top of page
man holding laptop in office

IT / OT Security News

Headlines: 2025

13 October 2025

Critical infrastructure CISOs Can't Ignore 'Back-Office Clutter' Data

OT and ICS systems indeed hold the crown jewels of critical infrastructure organizations, but unmonitored data sprawl is proving to be pure gold for increasingly brazen nation-state threat actors like Volt Typhoon, Pearce argues.

2 October 2025

Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency

The European Union’s cybersecurity agency ENISA has published its 2025 Threat Landscape report, which shows that a significant percentage of the attacks aimed at the EU over the past year targeted operational technology (OT) systems.

1 October 2025

NIST Publishes Guide for Protecting ICS Against USB-Borne Threats

NIST has published a new guide designed to help organizations reduce cybersecurity risks associated with the use of removable media devices in operational technology (OT) environments.

30 September 2025

New Guidance Calls on OT Operators to Create Continually Updated System Inventory

Cybersecurity agencies in several countries have teamed up to create new guidance for operational technology (OT) organizations, specifically for building and maintaining a definitive view of their architecture.

26 September 2025

No Patches for Vulnerabilities Allowing Cognex Industrial Camera Hacking

Some of the industrial cameras made by Cognex are affected by potentially serious vulnerabilities, but they will not receive a patch.

23 September 2025

Jaguar Land Rover Says Shutdown Will Continue Until at Least Oct 1 After Cyberattack

Jaguar Land Rover said Tuesday that its production lines, shut down after a cyberattack in August, will remain at a halt until at least Oct. 1.

19 September 2025

Unpatched Vulnerabilities Expose Novakon HMIs to Remote Hacking

Some of the industrial control system (ICS) products made by Taiwan-based Novakon are affected by serious vulnerabilities, and the vendor does not appear to have released any patches.

17 September 2025

Canadian Cybersecurity Network Releases Groundbreaking National Operational Technology (OT) Report on Risks to Canada's Critical Infrastructure

New research exposes vulnerabilities, talent gaps, and regulatory challenges threatening Canada’s OT resilience

16 September 2025

JLR's UK factory stoppage from cyber attack stretches to three weeks

Britain's largest carmaker, Jaguar Land Rover, said a pause in production due to a cyber attack would now stretch to September 24, extending the stoppage at its British plants to more than three weeks.

12 September 2025

DELMIA Factory Software Vulnerability Exploited in Attacks

Threat actors are exploiting a critical-severity vulnerability in DELMIA Apriso factory software, the US cybersecurity agency CISA warns.

10 September 2025

ICS Patch Tuesday: Rockwell Automation Leads With 8 Security Advisories

Several industrial control systems (ICS) giants have published new security advisories this Patch Tuesday, including Rockwell Automation, Siemens, Schneider Electric, and Phoenix Contact.

4 September 2025

US Offers $10 Million for Three Russian Energy Firm Hackers

The US Department of State this week announced rewards of up to $10 million for information on three Russian Federal Security Service (FSB) officers.

4 September 2025

Bridgestone Confirms Cyberattack Impacts Manufacturing Facilities Across North America

Tire manufacturer launches a comprehensive investigation after a limited cyber incident affects operations at multiple plants.

2 September 2025

Jaguar Land Rover manufacturing and retail ‘severely disrupted’ by cyber incident

Jaguar Land Rover’s manufacturing and retailing activities have been “severely disrupted” by a cyber incident, forcing it to shut down its systems.

1 September 2025

Lab Dookhtegan cyberattack on Iranian oil tankers traced to supply chain compromise of Fanava’s infrastructure

Following its March analysis of the Lab Dookhtegan cyberattack on Iranian oil tankers, Cydome released its ‘Second Wave Findings’ in August, a follow-up that filled in the missing details.

31 August 2025

Redefining industrial crown jewels in hyper-connected world as cyber-physical sabotage increases

The interconnected nature of organizational systems has made it more complicated to identify and protect industrial crown jewels, especially as nation-state hackers and state-sponsored adversaries attempt to breach such environments.

28 August 2025

China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years

The China-linked cyberespionage group known as Salt Typhoon has been compromising backbone and edge routers globally for persistent access to networks across multiple industries, government agencies in the US and allied countries warn.

