#ot

18 posts · Last used 8d

Back to Timeline
Claroty @Claroty@infosec.exchange · Aug 05, 2026
👋 Meet Claire, the industry's first CPS-native AI security agent. Designed to help security teams work smarter, Claire delivers AI-powered insights, simplifies complex investigations, and helps organizations protect their #OT, #IoT, #IoMT, and other cyber-physical environments with greater speed and confidence. 💡 Learn more: https://claroty.com/blog/how-claroty-claire-brings-ai-powered-cybersecurity-to-cyber-physical-systems #Cybersecurity #ArtificialIntelligence #AI #OTSecurity #CriticalInfrastructure #CPS #ClarotyClaire
0
0
0
CERT@VDE @certvde@infosec.exchange · Aug 03, 2026
#OT #Advisory VDE-2026-065 Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory. #CVE CVE-2026-9593 https://certvde.com/en/advisories/vde-2026-065/ #CSAF https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-065.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 30, 2026
#OT #Advisory VDE-2026-008 Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability. #CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102 https://certvde.com/en/advisories/vde-2026-008/ #CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 29, 2026
#OT #Advisory VDE-2026-041 CODESYS PROFINET Controller - Out-of-bounds Write CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. #CVE CVE-2026-35226 https://certvde.com/en/advisories/vde-2026-041/ #CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-06_vde-2026-041.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 28, 2026
#OT #Advisory VDE-2026-085 Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands. #CVE CVE-2026-16462 https://certvde.com/en/advisories/vde-2026-085/ #CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-085.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 28, 2026
#OT #Advisory VDE-2026-081 Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0. #CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510 https://certvde.com/en/advisories/vde-2026-081/ #CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 28, 2026
#OT #Advisory VDE-2026-076 ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0. #CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510 https://certvde.com/en/advisories/vde-2026-076/ #CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 27, 2026
#OT #Advisory VDE-2026-077 Lenze: Incorrect signature validation in the enable SSH routine The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device. #CVE CVE-2026-14837 https://certvde.com/en/advisories/vde-2026-077/ #CSAF https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-077.json
0
0
0
runZero, Inc @runZeroInc@infosec.exchange · Jul 17, 2026
Legacy Systems, Real-World Impacts: The Reality of OT Security In his latest SecurityWeek column, runZero's Tod Beardsley explores why vulnerability management in #OT is a completely different ballgame. As OT/IT convergence accelerates, we need to evolve our defense strategies before AI-assisted attackers take advantage of the hidden exposures and broken segmentation in these environments. Read Tod’s full analysis here: ➡️ https://www.securityweek.com/legacy-systems-real-world-impacts-the-reality-of-ot-security/
1
0
1
Fab @occirol@infosec.exchange · Jul 14, 2026
Any #OTSecurity account worth following ? Any ideas/recommendations ? #infosec #ot #security
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 13, 2026
#OT #Advisory VDE-2026-031 WAGO: Early-Boot Diagnostic Exposure in WAGO System I/O Field Devices Certain devices in the WAGO System I/O Field series enable an internal diagnostic capability during the initial stages of system startup. This behavior, which is not part of the publicly documented feature set, briefly allows access to system functions before the main operating environment becomes fully active. Under specific conditions, this could permit interactions with system components that are normally protected during regular operation. #CVE CVE-2026-4769 https://certvde.com/en/advisories/vde-2026-031/ #CSAF https://wago.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-031.json
0
0
0
JTI @jti42@infosec.exchange · Jul 08, 2026
Gammel-OT, jetzt neu: Verteilt, unisoliert, noch verrotteter als sonst. Quasi die Plasterouter-Version von Groß-OT für das es ja wenigstens noch manchmal etwas zwangsmäßigen Effort gibt. Plasterouter-OT sozusagen. https://www.heise.de/news/Sicherheitsalbtraum-Wechselrichter-Hoymiles-laesst-Nachbarschaften-verstummen-11357067.html Die Schwachstelle klingt...uhm...garstig. Besonders der Drohnenansatz gefält. 😱 #ot #plasterouter #gammelot #solarpunk #solarpower #blackout
1
1
1
Cyber℻ @eyetSystems@infosec.exchange · Jul 07, 2026
We spend so much time prepping for zero-day exploits from nation states. But this article suggests targeting water systems relies less on sophisticated malware and more on simple failures: weak passwords and poor segmentation in OT environments. It’s fundamentally a governance issue, not just a technical one. How robust is your organisation's strategy around systemic decay? #CyberSecurity #OT https://www.darkreading.com/ics-ot-security/iran-russia-china-target-water-systems-sabotage
0
0
0
Scott Wilson 🌈 @scottwilson@infosec.exchange · Jul 03, 2026
Hoo, boy… Everyone in #infosec & especially #OT needs to be aware of this. No patches exist or are likely… https://risky.biz/RBNEWS585/
0
0
0
Tara 🕷️:blobbat: @tarajdactyl@anarres.family · Apr 08, 2026
Boosted by hypebot @hypebot@goingdark.social
:boosts_ok_gay: attention anybody with substantial experience with Rust and networking: my team is hiring!! one of few rust jobs I'm aware of that is not web 3.0 horseplop. fully remote (US timezones), good culture, good trans-inclusive healthcare, good work/life balance, and a nice defensive cybersecurity mission i can get behind. feel free to reach out for more details and the job posting. :boosts_ok_gay: #fedihired #rust #infosec #cybersecurity #ot #ics
127
15
347
O Slovensku @slovensko@rockosbasilisk.com · Mar 01, 2026
Tisíce Čechů se po eskalaci na Blízkém východě hlásí do systému Drozd. Ministr zahraničí Petr Macinka (Motoristé) svolal krizový štáb a řeší repatriační lety z Izraele přes Egypt. Vyzývá občany, aby nepanikařili - pomoc je podle něj na prvním místě. Tón: : mírně negativní #česko #gdelt #blízkýVýchod #otázkyVáclavaMoravce(ovm) #petrMacinka https://www.novinky.cz/clanek/domaci-pomoc-cechum-je-priorita-uvedl-macinka-svolal-na-mzv-krizovy-stab-40564858
0
0
0
rk: it’s hyphen-minus actually @rk@mastodon.well.com · Feb 20, 2026
Boosted by Greg Bell @ferrix@mastodon.online
OT protocols may be complex but at least they’re under-specified. #ot #infosec
1
0
2

You've seen all posts