Výsledky hledání

sektor: vodárenství× v celém archivu zrušit filtry

33 karet z 33 položek CZ · EN/orig

6

Pyramid Solutions NetStaX EtherNet/IP Stack

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter…

EPSS 0.00 CVSS 9.8 CVE-2026-78012 Pyramid Solutions výroba a průmysl energetika vodárenství obrana US

tg: zneužíváno tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

IXON VPN Client

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client <1.4.7 (CVE-2026-75925) CVSS Vendor Equipment Vulnerabilities v3 9.6 IXON IXON VPN Client Improper Neutralization of CRLF Sequences ('CRLF Injection') Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy,…

CVSS 9.6 CVE-2026-75925 IXON energetika vodárenství výroba a průmysl US

tg: zneužíváno tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Rockwell Automation ControlFLASH

View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH <=V15.07 (CVE-2026-12663) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation ControlFLASH Missing Authentication for Critical Function Background Critical…

EPSS 0.00 CVSS 7.3 CVE-2026-12663 Rockwell Automation výroba a průmysl energetika vodárenství US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra…

EPSS 0.00 CVSS 8.3 CVE-2026-4827 Schneider Electric energetika vodárenství US

tg: zneužíváno tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (LDS) Execution with Unnecessary Privileges Background Critical Infrastructure…

CVSS 4.6 CVE-2026-77477 OPCFoundation energetika vodárenství výroba a průmysl obrana US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture,…

CVSS 7.5 CVE-2025-10478 Rockwell Automation výroba a průmysl vodárenství doprava US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

2

Rockwell Automation Redundancy Module Configuration Tool

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation Redundancy Module…

CVSS 7.3 CVE-2026-9633 CVE-2026-9634 Rockwell Automation výroba a průmysl energetika vodárenství doprava US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Rockwell Automation Historian ME

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…

CVSS 8.0 CVE-2025-12768 CVE-2026-12661 Rockwell Automation výroba a průmysl energetika vodárenství zdravotnictví US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

1

[Control Systems] National Instruments security advisory (AV26-856)

Serial Number: AV26-856Date: August 28, 2026 As of August 25, 2026, National Instruments is affected by vulnerabilities in the following product: LabVIEW Prior to 23.0.0 Prior to 23.3.10 Prior to 24.3.7 Prior to 25.3.5 Prior to 26.3.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Memory Corruption Vulnerabilities in NI LabVIEW - NI Integer Conversion Vulnerability Resulting in an Out of Bounds Read…

National Instruments výroba a průmysl energetika vodárenství telekomunikace CA

tg: zranitelnost tp: průmyslové systémy

Cyber Centre Kanada ·

1

Applied Systems Engineering ASE2000 V2 Communications Test Set

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected: ASE2000 >=2.25|<=2.37 (CVE-2018-1285, CVE-2026-18717) CVSS Vendor…

EPSS 0.17 CVSS 9.8 CVE-2018-1285 CVE-2026-18717 Applied Systems Engineering energetika vodárenství výroba a průmysl US

CISA Advisories ·

1

PLC na internete: aktuálne riziko aj pre kritickú infraštruktúru

Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ upozorňuje na nebezpečenstvo prevádzkovania programovateľných logických radičov (ďalej ako „PLC“) voľne dostupných z verejného internetu. PLC nie je zariadenie, ktoré má byť priamo dostupné z verejného internetu. Programovateľné logické radiče hrajú kľúčovú úlohu takmer vo všetkých odvetviach priemyslu. Ich vystavenie do verejného internetu môže viesť k ohrozeniu útočníkmi s... The post PLC na internete: aktuálne riziko aj pre kritickú…

energetika vodárenství výroba a průmysl telekomunikace SK

SK-CERT (NBÚ SR) ·

1

A Tale of Two SOCs: Insights From Two Red Team Assessments

Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity…

veřejná správa vodárenství US

CISA Advisories ·

1

24th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people – roughly two-thirds of the country’s population – as well as 200,000 organizations. The stolen data included identification numbers, license plates, payment amounts, dates and addresses. Attackers reportedly exploited a…

KEV ✓ EPSS 0.41 CVSS 10.0 CVE-2026-12569 CVE-2026-19478 CVE-2026-19489 CVE-2026-19490 Snowflake Siemens GitLab Cisco zdravotnictví výroba a průmysl energetika vodárenství IL

Check Point Research ·

1

Frequently asked questions about the active threat to Siemens S7 Series PLCs

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysUnattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs.The attackers are leveraging AI to build and refine…

Siemens veřejná správa energetika vodárenství výroba a průmysl US

Tenable Research ·

3

Defending Against an Active Threat to Siemens S7 Series PLCs

Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations Inventory all Siemens S7 Series programmable logic…