21 August 2025

FBI warns of Russian hacks targeting US critical infrastructure

Hackers associated with some of Russia’s most prolific cyber espionage units have over the last year been leveraging a vulnerability in older Cisco software to target thousands of networking devices associated with critical infrastructure IT systems, the FBI and Cisco said on Wednesday.

17 August 2025

Social engineering becomes strategic threat as OT sector faces phishing, deepfakes, and AI deception risks

Growing use of social engineering capabilities by cyber adversaries across OT (operational technology) environments is driving a new class of high-consequence threats that threaten the stability of critical systems.

13 August 2025

Norwegian Police Say Pro-Russian Hackers Were Likely Behind Suspected Sabotage at a Dam

Russian hackers are likely behind suspected sabotage at a dam in Norway in April that affected water flows, police officials told Norwegian media on Wednesday.

12 August 2025

OT Networks Targeted in Widespread Exploitation of Erlang/OTP Vulnerability

An Erlang/OTP vulnerability whose existence came to light in mid-April has been exploited in the wild, with many attacks apparently targeting operational technology (OT) networks.

9 August 2025

Free Wi-Fi Leaves Buses Vulnerable to Remote Hacking

Researchers demonstrated that smart buses, the transportation vehicles that incorporate various systems to improve safety, efficiency, and passenger experience, can be remotely hacked.

7 August 2025

Why blow up satellites when you can just hack them?

Black Hat Four countries have now tested anti-satellite missiles (the US, China, Russia, and India), but it's much easier and cheaper just to hack them.

6 August 2025

Turning Camera Surveillance on its Axis

Digital surveillance is the cornerstone of modern facilities security, with video system deployments guarding enterprises, airports, schools, and government agencies.

1 August 2025

Remote exploits in Dahua Hero C1 smart cameras, prompting security patches to prevent full device takeover

Bitdefender researchers have uncovered critical security flaws in Dahua’s Hero C1 (DH-H4C) smart camera series.

30 July 2025

Bank Heist: Physical ATM Backdoor & Linux Forensic Evasion Evasion

Deep dive into UNC2891’s multi‑stage bank intrusion: Raspberry Pi ATM implant, bind mount evasion, Dynamic DNS C2, and a CAKETAP move toward HSM manipulation.

25 July 2025

No Patch for Flaw Exposing Hundreds of LG Cameras to Remote Hacking

LG Innotek LNV5110R security cameras are affected by a vulnerability that can be exploited for unauthenticated remote code execution.

20 July 2025

Industrial cybersecurity redefined by regulatory pressure demanding visibility, governance, and harmonization

The ongoing momentum towards becoming and staying compliant would transform industrial cybersecurity, moving operators out of reactive checklists and into continual, systematic change.

18 July 2025

Singapore Says Cyber Espionage Group Targeting Critical Infrastructure

Singapore said on Friday that it was responding to cyberattacks on its critical infrastructure by an espionage group alleged by security experts to be linked to China.

17 July 2025

Printer Security Gaps: A Broad, Leafy Avenue to Compromise

Security teams aren't patching firmware promptly, no one's vetting the endpoints before purchase, and visibility into potential dangers is limited — despite more and more cyberattackers targeting printers as a matter of course.

15 July 2025

Train Brakes Can Be Hacked Over Radio—And the Industry Knew for 20 Years

A vulnerability affecting systems named End-of-Train and Head-of-Train can be exploited by hackers to cause trains to brake.

9 July 2025

Canadian Electric Utility Says Power Meters Disrupted by Cyberattack

7 July 2025

NightEagle APT Attacking Industrial Systems by Exploiting 0-Days and With Adaptive Malware

3 July 2025

Russia jails man for 16 years over pro-Ukraine cyberattacks on critical infrastructure

1 July 2025

Iranian Hackers’ Preferred ICS Targets Left Open Amid Fresh US Attack Warning

The US government is again warning about potential Iranian cyberattacks as researchers find that hackers’ favorite ICS targets remain exposed.

1 July 2025

Lake Risevatnet dam hack exposes industrial cyber gaps as weak passwords risk critical infrastructure attacks

30 June 2025

With increasing IT/OT convergence, reacting to any cyber incident is already too late!

Especially in APAC, the fallout from cyber extortion and related threats is too severe for organizations to rely on reactive strategies.

