Signals are individual enterprise-technology developments, captured as they happen: product launches, funding, partnerships, executive moves, vulnerabilities, and announcements across cloud infrastructure, networking, security, and AI. Looking for the synthesis? See Briefs
CISA published two advisories addressing security issues related to Industrial Control Systems, specifically focusing on ISO 15118-2 and Hitachi Energy TropOS. The advisories include technical details and mitigation recommendations for users and administrators.
CISA added CVE-2025-58034, a Fortinet FortiWeb OS command code injection vulnerability, to the Known Exploited Vulnerabilities Catalog with a one-week remediation guideline.
CISA added CVE-2025-58034, a Fortinet FortiWeb OS command code injection vulnerability, to its Known Exploited Vulnerabilities Catalog. This vulnerability is actively exploited, with a recommended remediation timeframe of one week. Federal agencies are required to address such vulnerabilities under BOD 22-01.
A vulnerability in Shelly Pro 4PM smart DIN rail switches prior to version 1.6 allows attackers to cause denial of service by exploiting a resource allocation flaw in the JSON parser. The issue has a CVSS v4 score of 8.3. Mitigations include software updates and network security measures.
Schneider Electric's PowerChute Serial Shutdown versions 1.3 and earlier have vulnerabilities including path traversal, excessive authentication attempts, and incorrect default permissions. Version 1.4 fixes these issues. Users are advised to apply the update and follow recommended security measures to reduce risk.
CISA published six advisories on Industrial Control Systems highlighting security issues and vulnerabilities related to products from Schneider Electric, Shelly, and METZ CONNECT. The advisories provide technical details and mitigations, urging users and administrators to review them for security maintenance.
A vulnerability related to weak cryptographic algorithms in Schneider Electric's EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio products was detailed. Patches are available in version 2023.1 Patch 1. Mitigation steps and best cybersecurity practices are recommended by Schneider Electric and CISA.
Zenitel's TCIV-3+ devices prior to version 9.3.3.0 have vulnerabilities including OS command injection, out-of-bounds write, and cross-site scripting. These issues could allow arbitrary code execution or denial of service. Mitigations include upgrading firmware and network security measures.
SiRcom SMART Alert (SiSA) version 3.0.48 allows unauthenticated remote access to control emergency sirens via bypass of login.
Not an agent? Get the next brief
A synthesis of what changed across the vendors, projects and technologies tracked here. Published every two weeks. Subscribing creates a free Decision Insights account.