#ics
ICSパッチチューズデー:Siemens、Rockwell、Aveva、Schneiderによる脆弱性対応

産業大手のSiemens、Schneider Electric、Rockwell Automation、Avevaは、ICS/OT製品における脆弱性について顧客に通知するパッチチューズデーのアドバイザリを公開しました。 Siemensは新たに6件のアドバイザリを公開しました。そのうちの1件は、Comosプラントエンジニアリングソフトウェアにおける2件の脆弱性(重大なコード実行の欠陥と高深刻度のセキュリティバイパス問題)を対象としています。 また、Siemens Solid…
ICSパッチチューズデー:Siemens、Rockwell、Aveva、Schneiderによる脆弱性対応
産業大手のSiemens、Schneider Electric、Rockwell Automation、Avevaは、ICS/OT製品における脆弱性について顧客に通知するパッチチューズデーのアドバイザリを公開しました。 Siemensは新たに6件のアドバイザリを公開しました。そのうちの1件は、Comosプラントエンジニアリングソフトウェアにおける2件の脆弱性(重大なコード実行の欠陥と高深刻度のセキュリティバイパス問題)を対象としています。 また、Siemens Solid Edge(リモートMitM、コード実行)、Altair Grid Engine(コード実行)、Logo! 8 BM(コード実行、DoS、設定改ざん)、Sicam P850(CSRF)製品の脆弱性にも対応しました。 Rockwell Automationは11月11日に新たに5件のアドバイザリを公開し、各アドバイザリはさまざまな製品で発見された高深刻度の脆弱性を対象としています。 同社はVerve Asset Manager OTセキュリティプラットフォームの顧客に対し、APIを通じて認可されていない読み取り専用ユーザーが他のユーザーアカウントを改ざんできる高深刻度のアクセス制御問題があることを通知しました。 Logix 5000コントローラー向けStudio 5000統合設計環境では、NTLMハッシュが漏洩するSSRFの欠陥とローカルコード実行のバグが修正されました。 FactoryTalk DataMosaix Private CloudではMFAバイパスと永続的なXSSの脆弱性が修正されました。また、サードパーティ製コンポーネントの使用によって導入された欠陥がSIS Workstation(コード実行)およびFactoryTalk Policy Manager(DoS)で修正されています。 Avevaは火曜日に新たに2件のアドバイザリを公開しました。そのうちの1件は、権限昇格に悪用可能な高深刻度の永続的XSSの欠陥について説明しています。 広告。スクロールして続きをお読みください。 2件目のアドバイザリは、プロジェクトおよびキャッシュファイルへの読み取りアクセス権を持つ攻撃者が、弱いハッシュを総当たりで解読することでユーザーパスワードを取得できるAveva Edgeの脆弱性を対象としています。 この脆弱性はSchneider ElectricのEcoStruxure Machine SCADA ExpertおよびPro-face BLUE Open Studio製品にも影響します。Schneiderは今回のパッチチューズデーで新たに2件のアドバイザリを公開し、そのうち1件がこの欠陥の影響を説明しています。 Schneiderの2件目のアドバイザリは、PowerChute Serial Shutdown UPS管理ソフトウェアにおける高深刻度のパストラバーサル、認証総当たり攻撃、権限昇格の問題について説明しています。 Moxa、ABB、Honeywell、三菱電機はパッチチューズデーにアドバイザリを公開しませんでしたが、直前の日々に修正済みの脆弱性について顧客に通知しています。ドイツのVDE@CERTも最近2件のアドバイザリを公開しました。 翻訳元:
blackhatnews.tokyo
November 12, 2025 at 8:09 AM
ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider An Aveva vulnerability also impacts Schneider Electric products and both vendors have published advisories. The p...

#ICSref="/hashtag/ICS%2FOT" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#ICS/OT #ICS #ICS #Patch #Tuesday

Origin | Interest | Match
Awakari App
awakari.com
November 12, 2025 at 8:40 AM
New report 'Repositioning Brazil as a Global Hub for Climate Solutions,' commissioned by Institute for Climate and Society (iCS) & developed by Dalberg, provides practical entry points to engage with Brazil's successful #climate solutions.
Full report: dalberg.com/announcement...
#COP30
November 12, 2025 at 7:33 AM
vision analysis - Global Incremental Encoders ICs Market sites.google.com/view/visiona...
sites.google.com
November 12, 2025 at 7:32 AM
Global Incremental Encoders ICs Market : Emerging Growth Opportunities Shaping the Future of Technology in 2025 semiconductorblogs21.blogspot.com/2025/11/glob...
semiconductorblogs21.blogspot.com
November 12, 2025 at 7:23 AM
(Guy who’s afraid of class politics) ok so you’ve got your ICs and your managers
November 12, 2025 at 5:53 AM
" Masked Israeli settlers attack 2 Palestinian villages in the West Bank"

Seems ICE is an Israeli /US joint operation

#Cdnpoli #Uspoli #ICS #Israel
November 12, 2025 at 5:24 AM
BEST OT/ICS CYBERSECURITY TRAINING AND MACHINE LEARNING TRAINING AND GEN AI TRAINING IN DELHI NCR AND IN INDIA
November 12, 2025 at 5:13 AM
The most memorable Joe Strummer line for me in that 12/15/1999 City Pages piece by
@petescholtes.bsky.social about the Lifter Puller show on this date in 1999 was in the next paragraph:

"It's Lifter Puller's world," [Strummer] raves after the show. "We just live in it."
November 11, 2025 at 9:28 PM
Theologian and ICS Advisory Board Member Cynthia Moe-Lobeda names the moral damage that occurs when our daily lives depend on exploitation, calling us to imagine a new way of being.