27 June 2025

FDA Urges Medical Device Manufacturers to Improve OT Security

The U.S. Food and Drug Administration (FDA) is urging medical device manufacturers to ensure the security of connected operational technologies due to the increasing threat to manufacturing supply chains.

27 June 2025

Critical ICS vulnerabilities threaten Mitsubishi Electric and TrendMakers hardware across commercial facilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released two industrial control systems (ICS) advisories highlighting hardware vulnerabilities in Mitsubishi Electric and TrendMakers equipment.

25 June 2025

New Vulnerabilities Expose Millions of Brother Printers to Hacking

Rapid7 has found several serious vulnerabilities affecting over 700 printer models from Brother and other vendors.

25 June 2025

Risky Bulletin: Hackers breach Norwegian dam, open valve at full capacity

Unidentified hackers have breached the systems of a Norwegian dam and opened its water valve at full capacity in an incident this April.

23 June 2025

Israeli officials say Iran exploiting security cameras to guide missile strikes

Israeli officials are urging citizens to disconnect internet-connected security cameras, warning that Iran may be exploiting them to gather real-time intelligence and adjust missile targeting.

18 June 2025

Virtual Routes highlights Europe’s water systems under siege from cyber attacks, provides policy recommendations

A new report from Virtual Routes highlights that many critical infrastructure entities across Europe remain ill-prepared to defend against cyber threats.

13 June 2025

MISSION2025 cyber campaign expands global targeting of manufacturing, critical infrastructure

Cyfirma researchers this week profiled MISSION2025, a Chinese state-sponsored threat group tied to APT41.

12 June 2025

The ZTNA Blind Spot: Why Unmanaged Devices Threaten Your Hybrid Workforce

It’s time for enterprises to stop treating unmanaged devices as an edge case and start securing them as part of a unified Zero Trust strategy.

11 June 2025

ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, CISA

Industrial solutions providers Siemens, Schneider Electric and Aveva have released June 2025 Patch Tuesday ICS security advisories.

11 June 2025

40,000 Security Cameras Exposed to Remote Hacking

Bitsight has identified over 40,000 security cameras that can be easily hacked for spying or other types of malicious activity.

11 June 2025

Cyberattacks in manufacturing: What’s driving the trend?

Manufacturers are increasingly vulnerable to attacks amid a lack of specialized employee training and poor infrastructure, experts say.

5 June 2025

Misconfigured HMIs Expose US Water Systems to Anyone With a Browser

Censys researchers follow some clues and find hundreds of control-room dashboards for US water utilities on the public internet.

4 June 2025

35,000 Solar Power Systems Exposed to Internet

Researchers from Forescout have analyzed the prevalence of internet-exposed solar power devices and shared a list of the top vendors and devices.

4 June 2025

Mounting cyberattacks hit manufacturing, OT systems

Manufacturing organizations have been subjected to cyber intrusions from 71% more threat actors in 2024, compared with the previous year

3 June 2025

1,000 Instantel Industrial Monitoring Devices Possibly Exposed to Hacking

A critical command execution vulnerability has been found by a researcher in Instantel Micromate monitoring units.

30 May 2025

Critical Rockwell PowerMonitor 1000 vulnerabilities risk device takeover, raising industrial cybersecurity threat

New research from Claroty’s Team82 uncovered critical security vulnerabilities in the Allen-Bradley (Rockwell Automation) PowerMonitor 1000

22 May 2025

Russian hackers target Western firms shipping aid to Ukraine, US intelligence says

Hackers working for Russian military intelligence targeted Western technology and logistics companies involved in shipping assistance to Ukraine

21 May 2025

Critical Flaw Allows Remote Hacking of AutomationDirect Industrial Gateway

More than 100 AutomationDirect MB-Gateway devices may be vulnerable to attacks from the internet due to CVE-2025-36535.

14 May 2025

ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact

Industrial giants Siemens, Schneider Electric and Phoenix Contact have released ICS security advisories on the May 2025 Patch Tuesday.

14 May 2025

Rogue communication devices found in Chinese solar power inverters

U.S. energy officials are reassessing the risk posed by Chinese-made devices that play a critical role in renewable energy infrastructure after unexplained communication equipment was found inside some of them, two people familiar with the matter said.

