Rockwell Automation · GuardLogix 5580
Safety task tampering via CIP.
43 advisory aktif dari vendor (Siemens, Schneider, Rockwell, ABB, Honeywell), pemerintah (CISA, BSI), dan CERT regional. Setiap advisory tertaut ke sumber resminya.
Safety task tampering via CIP.
DoS via crafted Modbus packet.
Privilege escalation service account.
RCE pada drive web interface.
Cleartext credential channel diagnostik.
Auth bypass HTTP REST API.
Authentication bypass web management.
Stack overflow EtherNet/IP parser.
Improper auth pada engineering interface SIS.
Buffer overflow web server onboard.
Path traversal historian.
Stored XSS HMI web access.
Aktivitas aktif CyberAv3ngers terhadap PLC Unitronics & Vision.
Penyalahgunaan tool remote support vendor di pabrik Jepang.
Aktivitas Sandworm meningkat menjelang exercise NATO.
Kampanye Sandworm baru menargetkan ICCP/IEC-104.
Auth bypass via SLMP.
Aktivitas aktif aktor pro-state terhadap PLC water terbuka di internet.
Pre-auth RCE pada engineering web service relay proteksi.
Hardcoded credentials service account.
Command injection CLI management.
RCE pada drive web interface.
Tampering safety task via Modbus/UMAS tanpa otentikasi.
Heap overflow di parser EtherNet/IP memungkinkan crash/PRC.
Joint advisory: aktor PRC mengeksploitasi appliance edge untuk persistence pre-positioning.
Safety task tampering via CIP.
Local privilege escalation via DLL hijack.
RCE via project file parsing.
Auth bypass admin web interface industrial firewall.
Buffer overflow di CIP message handler.
DoS via crafted EtherNet/IP.
Auth bypass engineering protocol pada SIS.
Improper auth pada engineering interface SIS.
Auth bypass di web mgmt PLC; eksploitasi aktif diobservasi.
Volt/Voltzite recon terhadap IEC-104 RTU US utility.
SSL VPN heap overflow di firewall ruggedized.
Ransomware DragonForce/Akira meningkat menyerang Tier-1/2 auto supplier.
Cert validation bypass pada chain custom.
Default password Unitronics terus dieksploitasi aktor Iran-linked di water utility.
Qilin & RansomHub aktif menyerang lab & rumah sakit global.
Command injection di IOS-XE web UI switch industrial.
Remote root via SNMPv3 di router substation.
Spike eksploitasi HMI water utility yang exposed ke internet.