
IT / OT Security News
Headlines: 2025
13 October 2025
Critical infrastructure CISOs Can't Ignore 'Back-Office Clutter' Data
OT and ICS systems indeed hold the crown jewels of critical infrastructure organizations, but unmonitored data sprawl is proving to be pure gold for increasingly brazen nation-state threat actors like Volt Typhoon, Pearce argues.
2 October 2025
Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency
The European Union’s cybersecurity agency ENISA has published its 2025 Threat Landscape report, which shows that a significant percentage of the attacks aimed at the EU over the past year targeted operational technology (OT) systems.
30 September 2025
New Guidance Calls on OT Operators to Create Continually Updated System Inventory
Cybersecurity agencies in several countries have teamed up to create new guidance for operational technology (OT) organizations, specifically for building and maintaining a definitive view of their architecture.
1 September 2025
Lab Dookhtegan cyberattack on Iranian oil tankers traced to supply chain compromise of Fanava’s infrastructure
Following its March analysis of the Lab Dookhtegan cyberattack on Iranian oil tankers, Cydome released its ‘Second Wave Findings’ in August, a follow-up that filled in the missing details.
31 August 2025
Redefining industrial crown jewels in hyper-connected world as cyber-physical sabotage increases
The interconnected nature of organizational systems has made it more complicated to identify and protect industrial crown jewels, especially as nation-state hackers and state-sponsored adversaries attempt to breach such environments.
28 August 2025
China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years
The China-linked cyberespionage group known as Salt Typhoon has been compromising backbone and edge routers globally for persistent access to networks across multiple industries, government agencies in the US and allied countries warn.
21 August 2025
FBI warns of Russian hacks targeting US critical infrastructure
Hackers associated with some of Russia’s most prolific cyber espionage units have over the last year been leveraging a vulnerability in older Cisco software to target thousands of networking devices associated with critical infrastructure IT systems, the FBI and Cisco said on Wednesday.
17 August 2025
Social engineering becomes strategic threat as OT sector faces phishing, deepfakes, and AI deception risks
Growing use of social engineering capabilities by cyber adversaries across OT (operational technology) environments is driving a new class of high-consequence threats that threaten the stability of critical systems.
20 July 2025
Industrial cybersecurity redefined by regulatory pressure demanding visibility, governance, and harmonization
The ongoing momentum towards becoming and staying compliant would transform industrial cybersecurity, moving operators out of reactive checklists and into continual, systematic change.
27 June 2025
Critical ICS vulnerabilities threaten Mitsubishi Electric and TrendMakers hardware across commercial facilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released two industrial control systems (ICS) advisories highlighting hardware vulnerabilities in Mitsubishi Electric and TrendMakers equipment.
14 May 2025
Rogue communication devices found in Chinese solar power inverters
U.S. energy officials are reassessing the risk posed by Chinese-made devices that play a critical role in renewable energy infrastructure after unexplained communication equipment was found inside some of them, two people familiar with the matter said.
21 April 2025
Frenos warns OT sector of critical Erlang vulnerability enabling remote code execution affecting millions of devices
Frenos, a company specializing in autonomous OT security assessment platforms, has alerted OT (operational technology) security professionals to a major new vulnerability discovered in 2025.
18 April 2025
Resecurity warns of increased cyber threats to energy and nuclear facilities from hacktivists and nation-states
As a continuation of its earlier research report, Resecurity released new threat intelligence research highlighting threat actors targeting energy installations in North America, Asia, and the European Union, including nuclear facilities and related research entities.
1 March 2025
Weak cyber defenses are exposing critical infrastructure — how enterprises can proactively thwart cunning attackers to protect us all
Direct attacks on critical infrastructure get a lot of attention, but the bigger danger often lies in something less visible: The poor cybersecurity practices of the businesses that keep these systems running.
11 February 2025
Time to reimagine the CISO’s role as OT security takes center stage
Traditionally, chief information security officers (CISOs) concentrated on protecting digital data, corporate networks and IT environments. Meanwhile, operational technology (OT) systems — found in critical sectors such as manufacturing, energy and transportation — operated in isolation, prioritizing stability and continuity over cybersecurity.
30 January 2025
Backdoor found in two healthcare patient monitors, linked to IP in China
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient data to a remote IP address and downloads and executes files on the device.