Understanding The South Staffordshire Water Cyber Attack
South Staffordshire PLC, parent company of South Staffs Water, a small independent utility that supplies water to 1.6 million customers, including 35,000 businesses, in central England was hit by a...
Evaluating Risk Across Your Entire OT Architecture
A SCADAfence New Feature Report Here is the standard, old school way of automated risk assessment across an OT network: First, scan each device individually. Then evaluate its specific level of risk...
ICS / OT Security News Update | SCADAfence - August 17
Our research team compiled the latest updates on newly announced CVEs, recent ransomware attacks including BlackCat & Luna, and IoT security news. They also offer analysis of the potential impacts...
SCADAfence Contributes New Metasploit Module For Pentesting BACnet
The SCADAfence engineering team has contributed a new module to the widely used Metasploit framework as a “pay it forward” program that will allow pentesters and asset owners to use a new set of...
CVE Prioritization Boosts OT Security & Saves Your Organization Money
A SCADAfence New Feature reportA large, robust Industrial Control Systems (ICS) network can contain tens of thousands of devices. Each of those devices may have any number of associated known CVEs...
Did Iranian Hackers Cause The Fire At An Israeli Power Plant?
Iranian Hackers Claimed Responsibility for the Power Plant Fire Almost immediately after a fire broke out in an active power plant in southern Israel on July 14, 2022, an Iranian hacking group...
ICS / OT Security News Update | SCADAfence - July 15
Our research team compiled the latest updates on newly announced CVEs, recent ransomware attacks and IoT security news. They also offer analysis of the potential impacts and their expert...
The Iran Steel Industry Cyber Attack Explained
Iran’s steel Industry was hit by a hacktivist group calling themselves ”Goneshke Darande” [Predatory Sparrow] on June 27th, 2022. The attack focused specifically on three steel companies that are...
What Really Caused The Freeport LNG Plant Explosion?
This blog is a response to a recently published article that implied a link between the June 8th explosion at the Freeport LNG plant and Russian threat actors. The author attempted to connect...
ICS / OT Security News Update | SCADAfence - June 22
Our research team compiled the latest updates on newly announced CVEs, recent ransomware attacks and IoT security news. They also offer analysis of the potential impacts and their expert...
Why Wind Farms’ OT Networks Could Be Ransomware’s Next Big Target
A Change In The Air The past several decades have seen a seismic shift in how the world thinks about energy. Concerns about climate change and global geopolitics have caused many nations to declare a...
Interview With SCADAfence's New Field CTO, Paul Smith
OT and ICS Industry veteran Paul Smith, author of “Pentesting Industrial Control Systems” has recently joined the SCADAfence team in the role of Field CTO. We interviewed Paul to get his thoughts on...
Weekly ICS / OT Security News Digest | SCADAfence - May 10
Our research team has put together all of the most relevant news topics in the Ransomware and IoT security fields, as well as their impacts and their expert recommendations:
CISA's Top 15 Routinely Exploited Vulnerabilities: SCADAfence Customers Stay Protected
On April 27, the Cybersecurity and Infrastructure Security Agency (CISA), published a joint advisory in collaboration with CSA/NSA/FBI/ACSC and other cybersecurity authorities, providing details on...
INCONTROLLER / Pipedream: State-Sponsored Attack Tools Targeting Multiple ICS Systems
Dangerous New Malware Can Shut Down, Sabotage Industrial Sites
Industroyer2 Malware Attack: Vigilance needed on ICS Networks
Russian-backed Group Attempts to Compromise Ukrainian Power Grid Using Industroyer2 Malware As part of their ongoing military assault against neighboring Ukraine, Russian-backed hacker group Sandworm...
Vulnerability Report: Rockwell PLC Unauthorized Code Injection [CVE-2022-1161 & 1159]
Two vulnerabilities in Rockwell programmable logic controllers and engineering workstation software have been disclosed. These vulnerabilities give attackers a way to modify automation processes and...
Your Weekly ICS / OT Security News Digest - March 31st
Our research team has put together all of the most relevant news topics in the ICS, IT, Ransomware & OT security fields, as well as their impacts and their expert recommendations:
OT Security in 2021 - The Roundup | SCADAfence
As 2021 draws to a close, it is time for our customary round-up of the year’s industry-changing cyber attacks, product and company updates, and SCADAfence’s achievements.
OT Security for Log4J with the SCADAfence Platform
Until two weeks ago, Log4j was just a popular Java logging framework, one of the numerous components that run in the background of many modern web applications. But since a zero-day vulnerability...
