⤷ Title: Water System Cyberattacks: How Nation-State Hackers Turned Utilities Into Targets
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 03:59:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #CyberAv3ngers #ICS Security #Nation_State Hackers #Volt Typhoon #Water Systems
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 03:59:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #CyberAv3ngers #ICS Security #Nation_State Hackers #Volt Typhoon #Water Systems
Information Security News
Water System Cyberattacks: How Nation-State Hackers Turned Utilities Into Targets
With the arrival of digitalization, waterworks and treatment plants have become prime targets for APT hackers. Yet they are not random victims. Rather, attackers deliberately choose them as pressu…
⤷ Title: FBI and Spanish Police Arrest Alleged Cyber Army of Russia Reborn Member
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 23:14:24 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Cyber Army of Russia Reborn #Cyber Attack #Cybersecurity #DDOS #FBI #ICS #Operation Red Circus #Operation Riptide #Russia #Z_Pentest
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 23:14:24 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Cyber Army of Russia Reborn #Cyber Attack #Cybersecurity #DDOS #FBI #ICS #Operation Red Circus #Operation Riptide #Russia #Z_Pentest
Hackread
FBI and Spanish Police Arrest Alleged Cyber Army of Russia Reborn Member
Spanish police and the FBI arrested an alleged Cyber Army of Russia Reborn member as international efforts against pro Russia cyberattacks continue worldwide.
⤷ Title: WAGO System I/O Flaw CVE-2026-4769 Leads to Full System Compromise
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 07:54:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4769 #firmware #ICS security #OT Security #WAGO #WAGO System I/O
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 07:54:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4769 #firmware #ICS security #OT Security #WAGO #WAGO System I/O
Daily CyberSecurity
WAGO System I/O Flaw CVE-2026-4769 Leads to Full System Compromise
TL;DR A critical flaw in WAGO System I/O field devices now has a fix. Tracked as CVE-2026-4769, the bug scores 9.8 on CVSS. An unauthenticated attacker can reach full system compromise during earl…
⤷ Title: CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 07:32:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Control #ICS #OT Security #Rockwell Automation
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 07:32:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Control #ICS #OT Security #Rockwell Automation
Daily CyberSecurity
CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules
TL;DR A maximum-severity Rockwell Automation vulnerability, CVE-2026-10577, affects the 1715 Redundant I/O EtherNet/IP adapter (1715-AENTR). The access control flaw scores 10.0 on both CVSS 3.1 an…
⤷ Title: CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 12:53:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #ICS #JWT #Opcenter X #Siemens
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 12:53:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #ICS #JWT #Opcenter X #Siemens
Daily CyberSecurity
CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access
TL;DR Siemens has patched a maximum-severity Opcenter X authentication bypass, tracked as CVE-2026-56451. The flaw scores 10.0 on both CVSS 3.1 and CVSS 4.0 scales. An unauthenticated remote attac…
⤷ Title: Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 13:03:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA #Cleartext Credentials #CVE_2026_55985 #CVE_2026_61884 #ICS #OT Security #TPDIN_Monitor_WEB2 #Tycon Systems #unpatched
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 13:03:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA #Cleartext Credentials #CVE_2026_55985 #CVE_2026_61884 #ICS #OT Security #TPDIN_Monitor_WEB2 #Tycon Systems #unpatched
Daily CyberSecurity
Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8
TL;DR CISA published advisory ICSA-26-202-01 on July 21, 2026. It covers a critical Tycon authentication bypass in the TPDIN-Monitor-WEB2 power monitor. Tycon Systems never replied to CISA, so no …
⤷ Title: Iranian Hackers Modify PLC Logic in US Infrastructure Attacks
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:09:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA Advisory #Critical Infrastructure #ICS Security #Iranian hackers #PLC Hacking
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:09:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA Advisory #Critical Infrastructure #ICS Security #Iranian hackers #PLC Hacking
Information Security News
Iranian Hackers Modify PLC Logic in US Infrastructure Attacks
Covert Sabotage of Critical Infrastructure Iranian threat actors have developed sophisticated techniques to covertly manipulate programmable logic controllers (PLCs), ensuring that human operators…
