct from a prior Iranian-linked campaign and is unattributed to any specific group. Join the discussion | Tenable Research | 08/20/2026, 14:01:58 UTC Added: 08/20/2026, 17:09:11 UTC |
Multiple industrial cybersecurity advisories were published by Siemens, Schneider Electric, Aveva, and Phoenix Contact addressing critical and high-severity vulnerabilities in their ICS/OT products. These vulnerabilities include authorization bypass, privilege escalation, command injection, remote code execution, and sensitive data exposure affecting various industrial devices and software. Exploitation scenarios vary, with some requiring elevated privileges or user interaction. Vendor advisories provide fixes for these security flaws. Join the discussion | SecurityWeek | 08/12/2026, 07:51:55 UTC Added: 01/15/2026, 09:16:05 UTC |
In late 2025, a small combined heat-and-power (CHP) plant in Poland was breached by attackers using a private APN to access its operational technology (OT) network. The attackers exploited a misconfiguration that allowed devices within the private APN network to communicate freely, enabling lateral movement. They compromised a FortiGate VPN/firewall and a Teltonika cellular router to tunnel into the private APN, then accessed a WAGO PFC200 PLC with default credentials. The attackers subsequently disabled key systems including a steam turbine and water treatment system by switching PLCs to STOP mode and activating password protection. The outage was short-lived and did not impact the population. This incident is notable as the first known real-world cyberattack leveraging lateral movement through a private APN to reach OT networks. The Polish CERT recommends treating private APNs as untrusted external networks and implementing client isolation and traffic allowlists. Join the discussion | Bleeping Computer | 08/10/2026, 23:07:21 UTC Added: 08/10/2026, 23:11:22 UTC |
Showing 1 to 10 of 13 results