Siemens výroba a průmysl energetika vodárenství obrana US

CISA Advisories ·

1

More than 200 victims of Medusa ransomware identified over the last year, CISA says

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

veřejná správa energetika vodárenství telekomunikace US

The Record ·

1

Haiwell IoT Cloud HMI Gateway

View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188) CVSS Vendor Equipment Vulnerabilities v3 10 Haiwell Haiwell IoT Cloud HMI Gateway Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors:…

EPSS 0.02 CVSS 10.0 CVE-2026-19188 Haiwell energetika výroba a průmysl vodárenství US

CISA Advisories ·

1

[Control Systems] Phoenix Contact security advisory (AV26-811)

Serial number: AV26-811Date: August 12, 2026 As of August 12, 2026, Phoenix Contact is affected by vulnerabilities in the following products: AXC F 1152 Prior to 2026.0.3 AXC F 1252 Prior to 2026.0.3 AXC F 2000 EA Prior to 2026.0.3 AXC F 2152 Prior to 2026.0.3 AXC F 3152 Prior to 2026.0.3 BPC 9102S Prior to 2026.0.3 BPC 9202S Prior to 2026.0.3 Catan C1 Prior to 2026.0.3 EPC 1502 Prior to 2026.0.3 EPC 1522 Prior to 2026.0.3 RFC 4072R Prior to 2026.0.3 RFC 4072S Prior to 2026.0.3 VL3 UPC 2440…

Phoenix Contact výroba a průmysl energetika vodárenství CA

Cyber Centre Kanada ·

1

ABB Ability Zenon

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data…

KEV ✓ EPSS 0.83 CVSS 7.8 CVE-2020-7921 CVE-2020-7928 CVE-2025-14847 ABB energetika zdravotnictví vodárenství výroba a průmysl US

CISA Advisories ·

1

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ EPSS 0.88 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Check Point Cisco Broadcom Microsoft vodárenství finance zdravotnictví telekomunikace IL

Check Point Research ·

2

What water utilities need to know about cybersecurity compliance

As federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities.Key takeawaysWhile the EPA’s national sanitary-survey mandate stalled in court, the agency is aggressively using existing authority, technical guidance, and enforcement alerts to inspect cyber gaps. Community water systems serving 3,301 to 49,999 people, the…

EPA CISA vodárenství US

Tenable Research ·

You were onto something with “It’s the Climb,” Miley

Welcome to this week’s edition of the Threat Source newsletter. For my fianceé’s 30th birthday, I took her on a weekend trip to Shenandoah National Park – a favorite of ours since we went to a wedding there several years back. We’ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that’s largely considered the most difficult in Virginia. I've always been warned that at the beginning and end, you hate Old Rag.…

Cisco Microsoft Check Point Zoho zdravotnictví veřejná správa vodárenství US

Cisco Talos ·

1

Coordinated "cyberattack" on U.S. water utilities: What you need to know

A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an…

KEV ✓ EPSS 0.64 CVSS 9.8 CVE-2021-22681 Rockwell Automation Schneider Electric Siemens vodárenství US

Tenable Research ·

1

27th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, while the RansomHouse group claimed responsibility and published a subset of the stolen…

KEV ✓ EPSS 0.85 CVE-2025-66376 CVE-2026-16232 CVE-2026-50522 Check Point Oracle Microsoft OpenAI energetika vodárenství veřejná správa doprava IL

Check Point Research ·

1

1

Útočníci získali přístup k desítkám tisíc firewallů Fortinet

Bezpečnostní výzkumníci upozornili na rozsáhlou kampaň zaměřenou na firewally a VPN brány Fortinet, při níž mělo být kompromitováno téměř 74 000 zařízení ve 194 zemích. Útočníci podle zveřejněných informací automatizovaně vyhledávali veřejně dostupná administrační rozhraní, získávali konfigurace zařízení a následně offline prolamovali přístupové údaje. Mezi údajně zasaženými organizacemi jsou nadnárodní společnosti, státní instituce i provozovatelé kritické infrastruktury. Případ zároveň…

Fortinet veřejná správa energetika vodárenství telekomunikace CZ

CSIRT.CZ (CZ.NIC) ·

1

1

1

Riasztás ipari vezérlőrendszereket érintő kampányról

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki egy kritikus infrastruktúrákat célzó, jelenleg is aktív támadási kampány kapcsán. A rendelkezésre álló elemzés szerint a kampány során iráni kötődésű szereplők ipari vezérlőrendszerekhez, ezen belül Rockwell Automation / Allen-Bradley PLC-khez fértek hozzá, és azok manipulálásával működési zavarokat idéztek elő. A támadások sajátossága, hogy nem […]

Rockwell Automation energetika výroba a průmysl vodárenství HU

NKI Maďarsko ·

1

1