ICS[AP] Dashboards are updated with the 5 (4 new & 1 update) CISA Advisories released on 5/8/25:
Horner Automation: 1 New
Hitachi Energy: 1 New | 1 Update
Mitsubishi Electric: 1 New
Pixmeo: 1 New
www.icsadvisoryproject.com
ICS[AP] Dashboards are updated with the 5 (4 new & 1 update) CISA Advisories released on 5/8/25:
Horner Automation: 1 New
Hitachi Energy: 1 New | 1 Update
Mitsubishi Electric: 1 New
Pixmeo: 1 New
www.icsadvisoryproject.com
We found unauthenticated remote code execution on an industrial PLC without ever touching the hardware.
By unpacking publicly available firmware for the KUNBUS Revolution Pi, our Adam Bromiley discovered four vulnerabilities. Two of them allowed RCE with no authentication required.
We dug into a misconfigured Node-RED instance, bypassed authentication in PiCtory, and chained bugs together to gain full control. This could affect safety-critical systems in the real world.
The upside? Disclosure was handled properly. KUNBUS and CISA coordinated the response well, and advisories and fixes for all four CVEs are now live.
Get the full breakdown and links to the advisories here: https://www.pentestpartners.com/security-blog/rces-and-more-in-the-kunbus-gmbh-revolution-pi-plc/
ICS[AP] Dashboards are updated with the 3 new CISA Advisories released on 5/6/25:
Optigo Networks: 1 New
Milesight: 1 New
BrightSign: 1 New
www.icsadvisoryproject.com
Safetybits Seamless #Compliance is a fresh approach to cybersecurity regulations that turns a chore into an ally in daily operations.
Helps you comply with security standards and regulations.
Continuous checks so you can act as soon as a new risks appear.
Uses multi-domain correlation to provide guidance through mitigation actions.
Reduces noise by documenting accepted risks.
And more! Discover it all in our blog:
https://safetybits.io/blog/introducing-seamless-compliance/
#cybersecurity #OTSecurity
Ever wondered how the first ever Open Security Conference was? Wonder no more!
Check out our past conferences for impressions: https://opensecurityconference.org/about/past-conferences/ and read our recap of #osco24: https://2024.opensecurityconference.org/conference/schedule
Enjoy and see you this year at #osco25!
#Cybersecurity #Security #InfoSec #AppSec #OTsecurity #OpenSpace [lisi]
A weekend full of physical security training #otsecurity
𝗡𝗲𝘂𝗲𝗿 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗝𝗼𝘂𝗿𝗻𝗮𝗹 – 𝗗𝗶𝗲 𝗔𝘂𝘀𝗴𝗮𝗯𝗲 𝗳𝘂̈𝗿 𝗔𝗽𝗿𝗶𝗹 𝗶𝘀𝘁 𝗱𝗮!
Unser Security Journal erscheint alle zwei Monate und bietet Ihnen tiefgehende Einblicke in die aktuelle Welt der Cybersicherheit!
In dieser Ausgabe haben wir wieder spannende Themen für dich:
𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆-𝗙𝗮𝗰𝗵𝗮𝗿𝘁𝗶𝗸𝗲𝗹 – diesmal zum Thema „CRA – Risiken und Chancen für KRITIS-Betreiber“
𝗡𝗲𝘄𝘀-𝗕𝗹𝗼𝗰𝗸 mit den wichtigsten Entwicklungen rund um die 𝗜𝗻𝗳𝗼𝗿𝗺𝗮𝘁𝗶𝗼𝗻𝘀𝘀𝗶𝗰𝗵𝗲𝗿𝗵𝗲𝗶𝘁
𝗧𝗼𝗽 𝟭𝟬 𝗱𝗲𝗿 𝗦𝗶𝗰𝗵𝗲𝗿𝗵𝗲𝗶𝘁𝘀𝗿𝗶𝘀𝗶𝗸𝗲𝗻 der letzten Monate
Ein Überblick über die wichtigsten 𝗜𝗖𝗦/𝗢𝗧 𝗦𝗰𝗵𝘄𝗮𝗰𝗵𝘀𝘁𝗲𝗹𝗹𝗲𝗻
Verpasse keine Ausgabe und bleib immer auf dem neuesten Stand, um die digitale Sicherheit zu stärken!
