Weekly Security Roundup: ICS Advisories Pile Up, AI’s Double Edge, and Cybercrime Reckonings

This week’s ingest is heavy on industrial control system (ICS) advisories, but the through-line is broader: attackers keep finding leverage in the seams of our infrastructure and tooling, whether that’s a PLC compiler, an AI support bot, or a “residential proxy” that turns out to be a botnet. Below, our take on the items worth your attention, with sources linked for the full details.

OpenPLC v3 arbitrary code execution. A vulnerability that turns file-write access into native code execution “through the normal OpenPLC program compilation process” is a reminder that build and compile pipelines are attack surface, not neutral plumbing. Open-source control software runs quietly in a lot of places; keep an eye on your deployments. Read the CISA advisory.

The language of AI could reshape human speech. Bruce Schneier flags a subtle cultural risk: LLMs are trained on written and scripted language, missing the “vast majority of speech” that happens face to face. As we increasingly talk like the machines that learned to talk like us, we risk a feedback loop that flattens linguistic diversity. A rare non-vulnerability item here, and a worthwhile long view. Read Schneier’s post.

Felons and fraudsters behind an offensive-security startup. Brian Krebs digs into a company dangling millions for zero-days that’s reportedly run by convicted felons with a history of fake intelligence firms. The zero-day acquisition market has always had a trust problem; this is a vivid case study in why provenance matters when someone’s buying the keys to widely used software. Read the KrebsOnSecurity investigation.

Hitachi Energy PROMOD V ships credentials in the clear. An insecure-HTTP-transmission flaw enabling credential theft or session hijacking in energy-planning software is a basic hygiene failure with serious downstream implications. Encryption in transit should be table stakes for anything touching the grid. Read the CISA advisory.

Hitachi Energy e-mesh EMS buffer overflow. A second Hitachi Energy advisory this week, this one a buffer overflow that could cause denial of service or code execution in an energy management system. Two flaws from one vendor in a single cycle is worth noting for asset owners tracking exposure. Read the CISA advisory.

Siemens Mendix Studio Pro build-pipeline parsing flaw. Like the OpenPLC issue above, this one triggers when the tool reads a “specially crafted malicious project” during the build. The recurring theme this week: your development and build tooling can be weaponized against you. Update to V11.12 or later. Read the CISA advisory.

Labcenter Proteus 9 memory-safety bugs. Out-of-bounds writes, stack overflows, and use-after-free in electronics design software round out the theme of engineering tools as targets. Attackers understand that compromising a design workstation can quietly poison what gets built downstream. Read the CISA advisory.

Hydro-Québec EV charging backend, CVSS 9.8. Improper access control and weak authentication throttling in an EV charging station backend earn one of the highest scores in this batch. As charging networks scale, their backends become critical infrastructure in their own right—and this is a loud warning about their maturity. Read the CISA advisory.

CISA adds an actively exploited ColdFusion bug to KEV. A path-traversal flaw in Adobe ColdFusion is now confirmed to be under active exploitation. If you still run ColdFusion, treat this as a drop-everything patch under BOD 26-04’s risk-prioritized timeline. Read the CISA alert.

FBI seizes the NetNut proxy platform and Popa botnet. A significant takedown: the FBI grabbed hundreds of domains tied to a residential proxy service run by a publicly traded firm, just weeks after

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *