All CosmicBytez Labs articles tagged #ICS, across news, security advisories, how-to guides, and projects.
Critical OS command injection via the HTTP Basic Auth username lets unauthenticated attackers run root commands on Weidmueller security routers.
Attackers penetrated the operational technology network of a Polish combined heat and power plant through the grid operator's private cellular network, successfully shutting down a steam turbine and water treatment systems serving roughly 50,000 residents.
A Black Hat USA 2026 presentation revealed that a 2024 safety recall covering 450,000 heavy trucks from Volvo, International, and Paccar secretly patched critical cybersecurity vulnerabilities — including a wireless remote code execution flaw in the Bendix EC80 brake controller.
Incorrect access control in the Executive Services component of NASA cFS v7.0.1 allows attackers to execute arbitrary code by placing a malicious shared object on target storage. CVSS score 9.1.
Thermo Fisher Scientific has patched a vulnerability in Applied Biosystems human identification software that could allow .fsa and .hid forensic DNA output files to be altered before analysis, with changes that are nearly impossible to detect.
A critical SQL injection vulnerability in PROCON-WEB SCADA's GetGridData endpoint allows unauthenticated remote attackers to execute arbitrary SQL commands against industrial control system databases.
A critical unauthenticated deserialization flaw in PTC's Windchill PLM platform is being actively weaponized by the Cl0p ransomware group, targeting aerospace, automotive, and manufacturing sectors.
Eclipse BaSyx Go Components up to v1.0.0 contains a CVSS 9.8 authorization bypass caused by inconsistent trailing-slash handling between the ABAC...
A critical authentication bypass in the Tycon Systems TPDIN-Monitor-WEB2 web interface allows unauthenticated remote attackers to gain full administrative...
This week's security roundup covers an AI-prioritizing infostealer targeting developer machines, a hardcoded Bluetooth key in 2.2 million car anti-theft...
A critical integer truncation vulnerability in OpENer 2.3.0 allows network attackers to trigger heap corruption or denial of service by sending malformed...
A critical out-of-bounds read vulnerability in OpENer 2.3.0 allows unauthenticated attackers to crash industrial EtherNet/IP devices by sending malformed...
A critical access control vulnerability in OpENer 2.3.0 allows unauthenticated attackers to send privileged encapsulation commands using arbitrary session...
A critical CVSS 9.8 improper authentication vulnerability in Dassault Systèmes DELMIA Apriso (releases 2020–2026) allows unauthenticated attackers to gain...
Critical path traversal vulnerability (CVSS 9.1) in Apache IoTDB affects versions 1.0.0 through 1.3.5 and 2.0.0 through 2.0.5. Users must upgrade...
A second critical path traversal vulnerability (CVSS 9.1) in Apache IoTDB affects versions 1.0.0 through 1.3.5 and 2.0.0 through 2.0.6. Patch to 1.3.6 or...
CISA has added CVE-2026-12569, a critical remote code execution vulnerability in PTC Windchill PDMlink and FlexPLM, to its Known Exploited Vulnerabilities...
CISA has added CVE-2026-12569, a remote code execution flaw in PTC Windchill, to its Known Exploited Vulnerabilities catalog after confirming active...
California Water Service has confirmed that Iranian hacker group Handala's cyberattack was limited to IT systems, with Mandiant's investigation finding no...
Accenture's $4.1 billion acquisition of Dragos (valued at $3.25B), runZero, and NetRise marks the largest consolidation in operational technology...
A CVSS 9.8 authentication bypass in Nefteprodukttekhnika's BUK TS-G Gas Station Automation System allows any unauthenticated attacker to gain full...
A critical CVSS 9.8 vulnerability in a local MQTT broker fails to enforce topic-level ACLs, allowing any client to use wildcard characters to enumerate hidden…
A CVSS 9.1 critical command injection vulnerability in Honeywell's Control Network Module web interface allows remote attackers to execute arbitrary...
This week's ThreatsDay threat roundup covers Microsoft Edge storing passwords in plaintext, industrial control system zero-days under active exploitation,...
A critical vulnerability in a programmable logic controller allows unauthenticated network attackers to brute force weak passwords and gain full...
A critical authentication bypass in Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 allows unauthenticated remote attackers to...
A critical CVSS 9.8 vulnerability in the MAVLink drone communication protocol allows unauthenticated attackers to send arbitrary SERIAL_CONTROL commands —...
Dragos and Mandiant report a 112% increase in cyberattacks targeting energy, water, and transportation systems in the first quarter of 2026, with...