A SCADAfence Update Regarding The Log4Shell Vulnerability
December 10, 2021, will always be remembered by the security community as the day when a highly critical zero‑day vulnerability was found in the very popular logging library for Java applications, ...
Simplifying Cyber Security for the Mining Industry
The COVID-19 pandemic has been detrimental to the world economy while flattening many industries. The mining industry was fortunate to be one of the very few industries to deliver exceptional growth...
To Patch or Not to Patch in OT | SCADAfence
When organizations are seeking out the right OT network security for their OT environments and OT devices, the clear objective is to decrease and eliminate risks. Too often organizations only adopt...
Implementing Zero Trust Security in OT Environments
In 2021, the increasing number of cyber security attacks on major critical infrastructure operators grabbed the headlines. The successful attacks targeted different industrial sectors such as oil...
IBM QRadar SIEM Integration For Complete OT Visibility
CISOs and security teams face an uphill battle when it comes to detecting and mitigating ever more frequent and sophisticated cyber threats, especially in OT environments.
Innovative OT Security Solutions. SCADAfence's largest product rollout
Over time, we have learned that we develop products not for our own innovation, but for you the customers, to help improve your OT security. In 2021, we were excited to launch three newly designed...
White House Pushes for Stronger Critical Infrastructure Security
In the wake of the different ransomware attacks on Colonial Pipeline, JBS Foods, Oldsmar Florida water system and other critical infrastructure, President Joe Biden signed a national security...
OT Networks Are the Low-Hanging Fruit for Supply Chain Attacks
When looking back at 2020 and 2021 the first thing that comes to mind is the different supply chain attacks on the industrial sectors. The successful attacks by threat actors exploited the industrial...
SCADAfence is the Most Advanced OT Security Vendor Covering MITRE ATT&CK for ICS
There is a lot of buzz recently on the topic of MITRE ATT&CK for ICS and rightfully so.
Ransomware Attacks on the Automotive Sector Are Picking Up Speed
50% of Automotive Manufacturers Susceptible to a Ransomware Attack The automotive industry has started to ramp up its digitalization in their manufacturing sites but cybersecurity is still an...
Kaseya Supply Chain Attack Delivers Mass Ransomware Event to MSPs
Just as the security community was recovering from the SolarWinds supply-chain attack, over July 4th holiday weekend Kaseya IT management software, commonly implemented by Managed Service Providers...
Water Utilities Face Increasing Risk of Cyber Attacks
Cyber Crime on the Rise - Ransomware is Everywhere Over the past few months, there is a feeling that every day a different organization has fallen victim to a ransomware attack. While the idea of a...
Top 20 PLC Secure Coding Practices Released
Over the years, programmable logic controllers (PLC) have been insecure by default. Security good practices have been created and adopted for IT which can be seen in OWASP’s Top Ten Vulnerabilities...
NERC Practice Guide: Helping Organizations Evaluate Network Monitoring Technologies
Earlier this month, on June 4th, the North American Electric Reliability Corporation (NERC) released a new practice guide that pinpoints how organizations should integrate network monitoring...
5 Key Takeaways from The U.S. Executive Order to Bolster Nation’s Cybersecurity
It’s no secret that Nation-State attackers are targeting US government agencies and organizations. As seen in the Solarwinds breach and the more recent Colonial Pipeline ransomware attack,...
Bridging the Gap Between IT & OT: How Rapid7 & SCADAfence Partnership Leads the Way
It's been over a decade since the headline-grabbing Stuxnet virus was introduced and the concept of nation-state-sanctioned cyber attacks was presented by security professionals. The concern about...
“Air-Gapping” Networks in IT and OT?
Following the Colonial Pipeline Ransomware incident, Twitter exploded in to an orgy of blather from people demanding that we “air-gap” ICS. Those righteous keyboard warriors know what is best, I’m...
SCADAfence Researchers: Vulnerability in the CODESYS Development System
There are new vulnerabilities discovered every day, and new patches issued to fix them. As part of our mission to secure the world’s OT, IoT and Cyber Physical infrastructures, we invest resources...
Colonial Pipeline Attack Spells Fuel Pipeline Shutdown: Increased OT Security Needed
On May 8th, news broke that Colonial Pipeline, one of the largest fuel pipelines in the US, was forced to stop all operations due to falling victim to a ransomware attack. The attack on Colonial...