13 May 2025

Do not let hackers halt your plant: Checklists for reviewing OT cyber resilience

Amid intensifying AI-boosted threats, industrial enterprises can review the following checklists to strengthen cybersecurity, ensure business continuity, and maintain cyber resilience.

13 May 2025

Spain investigates cyber weaknesses at small power plants after blackout, FT reports.

Senior government officials have “concerns” about the robustness of cyber defences at small and medium-sized power facilities, notably solar and wind farms...

13 May 2025

Spain investigating hacking link in blackout

Following a recent widespread blackout, Spain's cybersecurity agency is investigating the cyber defenses of smaller electricity generators, particularly renewable energy facilities.

7 May 2025

US Warns of Hackers Targeting ICS/SCADA at Oil and Gas Organizations

Agencies say the attacks leverage basic intrusion techniques, but poor cyber hygiene within critical infrastructure organizations could lead to disruptions and damage.

3 May 2025

Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and Malware

An Iranian state-sponsored threat group has been attributed to a long-term cyber intrusion aimed at a critical national infrastructure (CNI) in the Middle East that lasted nearly two years.

1 May 2025

Canadian Electric Utility Hit by Cyberattack

Nova Scotia Power and Emera are responding to a cybersecurity incident that impacted IT systems and networks.

24 April 2025

Cyberattack hits drinking water supplier in Spanish town near Barcelona

Aigües de Mataró, a Spanish water supplier responsible for both drinking water and sewage systems, announced on Wednesday that its corporate computer systems and website were hit by a cyberattack.

22 April 2025

Russia attempting cyber sabotage attacks against Dutch critical infrastructure

Russian state-sponsored hackers have attempted to sabotage Dutch critical infrastructure in attacks this year and last

21 April 2025

Lantronix Device Used in Critical Infrastructure Exposes Systems to Remote Hacking

Lantronix’s XPort device is affected by a critical vulnerability that can be used for takeover and disruption, including in the energy sector.

21 April 2025

Frenos warns OT sector of critical Erlang vulnerability enabling remote code execution affecting millions of devices

Frenos, a company specializing in autonomous OT security assessment platforms, has alerted OT (operational technology) security professionals to a major new vulnerability discovered in 2025.

20 April 2025

Countries shore up their digital defenses as global tensions raise the threat of cyberwarfare

Countries around the world are preparing for greater digital conflict as increasing global tensions.

18 April 2025

Resecurity warns of increased cyber threats to energy and nuclear facilities from hacktivists and nation-states

As a continuation of its earlier research report, Resecurity released new threat intelligence research highlighting threat actors targeting energy installations in North America, Asia, and the European Union, including nuclear facilities and related research entities.

14 April 2025

CyberAv3ngers: The Iranian Saboteurs Hacking Water and Gas Systems Worldwide

Despite their hacktivist front, CyberAv3ngers is a rare state-sponsored hacker group bent on putting industrial infrastructure at risk—and has already caused global disruption.

13 April 2025

Crosswalks in Silicon Valley hacked to play satirical messages from Musk and Zuckerberg sound-a-likes

City officials have disabled crosswalk voice announcement features, for now.

11 April 2025

China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report

In a secret meeting between Chinese and US officials, the former confirmed conducting cyberattacks on US infrastructure.

9 April 2025

ICS Patch Tuesday: Vulnerabilities Addressed by Rockwell, ABB, Siemens, Schneider

Industrial giants Siemens, Rockwell, Schneider and ABB have released their March 2025 Patch Tuesday ICS security advisories.

1 April 2025

Critical Vulnerability Found in Canon Printer Drivers

Microsoft’s offensive security team warned Canon about a critical code execution vulnerability in printer drivers.

28 March 2025

Critical Condition: Legacy Medical Devices Remain Easy Targets for Ransomware

Analysis found that 99% of healthcare organizations are vulnerable to publicly available exploits.

27 March 2025

More Solar System Vulnerabilities Expose Power Grids to Hacking

Forescout has found dozens of vulnerabilities in solar power systems from Sungrow, Growatt and SMA.

27 March 2025

New Sophisticated Linux-Backdoor Attacking OT Systems Exploiting 0-Day RCE

A sophisticated Linux-based backdoor dubbed “OrpaCrab” has emerged as a significant threat to operational technology (OT) systems.

