Back to Feed

Tag

IoT/OT

IoT/OT security, industrial control systems, embedded devices

50 items tagged #iot-ot

Articles

‼️ M6Plus Proof of Concept (POC) CVE-2026-4583 (Missing Replay Protection) The M6PLUS Bluetooth...

M6PLUS Bluetooth protocol lacks replay protection; POC released for CVE-2026-4583.

Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

Masjesu botnet emerges as DDoS-for-hire service targeting IoT devices globally via Telegram.

Operation Masquerade: FBI Disrupts Russian Router Hacking Campaign

FBI disrupts Russian GRU campaign hijacking routers via DNS attacks for espionage.

Iranian Threat Actors Disrupt US Critical Infrastructure Via Exposed PLCs

Iranian threat actors disrupted US critical infrastructure by compromising exposed programmable logic controllers.

Evasive Masjesu DDoS Botnet Targets IoT Devices

Masjesu DDoS botnet targets IoT devices across Vietnam, Brazil, India, Iran, Kenya, and Ukraine.

US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking

US disrupts Russian APT28 espionage operation using hacked routers for DNS hijacking and AitM attacks.

Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs

Iran-linked hackers disrupt U.S. critical infrastructure by targeting internet-exposed PLCs.

> Be United States government > Say state-sponsored Iranian Threat Actors targeting PLCs &...

US government warns of Iranian state-sponsored threat actors targeting industrial PLCs.

Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks

Iran-linked hackers disrupt US critical infrastructure via PLC and SCADA attacks.

‼️ CVE-2026-28286: ZimaOS Privilege Escalation Vulnerability PoC: https://t.co/9p04Qud3BT A pri...

CVE-2026-28286 privilege escalation in ZimaOS allows API restriction bypass and unauthorized write access.

Iran-Linked Hackers Are Sabotaging US Energy and Water Infrastructure

Iran-linked hackers sabotage US energy and water infrastructure via compromised industrial control devices.

‼️ CVE-2026-23398: Linux Kernel ICMP DoS Vulnerability PoC: https://t.co/qD3Vo8jHAF

CVE-2026-23398 Linux kernel ICMP DoS vulnerability disclosed with public PoC.

‼️ The FBI has released a joint Cybersecurity Advisory on Iranian-Affiliated cyber actors exploit...

FBI releases joint advisory on Iranian cyber actors exploiting PLCs in US critical infrastructure.

US warns of Iranian hackers targeting critical infrastructure

US agencies warn of Iranian APT targeting internet-exposed industrial control systems.

Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn

Iranian APT actors breach U.S. energy and water infrastructure OT devices, disrupt PLCs.

🚨 The UK has exposed Russian military intelligence targeting vulnerable routers to support cyber...

UK NCSC exposes APT28 exploiting vulnerable routers for DNS hijacking operations.

Mitsubishi Electric GENESIS64 and ICONICS Suite products

Mitsubishi Electric GENESIS64 and ICONICS Suite store SQL credentials in plaintext, enabling local credential

We have found 2 WHQL-signed kernel drivers exposing arbitrary code execution via IOCTL on \Device...

Two WHQL-signed Windows kernel drivers found with arbitrary code execution vulnerability via IOCTL.

‼️ I have posted about this tool before, but this is a new forum post. A threat actor advertisin...

NFC RIPPER Android toolkit advertised for NFC relay attacks on payment terminals and ATMs.

Apple Breaks Precedent, Patches DarkSword for iOS 18

Apple releases security patch for DarkSword vulnerability affecting iOS 18.

Drift loses $280 million as hackers seize Security Council powers

Drift Protocol loses $280M after attacker gains Security Council admin control via multisig bypass.

US Bans All Foreign-Made Consumer Routers - Schneier on Security

US bans foreign-made consumer routers; new imports require FCC approval and disclosure of foreign influence.

Siemens SICAM 8 Products

Siemens SICAM 8 products vulnerable to DoS via resource exhaustion and XML parsing flaws.

Hitachi Energy Ellipse

Hitachi Energy Ellipse RCE vulnerability via Jasper Report deserialization flaw affects critical manufacturing systems

Yokogawa CENTUM VP

Yokogawa CENTUM VP contains hardcoded password vulnerability affecting manufacturing and energy sectors worldwide.

Sophisticated CrystalX RAT Emerges

CrystalX RAT, a sophisticated malware-as-a-service, emerges with spyware, stealer, and remote access capabilities.

PX4 Autopilot

Critical authentication bypass in PX4 Autopilot MAVLink protocol allows unauthenticated remote shell command execution.

Anritsu Remote Spectrum Monitor

Anritsu Remote Spectrum Monitor critical authentication bypass affecting all versions worldwide.

#Kimwolf v7: The updated #IoT #botnet behind record #DDoS attacks adds HTTP/2 floods with Chrome...

Kimwolf v7 botnet adds HTTP/2 floods, Chrome spoofing, Tor C2, and blockchain RPC endpoints.

‼️🇪🇸 The Spanish electricity company FENIE Energía has allegedly been completely hacked, with a...

Spanish electricity company FENIE Energía suffers major breach with 430GB database leaked after failed ransom

‼️A new Android Remote Administration Tool (RAT) called "Darkweb" is being sold on a popular cybe...

New Android RAT 'Darkweb' marketed on cybercrime forum as most powerful hacking tool.

TP-Link Patches High-Severity Router Vulnerabilities

TP-Link patches high-severity router vulnerabilities enabling auth bypass and arbitrary command execution.

We Are At War

Geopolitical tensions drive state-sponsored cyber operations targeting critical infrastructure globally.

CISA Flags Critical PTC Vulnerability That Had German Police Mobilized

CISA alerts to critical PTC Windchill deserialization flaw CVE-2026-4681 affecting PLM software.

OpenCode Systems OC Messaging and USSD Gateway

OpenCode Systems OC Messaging and USSD Gateway 6.32.2 contains improper access control vulnerability allowing

PTC Windchill Product Lifecycle Management

Critical RCE vulnerability in PTC Windchill and FlexPLM affects manufacturing sector globally.

Mirai Malware Evolves into Hundreds of Variants Driving Botnet Growth

Mirai malware evolves into 116+ variants, driving 24% botnet C2 server surge globally.

US Bans New Foreign-Made Home Routers Over National Security Fears

FCC bans new foreign-made home routers from US market citing national security and cyber espionage risks.

FCC Bans New Routers Made Outside the US Over National Security Risks

FCC bans new consumer routers made outside US citing national security risks.

TP-Link warns users to patch critical router auth bypass flaw

TP-Link patches critical authentication bypass in Archer NX routers allowing firmware upload

FCC bans new routers made outside the USA over security risks

FCC bans sales of new foreign-made consumer routers in US citing supply-chain and critical infrastructure risks.

Poland Faced a Surge in Cyberattacks in 2025, Including a Major Assault on the Energy Sector

Poland faced 270,000 cyberattacks in 2025, including destructive energy sector assault suspected from Russia.

Iran Built a Vast Camera Network to Control Dissent. Israel Turned It Into a Targeting Tool

Israel hijacked Iran's street cameras to track and kill Supreme Leader Khamenei in February.

Pharos Controls Mosaic Show Controller

CISA warns of critical unauthenticated RCE in Pharos Controls Mosaic Show Controller firmware 2.15.3.

Schneider Electric Plant iT/Brewmaxx

Schneider Electric Plant iT/Brewmaxx versions 9.60+ vulnerable to Redis flaws enabling RCE and DoS.

Schneider Electric EcoStruxure Foxboro DCS

Schneider Electric EcoStruxure Foxboro DCS deserialization flaw allows RCE via malicious project files.

Grassroots DICOM (GDCM)

Memory leak in Grassroots DICOM (GDCM) 3.2.2 allows denial-of-service via malformed files.

Your Body Is Betraying Your Right to Privacy

Biometric surveillance and smart device data collection expose Americans to privacy risks and police searches.

Gcore Radar report reveals 150% surge in DDoS attacks year-on-year

Gcore Radar reports 150% YoY surge in DDoS attacks with 12 Tbps peak volume in Q4 2025.

Routers Replace PCs as Primary Threat Vector in Evolving Device Risk Landscape

Forescout report shows routers now primary enterprise threat vector, surpassing PCs.