All CosmicBytez Labs articles tagged #OT Security, across news, security advisories, how-to guides, and projects.
Attackers penetrated the operational technology network of a Polish combined heat and power plant through the grid operator's private cellular network, successfully shutting down a steam turbine and water treatment systems serving roughly 50,000 residents.
ELECTRUM/Sandworm compromised a Polish heat-and-power plant serving 50,000 residents through a private cellular APN, marking the first recorded cyberattack on distributed energy resources.
Senators Schiff and Klobuchar introduce legislation directing $300 million per year to secure U.S. water and wastewater infrastructure following coordinated Iranian-linked attacks on municipal systems across 12 states.
A Black Hat USA 2026 presentation revealed that a 2024 safety recall covering 450,000 heavy trucks from Volvo, International, and Paccar secretly patched critical cybersecurity vulnerabilities — including a wireless remote code execution flaw in the Bendix EC80 brake controller.
A critical SQL injection vulnerability in PROCON-WEB SCADA's GetGridData endpoint allows unauthenticated remote attackers to execute arbitrary SQL commands against industrial control system databases.
A critical unauthenticated deserialization flaw in PTC's Windchill PLM platform is being actively weaponized by the Cl0p ransomware group, targeting aerospace, automotive, and manufacturing sectors.
Fairlife, the premium dairy brand owned by Coca-Cola, has suspended production at its U.S. facilities following a cyber incident. Plants in Michigan, New...
A critical CVSS 9.8 improper authentication vulnerability in Dassault Systèmes DELMIA Apriso (releases 2020–2026) allows unauthenticated attackers to gain...
California Water Service has confirmed that Iranian hacker group Handala's cyberattack was limited to IT systems, with Mandiant's investigation finding no...
Accenture's $4.1 billion acquisition of Dragos (valued at $3.25B), runZero, and NetRise marks the largest consolidation in operational technology...
Mackay Sugar, one of Australia's largest sugar producers, is working urgently to restore harvesting and milling operations after The Gentlemen ransomware...
Threat actors are actively targeting Internet-exposed Automatic Tank Gauges (ATGs) at US gas stations, exploiting decades-old unprotected interfaces to…
A CVSS 9.9 critical vulnerability in ABB T-MAC Plus v4.0-24 exposes internal files and directories to external parties, allowing unauthenticated attackers to…
A CVSS 9.1 critical command injection vulnerability in Honeywell's Control Network Module web interface allows remote attackers to execute arbitrary...
Claroty researchers have disclosed two vulnerabilities in the EnOcean SmartServer IQ building management controller that can be chained for security...
A critical authentication bypass in Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 allows unauthenticated remote attackers to...
Dragos and Mandiant report a 112% increase in cyberattacks targeting energy, water, and transportation systems in the first quarter of 2026, with...