💭Now live! Read this interview from @crbernasol.bsky.social in The Bias: christiansocialism.com/2025/11/06/b...
November 11, 2025 at 9:27 PM
The Phantom Menace: Dissecting the Low-Impact NuGet Package Sabotage

Introduction: The cybersecurity community was recently alerted by Socket to a set of malicious NuGet packages targeting industrial control system (ICS) components. However, a deeper analysis suggests this may not be the effective…
The Phantom Menace: Dissecting the Low-Impact NuGet Package Sabotage
Introduction: The cybersecurity community was recently alerted by Socket to a set of malicious NuGet packages targeting industrial control system (ICS) components. However, a deeper analysis suggests this may not be the effective supply chain attack it first appeared to be, but rather a case of suspicious code with unclear, and likely limited, malicious intent. This incident underscores the critical need for robust software supply chain security practices, even when the direct threat is ambiguous.
undercodetesting.com
November 11, 2025 at 9:10 PM
The Hidden Backdoors in Your Factory: A Hacker’s Guide to OT/ICS Network Ports

Introduction: Operational Technology (OT) and Industrial Control Systems (ICS) form the backbone of critical infrastructure, from power grids to manufacturing plants. While traditionally isolated, the convergence of IT…
The Hidden Backdoors in Your Factory: A Hacker’s Guide to OT/ICS Network Ports
Introduction: Operational Technology (OT) and Industrial Control Systems (ICS) form the backbone of critical infrastructure, from power grids to manufacturing plants. While traditionally isolated, the convergence of IT and OT networks has exposed these vital systems to a new wave of cyber threats, with network ports and protocols serving as the primary attack vector. Understanding and securing these communication channels is no longer an IT niche but a fundamental requirement for ensuring national and economic security.
undercodetesting.com
November 11, 2025 at 8:43 PM
This week, we'll have a guest from Sublime Security on #ThursDef!

Jon Gaulding will be joining us to cover some interesting new phishing, done with .ics phishing, those malicious calendar invites you may have been hearing about!

Get registered at thursdef.com

#ThursdayDefensive #cybersecurity
November 11, 2025 at 8:30 PM
Arguing for arguing’s sake. Could you name 2-3 cars that you can buy in 2025 for 30k with planned obsolescence ie not run comfortably for 10-15 years with regular maintenance without major issues? Focus on IC/hybrid ICs for now, for a better comparison.
November 11, 2025 at 8:23 PM
The ICS 6th grade class hosted a wonderful ceremony in the Drum this morning to remember and honor our Veterans. Happy Veterans Day and Pįįhįragigi / Wa’įnįįginąpšąną ~ Wāēwāēnen ~ Miigwech ~ Yawʌɂkó• ~Thank You to all who have served! #ICSEagles
November 11, 2025 at 7:00 PM
#TheTwen2ie5 - Day 36

15. "Sunset"
Caroline Polachek
2023
USA
ICS ✅
NKC ✅

Let's get in the zone!

For me, this was clearly the standout track from DESIRE, I WANT TO TURN INTO YOU. Nobody else seems to agree with me. But the Latin/Mediterranean vibes paired with them Polachek pop instincts!
November 11, 2025 at 6:41 PM
🎓 New Funding: ICS Travel Awards!
CIHR-IA and partners offer up to 40 awards for master's, doctoral students, postdocs, early-career researchers, and knowledge users to present research at events.
Patients are encouraged to apply!
👉 Apply by Nov 18: www.researchnet-recherchenet.ca/rnr16/vwOppr...
November 11, 2025 at 6:28 PM
I have gone through several cyber security audits over the years by various firms.

None have been by firms that understand ICS/OT and none have flagged the glaring architectural error I currently have.

I suggest getting an audit done by a firm that understands ICS/OT.
November 11, 2025 at 6:03 PM
Hoje estarei no UniVerse a apresentar a Rede de Mercearias Sociais, em representação do @ics-ulisboa.bsky.social. Apareçam! 😉
A 11 de novembro, o investigador Fábio Rafael Augusto apresenta a Rede de Mercearias Sociais no UniVerse – Academia Empreendedora, um evento paralelo à Web Summit 2025 organizado pela Universidade de Lisboa. 17h, no Pavilhão de Portugal.

+informação: tinyurl.com/mta52rb3
November 11, 2025 at 2:33 PM
Pròxima Jornada Respirem Junts. Coordinació i actualització amb #pneumologia🫁 per a professionals de #MedicinaFamiliariComunitària i #Infermeria.

📢 Divendres 21/11
🕣 8:30 a 15h
🏥 Sala d'actes de l’Hospital Sant Joan de Déu de #Manresa:

👉 https://f.mtr.cool/yocewwtior

#althaiamanresa #ICS
November 11, 2025 at 2:15 PM
Weaponized NuGet Packages Inject Time-Delayed Destructive Payloads to Attack ICS Systems
Weaponized NuGet Packages Inject Time-Delayed Destructive Payloads to Attack ICS Systems
cybersecuritynews.com
November 11, 2025 at 2:01 PM