CVE-2026-16462 is a critical SQL injection in Weidmueller PROCON-WEB SCADA, rated CVSS 9.8. An unauthenticated attacker can run SQL commands. Patch now.
#PROCONWEB #Weidmueller #CVE202616462 #SQLInjection #SCADA #CyberSecurity
https://securityonline.info/procon-web-scada-cve-2026-16462/?utm_source=mastodon&utm_medium=jetpack_social
About This Hashtag
#scada
5 posts
Last used Aug 03
#scada
5 posts· Last used Aug 03
A coordinated cyberattack disrupted Minnesota water systems across 30 municipalities, targeting critical infrastructure and cellular equipment.
#Cybersecurity #CriticalInfrastructure #WaterSecurity #Minnesota #SCADA
https://meterpreter.org/minnesota-water-systems-cyberattack/?utm_source=mastodon&utm_medium=jetpack_social
🚨 BREAKING: A coordinated cyberattack targeted 30+ community water systems across Minnesota, disrupting operational technology (OT) and temporarily taking one treatment plant offline.
State and federal agencies, including CISA, FBI, and EPA, are investigating. Officials say there is no evidence that drinking water quality was compromised, and the attack has not yet been attributed to any threat actor.
Full analysis, technical breakdown, and what this means for critical infrastructure security:
🔗 https://thecybersecguru.com/news/minnesota-water-systems-cyberattack-ot/
#CyberSecurity #OTSecurity #ICS #SCADA #CriticalInfrastructure #WaterSecurity #CyberAttack #ThreatIntel #CISA #InfoSec
Hack like Mr Robot // WiFi, Bluetooth and Scada hacking
OccupytheWeb explains how hacks shown in the Mr Robot TV Series actually work. He compares real world WiFi, Bluetooth and Scada hacking vs what is shown in the TV series.
https://www.youtube.com/watch?v=3yiT_WMlosg
#youtube #wifi #bluetooth #scada #ics #infosec #cybersecurity #hacking
Came across a disclosure in Altus BluePlant 9.1.40 — a SCADA HMI / ICS platform. CVSS 9.8, unauthenticated RCE, default configuration, as the service account (administrator).
The standout: the vendor's auth validator hardcodes three credential-bypass paths in code. Use any one to bypass Connect, get a connectionHandle, then drive a generic RMI gateway to FileServer.RunProcess → Process.Start. No creds, no TLS, port 3100 reachable by default after install.
Full root-cause + self-contained PoC on the advisory page.
https://0day-rubbish.com/blog/altus-blueplant-hardcoded-creds-rce
https://github.com/Exploit-Garbage/0day-Rubbish
The project attributes discovery to an automated multi-LLM process (Claude/OpenAI/DeepSeek/GLM), defensive framing, full-disclosure posture. Not affiliated; noting for awareness.
#infosec #ICS #SCADA #OTsecurity #vulnerability #0day #RCE #exploit
You've seen all posts