Back to Feed

Tag

IoT/OT

IoT/OT security, industrial control systems, embedded devices

50 items tagged #iot-ot

Articles

RondoDox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers

RondoDox botnet exploits 2018 ASUS router vulnerability to hijack over 1 million devices.

ABB B&R Automation Runtime

ABB B&R Automation Runtime <6.4 patched for session hijacking, XSS, and CSV injection flaws.

Hitachi Energy GMS600

Hitachi Energy GMS600 versions 1.3.0–1.3.1 vulnerable to OpenSSL timing attack (CVE-2022-4304)

ABB Terra AC Wallbox

ABB Terra AC Wallbox EV charger has three buffer overflow vulnerabilities affecting firmware versions ≤1.8.33.

Siemens SENTRON 7KT PAC1261 Data Manager

Siemens SENTRON 7KT PAC1261 Data Manager HTTP request smuggling flaw allows admin token theft

Siemens Solid Edge

Siemens Solid Edge SE2026 before Update 5 has two file parsing vulnerabilities in PAR format handling.

Siemens SIMATIC

Siemens SIMATIC HMI Unified Comfort Panels before V21.0 vulnerable to unauthenticated web browser access via help link.

Siemens Ruggedcom Rox

Siemens Ruggedcom Rox OS command injection vulnerability allows authenticated RCE with root privileges.

Universal Robots Polyscope 5

Critical OS command injection in Universal Robots Polyscope 5 allows unauthenticated remote code execution.

Siemens Simcenter Femap

Siemens Simcenter Femap heap buffer overflow in Datakit library allows RCE via malicious IPT files

Siemens gWAP

Siemens gWAP RCE vulnerability via Axios library prototype pollution gadget chain

Siemens Siemens ROS#

Siemens ROS# path traversal vulnerability (CVE-2026-41551) allows arbitrary file access in versions before 2.2.2.

Siemens Teamcenter

Siemens Teamcenter affected by multiple critical vulnerabilities including XSS, hardcoded credentials, and PDF.js flaw.

Siemens Industrial Devices

Siemens industrial devices contain null pointer dereference vulnerability enabling denial of service via crafted IPv4

Siemens Ruggedcom Rox

Siemens Ruggedcom Rox improper access control flaw allows authenticated remote file read with root privileges

Siemens Opcenter RDnL

Siemens Opcenter RDnL affected by missing authentication in ActiveMQ Artemis (CVE-2026-27446)

Siemens SIPROTEC 5

Siemens SIPROTEC 5 uses weak session IDs vulnerable to brute-force hijacking attacks

Siemens Ruggedcom Rox

Siemens Ruggedcom Rox input validation flaw allows authenticated RCE with root privileges.

Siemens SIMATIC S7 PLC Web Server

Siemens SIMATIC S7 PLC web servers contain multiple XSS vulnerabilities requiring urgent patching.

CI Fortify | CISA

CISA launches CI Fortify initiative urging critical infrastructure operators to prepare for geopolitical conflict

ICS Patch Tuesday: New Security Advisories From Siemens, Schneider, CISA

Siemens, Schneider Electric, and CISA publish May 2026 Patch Tuesday advisories for ICS vulnerabilities.

Subnet Solutions PowerSYSTEM Center

Subnet Solutions PowerSYSTEM Center CRLF injection vulnerability affects multiple versions

ABB Automation Builder Gateway for Windows

ABB Automation Builder Gateway for Windows exposes PLC networks via insecure default remote access on port 1217.

ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities

ABB WebPro SNMP Card PowerValue contains three critical vulnerabilities enabling authentication bypass and DoS attacks.

ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax

ABB AC500 V3 PLC critical stack buffer overflow in CMS cryptographic parsing (CVE-2025-15467)

Fuji Electric Tellus

Fuji Electric Tellus 5.0.2 kernel driver flaw allows local privilege escalation (CVE-2026-8108)

ABB AC500 V3 Multiple Vulnerabilities

ABB AC500 V3 PLCs patched for three critical vulnerabilities enabling auth bypass, cert theft, and DoS

Cyber Espionage Group Targets Aviation Firms to Steal Map Data

Cyber espionage group targets aviation firms to steal geospatial and GPS data.

MAXHUB Pivot Client Application

MAXHUB Pivot client application CVE-2026-6411 uses hardcoded AES key allowing email disclosure

Why Outdated Maintenance Software Is a Growing Ransomware Risk

Outdated maintenance software exposes companies to ransomware via weak access controls and unpatched systems.

Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion

Threat actors used Claude AI to guide attack on Mexican water utility's OT systems in January 2026.

Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks

New Mirai-derived xlabs_v1 botnet exploits exposed ADB to hijack IoT devices for DDoS attacks.

Rowhammer Attack Against NVIDIA Chips https://t.co/xYv2kEnOHD

Researchers demonstrate Rowhammer attack against NVIDIA GPU chips.

CISA: Critical Infrastructure Must Master Isolation, Recovery

CISA issues CI Fortify guidance for critical infrastructure to master isolation and recovery against nation-state

CVE-2026-0073: Zero-Click RCE Flaw in Android's Wireless ADB Bypasses Authentication https://t.c...

CVE-2026-0073 zero-click RCE in Android Wireless ADB bypasses authentication.

CI Fortify | CISA

CISA launches CI Fortify initiative urging critical infrastructure operators to prepare for geopolitical conflict

ABB B&R Automation Studio

ABB B&R Automation Studio certificate validation flaw allows server spoofing.

Johnson Controls CEM AC2000

Johnson Controls CEM AC2000 DLL hijacking vulnerability (CVE-2026-21661) allows privilege escalation across multiple

ABB B&R PVI

ABB B&R PVI vulnerability allows authenticated local attackers to read credentials from client logs.

Hitachi Energy PCM600

Hitachi Energy PCM600 path traversal vulnerability (Zip-Slip) affects energy infrastructure worldwide.

ABB B&R Automation Runtime

ABB B&R Automation Runtime DoS vulnerability (CVE-2025-11044) in ANSL-Server component patched.

New AirSnitch attack techniques target the Wi-Fi infrastructure itself. We show how attackers can...

AirSnitch attack techniques enable packet interception and injection on Wi-Fi infrastructure, bypassing encryption.

‼️ Interesting claim... A threat actor operating under the alias paws is selling root-level remot...

Threat actor 'paws' offers root RCE access to compromised Linux firewall for $1,500 in Monero.

Anti-DDoS Firm Heaped Attacks on Brazilian ISPs

Brazilian DDoS protection firm's infrastructure breached, enabling botnet attacks on ISPs.

ABB AWIN Gateways

ABB AWIN Gateways contain three high-severity authentication bypass flaws affecting critical manufacturing

ABB PCM600

ABB PCM600 path traversal vulnerability allows arbitrary code execution via crafted messages.

ABB Ability OPTIMAX

ABB Ability OPTIMAX authentication bypass vulnerability in Azure AD SSO integration.

ABB System 800xA, Symphony Plus IEC 61850

CVE-2025-3756 in ABB System 800xA and Symphony Plus IEC 61850 allows DoS via crafted packets.

ABB Ability Symphony Plus Engineering

ABB Ability Symphony Plus Engineering affected by four high-severity PostgreSQL vulnerabilities enabling arbitrary code

ABB Edgenius Management Portal

Critical authentication bypass in ABB Edgenius Management Portal allows arbitrary code execution.