#ics
24 posts · Last used 12d
📰 CISA & FBI Warn of Third-Party Risks to Industrial Control Systems
CISA & FBI issue joint guidance on securing critical infrastructure from third-party ICS integrator risks. The advisory stresses least privilege, robust contracts, and secure remote access monitoring. #ICS #OTsecurity #CISA #SupplyChain
🔗 https://cyber.netsecops.io/articles/cisa-fbi-warn-critical-infrastructure-on-third-party-ics-risks/?utm_source=mastodon&utm_medium=social&utm_campaign=daily
CISA has issued an advisory for CVE-2026-34223 in Siemens Desigo CC: a compromised graphics document can trigger client-side code execution and write arbitrary files. System compromise and potential lateral movement make this relevant to ICS defenders. #CyberSecurity #ICS #Vulnerability
https://cyberworldops.eu/en/malicious-graphics-files-put-siemens-desigo-cc-clients-at-risk-of-code
Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy
Cybercriminals are exploiting legitimate Google infrastructure in a sophisticated phishing operation that bypasses email security gateways and enterprise firewalls. The attack chains together six distinct Google properties including Meet, Search, DoubleClick, Custom Search, Tag Manager and Analytics to proxy malicious traffic through trusted domains. Victims' email addresses are encoded in URL fragments and stripped before server-side logging. Landing pages dynamically impersonate target organizations by pulling live logos from Clearbit, capturing real-time website screenshots, and validating domains via Google's DNS API. The operation includes multilingual support for 16 languages and dual execution tracks: credential harvesting with immediate Telegram exfiltration, or silent ScreenConnect remote access tool installation. Lures span document reviews, credential expiry notices, package delivery, payment notifications, government benefits and voicemail themes targeting manufacturing, government, finance and...
Pulse ID: 6a9ef40735b49c55dc7166c9
Pulse Link: https://otx.alienvault.com/pulse/6a9ef40735b49c55dc7166c9
Pulse Author: AlienVault
Created: 2026-09-07 17:27:35
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #CyberSecurity #DNS #DoubleClick #Email #Google #Government #ICS #InfoSec #Manufacturing #OTX #OpenThreatExchange #Phishing #Proxy #RAT #Rust #ScreenConnect #Telegram #bot #AlienVault
CVE-2026-11841 lets an unauthenticated attacker reach internal files on SICK InspectorP6xx devices, risking device compromise. CVSS 9.4. Update to 5.4.0.
#SICK #InspectorP6xx #CVE202611841 #OTSecurity #ICS #CyberSecurity
http://securityonline.info/sick-inspectorp6xx-cve-2026-11841/?utm_source=mastodon&utm_medium=jetpack_social
📰 𝗡𝗲𝘂𝗲𝘀 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗝𝗼𝘂𝗿𝗻𝗮𝗹 – 𝗱𝗶𝗲 𝗝𝘂𝗹𝗶-𝗔𝘂𝘀𝗴𝗮𝗯𝗲 𝗶𝘀𝘁 𝗱𝗮!
Unser Security Journal erscheint alle zwei Monate und liefert tiefgehende Einblicke in aktuelle Entwicklungen der Cybersicherheit.
🌐 In dieser Ausgabe erwarten Sie wieder spannende Inhalte:
𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆-𝗙𝗮𝗰𝗵𝗮𝗿𝘁𝗶𝗸𝗲𝗹: Der Tag, an dem Washington eine KI abschaltete – Die Sperrung von Claude Fable 5 und Mythos 5
🗞️ 𝗡𝗲𝘄𝘀-𝗕𝗹𝗼𝗰𝗸: wichtigste Entwicklungen in der Informationssicherheit
🔟 𝗧𝗼𝗽 𝟭𝟬: Sicherheitsrisiken der letzten Monate
⚙️ 𝗜𝗖𝗦/𝗢𝗧: relevanteste Schwachstellen im Überblick
Verpassen Sie keine Ausgabe und bleiben Sie auf dem neuesten Stand, um die digitale Sicherheit zu stärken!
👉 Jetzt anmelden: https://www.gai-netconsult.de/security-journal/
#SecurityJournal #CyberSecurity #Informationssicherheit #Sicherheitsmanagement #ICS #OTSecurity #RiskManagement #StaySecure
MicroLogix 1400 attacks hit internet-exposed PLCs at water utilities, locking out operators. Rockwell shares recovery and hardening steps.
#MicroLogix1400 #RockwellAutomation #ICS #OTSecurity #WaterUtilities
https://securityonline.info/micrologix-1400-attacks/?utm_source=mastodon&utm_medium=jetpack_social
Phoenix Contact CHARX SEC-3150 v1.0.0 hit by CRITICAL (CVSS 9.3) command injection (CVE-2026-7849): unauthenticated remote attackers can execute root commands. No mitigation yet — restrict access! https://radar.offseq.com/threat/cve-2026-7849-cwe-77-improper-neutralization-of-special-elements-used-in-a-command-command-injection-8b9703c63834cb6a #OffSeq #ICS #Vuln #CVE2026_7849
🚨 BREAKING: A coordinated cyberattack targeted 30+ community water systems across Minnesota, disrupting operational technology (OT) and temporarily taking one treatment plant offline.
State and federal agencies, including CISA, FBI, and EPA, are investigating. Officials say there is no evidence that drinking water quality was compromised, and the attack has not yet been attributed to any threat actor.
