Cybersecurity is the discipline, processes, and technologies that protect enterprise networks, information systems, and data from unauthorized access, disruption, or misuse, enabling organizations to maintain confidentiality, integrity, availability, and regulatory compliance across on-premises, cloud, and hybrid digital environments.
CISA will cease updating ICS security advisories for Siemens vulnerabilities as of January 10, 2023. Siemens advises updating Spectrum Power 4 to V4.70 SP12 Update 2. Several serious vulnerabilities have been identified, allowing remote code execution and privilege escalation, requiring immediate attention.
CISA, in collaboration with federal and international partners, has issued an updated Cybersecurity Advisory on Akira ransomware, detailing latest attack methods and prevention strategies.
Mitsubishi Electric has reported a vulnerability in its MELSEC iQ-F Series that may allow a Denial of Service condition when exploited. Affected models are detailed, and mitigation measures are recommended.
General Industrial Controls has reported vulnerabilities in Lynx+ Gateway, including weak password requirements and missing authentication, which could lead to unauthorized access. CISA recommends defensive measures to mitigate risks, as no public exploitation targeting these vulnerabilities has been documented.
AVEVA has reported a vulnerability in its Edge software that may allow attackers to reverse engineer passwords via weak cryptographic algorithms. Users are advised to upgrade to the latest version and implement specific security measures to mitigate risks.
Siemens has addressed vulnerabilities in Altair Grid Engine versions prior to V2026.0.0, which can allow attackers to escalate privileges. CISA advises updates, mitigations, and cybersecurity practices to minimize risks.
CISA will cease updates for Siemens ICS security advisories after January 10, 2023. Siemens reports vulnerabilities in COMOS software versions prior to 10.4.5, with risk of code execution and data infiltration. Users are advised to upgrade software and follow additional security measures to mitigate risks.
CISA will cease updates on Siemens ICS security advisories for product vulnerabilities. The SICAM P850 and P855 families face vulnerabilities allowing unauthorized actions via CSRF and session hijacking. Users are urged to update to version 3.11 or later and follow recommended security practices.