⤷ Title: Panduit IntraVUE Vulnerability CVE-2026-42933 (CVSS 10) Bypasses OT Segmentation
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 14:02:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_28698 #CVE_2026_40430 #CVE_2026_42933 #ICS Advisory #OT Security #Panduit IntraVUE #Pronetiqs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 14:02:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_28698 #CVE_2026_40430 #CVE_2026_42933 #ICS Advisory #OT Security #Panduit IntraVUE #Pronetiqs
Daily CyberSecurity
Panduit IntraVUE Vulnerability CVE-2026-42933 (CVSS 10) Bypasses OT Segmentation
TL;DR CISA published ICS advisory ICSA-26-204-04 on July 23, 2026. It details five security bugs in Panduit IntraVUE, an industrial network monitoring platform built by Pronetiqs. The most severe …
⤷ Title: C-CURE 9000 Vulnerability CVE-2026-21655 Enables Remote Code Execution, CVE-2026-21653 Scores CVSS 9.6
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 14:29:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #C_CURE 9000 #CVE_2026_21653 #CVE_2026_21655 #CVE_2026_34496 #ICS Advisory #Johnson Controls #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 14:29:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #C_CURE 9000 #CVE_2026_21653 #CVE_2026_21655 #CVE_2026_34496 #ICS Advisory #Johnson Controls #Remote Code Execution
Daily CyberSecurity
C-CURE 9000 Vulnerability CVE-2026-21655 Enables Remote Code Execution, CVE-2026-21653 Scores CVSS 9.6
TL;DR CISA published ICS advisory ICSA-26-204-01 on July 23, 2026. It covers three flaws in Johnson Controls C-CURE 9000 and victor application servers. The most severe C-CURE 9000 vulnerability, …
⤷ Title: MicroLogix 1400 Attacks Lock Operators Out of Water Utility PLCs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 02:15:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ICS #MicroLogix 1400 #OT Security #PLC Security #Rockwell Automation #Water Utilities
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 02:15:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ICS #MicroLogix 1400 #OT Security #PLC Security #Rockwell Automation #Water Utilities
Daily CyberSecurity
MicroLogix 1400 Attacks Lock Operators Out of Water Utility PLCs
TL;DR Attackers are hijacking internet-exposed MicroLogix 1400 controllers at U.S. water utilities. They change device IP addresses and set unknown passwords, so operators lose their view of equip…
⤷ Title: [THM] — Kaboomm OT/ICS writeup
════════════════════════
𐀪 Author: Munpao
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 06:47:26 GMT
════════════════════════
⌗ Tags: #tryhackme #sto #ics_security
════════════════════════
𐀪 Author: Munpao
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 06:47:26 GMT
════════════════════════
⌗ Tags: #tryhackme #sto #ics_security
Medium
[THM] — Kaboomm OT/ICS writeup
Scann
⤷ Title: CVE-2026-58115: CVSS 10 Node-RED RCE Hits SIMATIC IoT2050
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 07:32:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_58115 #ICS security #Node_RED #Remote Code Execution #Siemens #SIMATIC IoT2050
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 07:32:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_58115 #ICS security #Node_RED #Remote Code Execution #Siemens #SIMATIC IoT2050
Daily CyberSecurity
CVE-2026-58115: CVSS 10 Node-RED RCE Hits SIMATIC IoT2050
TL;DR Siemens has disclosed CVE-2026-58115, a maximum-severity flaw in SIMATIC IoT2050 Advanced devices. The bug scores a perfect CVSS 10.0 and enables remote code execution through Node-RED. An u…
⤷ Title: CVE-2025-41771: SQL Injection Flaw Hits Phoenix Contact PLCnext
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 07:38:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_41769 #CVE_2025_41771 #ICS security #Phoenix Contact #PLCnext #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 07:38:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_41769 #CVE_2025_41771 #ICS security #Phoenix Contact #PLCnext #sql injection
Daily CyberSecurity
CVE-2025-41771: SQL Injection Flaw Hits Phoenix Contact PLCnext
TL;DR Phoenix Contact disclosed three vulnerabilities in PLCnext firmware on August 12, 2026. One flaw, CVE-2025-41771, lets a low-privileged attacker execute unauthorized SQL queries. A second, c…
⤷ Title: When the Database Isn’t Enough: Popping ScadaBR and Reading a PLC via Modbus TCP
════════════════════════
𐀪 Author: Michele Grimaldi
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 09:45:46 GMT
════════════════════════
⌗ Tags: #tryhackme #ics_security #penetration_testing #cybersecurity #ctf_writeup
════════════════════════
𐀪 Author: Michele Grimaldi
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 09:45:46 GMT
════════════════════════
⌗ Tags: #tryhackme #ics_security #penetration_testing #cybersecurity #ctf_writeup
Medium
When the Database Isn’t Enough: Popping ScadaBR and Reading a PLC via Modbus TCP
Writeup — ScadaBR CTF (TryHackMe, room: Brr)