Jetzt anmelden: https://www.gai-netconsult.de/security-journal/
ICS[AP] Dashboards are updated with the 2 new CISA Advisories released on 5/1/25:
KUNBUS: 1 New
MicroDicom: 1 New
www.icsadvisoryproject.com
The #blackout on April 28 doesn’t seem to be the work of a cyberattack .
However, given the current geopolitical climate, the cause doesn’t matter to many.
Like a fire drill, this is the closest we’ve come to experiencing the effects of such an attack, and many have realized they are not ready for when the real thing comes.
ICS[AP] Dashboards are updated with the 3 (2 new & 1 updated) CISA Advisories released on 4/29/25:
Rockwell Automation: 1 New
Delta Electronics: 1 New
Lantronix: 1 Update
www.icsadvisoryproject.com
ICS[AP] Dashboards are updated with the 7 (4 new & 1 updated) CISA Advisories released on 4/24/25:
Schneider Electric: 1 New
ALBEDO Telecom: 1 New
Vestel: 1 New
Nice: 1 New
Johnson Controls Inc.: 1 New
Planet Technology: 1 New
Fuji Electric: 1 Update
www.icsadvisoryproject.com
ICS[AP] Dashboards are updated with the 5 (4 new & 1 updated) CISA Advisories released on 4/22/25:
Siemens: 2 New
Schneider Electric: 1 New | 1 Update
ABB: 1 New
www.icsadvisoryproject.com
The steps are simple:
- download the corresponding images;
- write the image to the drive, expand the filesystem;
- install the drive and start.
Then you have to configure your network and the old OT hardware can reliably do its job (incl. analysis/remote maintenance for soc/siem) for many years to come, including the possibility of updates either via network or USB stick. 3/3
The hardware was refurbished, including a quick analysis of the equipment. I quickly realized that modern and up-to-date network firewall firmware could be installed on both devices without much effort and high costs. Since #BSDRP , #OPNSense and #pfSense no longer support x86 (i586/i686) architectures, the choice fell on the current #OpenWrt and #DDWRT versions for x86 (i586/i686) architectures. 2/3
One of the key statements was as follows: “We no longer receive support for the OT network hardware and cannot simply replace it!” I asked for the manufacturer and type designation:
- Securepoint Black Dwarf V. 1.0 - CPU VIA Eden - 1 GB RAM
- Securepoint RC200 V. 1.1 - CPU Intel N270 - 1 GB RAM
I went on a shopping tour and, after the first test of the Securepoint RC200, experienced a real surprise (not funny). Back to the actual problem. 1/3
OT cybersecurity is officially a board-level issue.
Regulators are cracking down on companies that fail to secure critical infrastructure: Operational tech is now in the crosshairs
Most OT attacks start in IT networks
Poor segmentation = high risk
Legal & financial accountability is coming
Boards can’t afford to treat OT like an afterthought. The next breach won’t just be a tech failure — it’ll be a leadership failure.
#CyberSecurity #OTSecurity #BoardLeadership #Compliance #RiskManagement #security #privacy #cloud #infosec
https://www.darkreading.com/ics-ot-security/boards-fix-ot-security-regulators
ICS[AP] Dashboards are updated with the 6 CISA Advisories released on 4/17/25 for the following vendors:
Schneider Electric: 3 New | 2 Updated
Yokogawa: 1 New
www.icsadvisoryproject.com
Reserve the dates! The Open Security Conference takes place on 2-5 October 2025 in Rückersbach, close to Frankfurt/Main in Germany. We welcome everyone interested in #cybersecurity to learn and grow together at #osco. https://opensecurityconference.org/ #osco25 #InfoSec #AppSec #OTsecurity #security #OpenSpace [lisi]
LAST CALL – OT.SEC.CON IS TOMORROW!
Catch #OTsecurity expert, Paul Veeneman at tomorrow’s OT.SEC.CON event.
REGISTER HERE: https://www.accelevents.com/e/u/checkout/otseccon/tickets/order
TOPIC: Cybersecurity by Design: Building Resilience into Industrial Control Systems
ICS[AP] Dashboards are updated with the 9 new CISA Advisories released on 4/15/25:
Siemens: 3 New
Growatt: 1 New
Lantronix: 1 New
National Instruments Corp (NI): 1 New
Delta Electronics: 1 New
ABB: 1 New
Mitsubishi Electric Europe B.V.: 1 New
www.icsadvisoryproject.com