26 March 2025

Vulnerabilities Allow Remote Hacking of Inaba Plant Monitoring Cameras

Production line monitoring cameras made by Inaba can be hacked for surveillance and sabotage, but they remain unpatched.

26 March 2025

New Sophisticated Linux Backdoor Targets OT Systems via 0-Day RCE Exploit

Researchers at QiAnXin XLab have uncovered a sophisticated Linux-based backdoor dubbed OrpaCrab

25 March 2025

Ransomware Shifts Tactics as Payouts Drop: Critical Infrastructure in the Crosshairs

Threats themselves change very little, but the tactics used are continually revised to maximize the criminals’ return on investment and effort.

12 March 2025

China’s Volt Typhoon Hackers Dwelled in US Electric Grid for 300 Days

ICS/OT security firm Dragos on Wednesday published a case study describing an intrusion attributed to the notorious Chinese threat actor Volt Typhoon into the US electric grid.

5 March 2025

Organizations Still Not Patching OT Due to Disruption Concerns: Survey

Cyber-physical systems security company TXOne Networks has published its 2024 Annual OT/ICS Cybersecurity Report.

5 March 2025

Camera off: Akira deploys ransomware via webcam

In this article, our team details how Akira was able to compromise an unsecured webcam in order to circumvent an Endpoint Detection and Response (EDR) tool and deploy ransomware.

4 March 2025

ICS/OT Security Budgets Increasing, but Critical Areas Underfunded: Report

The SANS Institute and OPSWAT on Tuesday published the 2025 ICS/OT Cybersecurity Budget Report.

1 March 2025

Weak cyber defenses are exposing critical infrastructure — how enterprises can proactively thwart cunning attackers to protect us all

Direct attacks on critical infrastructure get a lot of attention, but the bigger danger often lies in something less visible: The poor cybersecurity practices of the businesses that keep these systems running.

28 February 2025

Report Reveals Wireless Networks Remain Exposed to Cyber Attacks

Cybersecurity company Nozomi Networks has released its latest OT and IoT security report, OT/IoT Cybersecurity Trends and Insights, February 2025.

25 February 2025

Nine Threat Groups Active in OT Operations in 2024: Dragos

Industrial cybersecurity company Dragos on Tuesday published its 2025 OT/ICS Cybersecurity Report, which provides insights on the threat activity and trends observed last year.

12 February 2025

Nation-StateRussian Seashell Blizzard Hackers Have Access to Critical Infrastructure: Microsoft

A subgroup of the Russia-linked Seashell Blizzard is tasked with broad initial access operations to sustain long-term persistence.

11 February 2025

Time to reimagine the CISO’s role as OT security takes center stage

Traditionally, chief information security officers (CISOs) concentrated on protecting digital data, corporate networks and IT environments. Meanwhile, operational technology (OT) systems — found in critical sectors such as manufacturing, energy and transportation — operated in isolation, prioritizing stability and continuity over cybersecurity.

4 February 2025

Contec Patient Monitors Not Malicious, but Still Pose Big Risk to Healthcare

The Contec CMS8000 patient monitors do not contain a malicious backdoor but are plagued by an insecure and vulnerable design.

30 January 2025

Backdoor found in two healthcare patient monitors, linked to IP in China

The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient data to a remote IP address and downloads and executes files on the device.

27 January 2025

Building Automation Protocols Increasingly Targeted in OT Attacks: Report

Industrial automation protocols continue to be the most targeted in OT attacks, but building automation systems have been increasingly targeted.

15 January 2025

The High-Stakes Disconnect For ICS/OT Security

Why does ICS/OT need specific controls and its own cybersecurity budget today? Because treating ICS/OT security with an IT security playbook isn't just ineffective—it's high risk.

15 January 2025

ICS Patch Tuesday: Security Advisories Published by Schneider, Siemens, Phoenix Contact, CISA

Schneider Electric, Siemens, CISA, and Phoenix Contact have released January 2025 Patch Tuesday ICS security advisories.

14 January 2025

Western Security Agencies Share Advice on Selecting OT Products

CISA and other Western security agencies have shared guidance for OT owners and operators when procuring products.

8 January 2025

Cyber Threats Rising: US Critical Infrastructure Under Increasing Attack in 2025

As we enter 2025, the frequency and sophistication of cyberattacks on critical national infrastructure (CNI) in the US are rising at an alarming rate.

bottom of page