Full analysis, technical breakdown, and what this means for critical infrastructure security:
🔗 https://thecybersecguru.com/news/minnesota-water-systems-cyberattack-ot/
#CyberSecurity #OTSecurity #ICS #SCADA #CriticalInfrastructure #WaterSecurity #CyberAttack #ThreatIntel #CISA #InfoSec
Hack like Mr Robot // WiFi, Bluetooth and Scada hacking
OccupytheWeb explains how hacks shown in the Mr Robot TV Series actually work. He compares real world WiFi, Bluetooth and Scada hacking vs what is shown in the TV series.
https://www.youtube.com/watch?v=3yiT_WMlosg
#youtube #wifi #bluetooth #scada #ics #infosec #cybersecurity #hacking
Hack like Mr Robot // WiFi, Bluetooth and Scada hacking
Replying to
Reward: You've received a Depreciated Legacy Asset — it's a firewall from 2014. Good luck.
#ManufacturingCybersecurity #IndustrialControl #CyberSecurity #SonicWall #ICS #FactoryFloorFail (3/3)
Came across a disclosure in Altus BluePlant 9.1.40 — a SCADA HMI / ICS platform. CVSS 9.8, unauthenticated RCE, default configuration, as the service account (administrator).
The standout: the vendor's auth validator hardcodes three credential-bypass paths in code. Use any one to bypass Connect, get a connectionHandle, then drive a generic RMI gateway to FileServer.RunProcess → Process.Start. No creds, no TLS, port 3100 reachable by default after install.
Full root-cause + self-contained PoC on the advisory page.
https://0day-rubbish.com/blog/altus-blueplant-hardcoded-creds-rce
https://github.com/Exploit-Garbage/0day-Rubbish
The project attributes discovery to an automated multi-LLM process (Claude/OpenAI/DeepSeek/GLM), defensive framing, full-disclosure posture. Not affiliated; noting for awareness.
#infosec #ICS #SCADA #OTsecurity #vulnerability #0day #RCE #exploit
Siemens Opcenter X authentication bypass (CVE-2026-56451, CVSS 10) lets attackers forge JWTs for full unauthorized access. Update to V2604 now.
#Siemens #OpcenterX #CVE202656451 #ICS #AuthenticationBypass
https://securityonline.info/siemens-opcenter-x-auth-bypass/?utm_source=mastodon&utm_medium=jetpack_social
Replying to
KNOWN ISSUE: You haven't done that yet, have you? The ROX II is right there, humming away in a rack, feeling very open-sourcey about its privileges.
Patch Siemens ROX II to firmware V2.17.1 immediately — that is the only listed remediation.
Reward: You've received a Cursed Root Certificate of Participation.
#CyberSecurity #OTSecurity #ZeroDay #Siemens #ICS #PatchedOrPerish (2/2)
🚨 ALERT: CVE-2023-4346 allows attackers to purge and lock KNX industrial control devices. If you manage building automation, your perimeter is at risk. Get the forensic indicators and hardening playbooks you need to secure your assets. https://thecybermind.co/m6eo
#CyberSecurity #ICS #KNX #TCM #IndustrialSecurity
CRITICAL severity: All critical infrastructure sectors must plan for eventual cyber defense failure. CPRE (Cyber Physical Resilience Engineering) recommends resilient designs, independent safety controls, and digital twins. More: https://radar.offseq.com/threat/should-critical-infrastructure-be-designed-assumin-9832f0b6ad8c16a7 #OffSeq #ICS #Resilience
CVE-2026-10577: CRITICAL vuln in Rockwell 1715 EtherNet/IP module. Debug port lacks authentication, enabling remote CLI access for file deletion, task stop, or memory changes. Review device exposures now. https://radar.offseq.com/threat/cve-2026-10577-cwe-306-missing-authentication-for--25c66fc4335b822a #OffSeq #ICS #CVE2026_10577 #OTSecurity
CVE-2026-4769 exposes WAGO System I/O field devices. An early-boot flaw lets an unauthenticated attacker reach full system compromise.
#WAGO #CVE20264769 #ICS #OTSecurity #Firmware
https://securityonline.info/wago-system-io-cve-2026-4769/?utm_source=mastodon&utm_medium=jetpack_social
Bypassing Zero Trust using... laws of physics? 🤯⚡
Join SpaceCoastSec Aug 12 @ 6:30 PM as Paul Coggin breaks down Purdue Level 0 cyber-physics transduction attacks. No packets, just weaponized energy! ⚛️💥
RSVP: https://www.meetup.com/spacecoastsec/events/313526424
#SpaceCoast #ICS #Cybersecurity #Brevard #BuildingCommunity
CVE-2026-12819 (CRITICAL, CVSS 9.3) in deltaww DVP-12SE PLC: Modbus TCP service lacks authentication, allowing unauthenticated access to critical PLC functions. Segment networks & restrict access. https://radar.offseq.com/threat/cve-2026-12819-cwe-306-missing-authentication-for--8fd3769bc2b1bbcf #OffSeq #ICS #Vulnerability #PLCsecurity
Replying to
Hieronder screenshots van hetgeen ik noemde in de toot hierboven:
• De nieuwe ICS phishingsite (achter Cloudflare, geen phishing-waarschuwing);
• De Coudflare phishing-waarschuwing;
• Met "/whatever" achter de link geplakt waarschuwt Cloudflare NIET voor phishing (dus hadden de phishers dat eenvoudig kunnen omzeilen). Na enige tijd meldt Cloudflare dat de site onbereikbaar is.
#ICS #ICSphishing #Phishing #CloudflareIsEvil





