Skip to content
feed: live
>_ 0dayNews
Vendor

ICS / OT

Vulnerabilities and intrusions affecting industrial control systems, SCADA, PLCs, and the operational-technology stack — plus the wider "physical-layer" surface of firmware in embedded devices and covert channels against air-gapped machines. Where a bug can mean a plant trip, not just a data breach.

Articles
~/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine
AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes
ics ot

AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes

AIVD and MIVD say Russian intel is hijacking exposed IP cameras across EU, NATO states, and Ukraine to watch military convoys and weapons shipments to Kyiv.

read →
~/articles/2026-07-15-knx-cve-2023-4346-cisa-kev-account-lockout-bod-26-04
KNX account-lockout flaw added to CISA KEV, three years on
ics ot

KNX account-lockout flaw added to CISA KEV, three years on

CVE-2023-4346 turns the KNX Association's account-lockout mechanism into a device-purge weapon on a building-automation bus. CISA added it to KEV under BOD 26-04.

read →
~/articles/2026-07-13-fsb-centre-16-cve-2018-0171-router-hygiene-csa
Seven years on, CVE-2018-0171 draws a 13-state advisory
ics ot

Seven years on, CVE-2018-0171 draws a 13-state advisory

US, UK, and eleven allied governments co-signed a July 13 advisory naming FSB Centre 16 as the actor still pulling configs off end-of-life Cisco routers via CVE-2018-0171.

read →
~/articles/2026-07-11-u-boot-libfdt-fit-parsing-six-brly-flaws
Six U-Boot flaws trace to one libfdt helper
ics ot

Six U-Boot flaws trace to one libfdt helper

Binarly disclosed six bugs in U-Boot's FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.

read →
~/articles/2026-07-09-talos-vdr-wolfssl-geovision-vtk-dicom-disclosure
Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM
ics ot

Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM

Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.

read →
~/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched
Tenda Router Backdoor Has No Patch. Here's What to Do.
ics ot

Tenda Router Backdoor Has No Patch. Here's What to Do.

CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn't respond. No fix is coming — here's the mitigation.

read →
~/articles/2026-07-06-trojpix-air-gap-video-cable-emanation-shandong
TrojPix: air-gap exfil via video-cable RF emanation
Analysis
ics ot

TrojPix: air-gap exfil via video-cable RF emanation

Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.

read →
~/articles/2026-07-04-armored-likho-busysnake-power-sector-kaspersky
Armored Likho Ties BusySnake to Power-Sector Spying
ics ot

Armored Likho Ties BusySnake to Power-Sector Spying

Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.

read →