Critical vulnerabilities in Siemens PLC devices could allow bypass of protected boot features (CVE-2022-38773)

Red Balloon Security disclosed multiple, critical architectural vulnerabilities in the Siemens SIMATIC and SIPLUS S7-1500 Series PLC that allow for bypass of all protected boot features. These vulnerabilities affect over 120 different models of the Sie… Continue reading Critical vulnerabilities in Siemens PLC devices could allow bypass of protected boot features (CVE-2022-38773)

This Week in Security: npm Timing Leak, Siemens Universal Key, and PHP in PNG

First up is some clever wizardry from the [Aqua Nautilus] research team, who discovered a timing attack that leaks information about private npm packages. The setup is this, npm hosts …read more Continue reading This Week in Security: npm Timing Leak, Siemens Universal Key, and PHP in PNG

Record energy haul: Offshore prototype operates over capacity for 24 hrs

A prototype wind turbine has recorded an extraordinary single-day renewable energy production total, bringing in a massive 359 megawatt-hours in a 24-hour time period. To get there, it had to operate over its rated capacity, essentially all day long.Co… Continue reading Record energy haul: Offshore prototype operates over capacity for 24 hrs

Recyclable turbine blades now available for onshore wind energy projects

Early last month, Siemens Gamesa reported that recyclable turbine blades had been successfully installed at the Kaskasi offshore wind farm in the North Sea. Now the company has announced the market availability of an onshore equivalent.Continue Reading… Continue reading Recyclable turbine blades now available for onshore wind energy projects

Wind turbine fitted with recyclable blades starts generating electricity

Harvesting wind energy is an important part of the renewables mix, but when those huge turbine blades reach the end of their working lives, they could end up as waste in landfill. Siemens Gamesa has developed a recyclable blade that can be used to crea… Continue reading Wind turbine fitted with recyclable blades starts generating electricity

Beware of password-cracking software for PLCs and HMIs!

A threat actor is targeting industrial engineers and operators with trojanized password-cracking software for programmable logic controllers (PLCs) and human-machine interfaces (HMIs), exploiting their pressing needs to turn industrial workstations int… Continue reading Beware of password-cracking software for PLCs and HMIs!

Researchers disclose 56 vulnerabilities impacting thousands of OT devices

Forescout’s Vedere Labs disclosed OT:ICEFALL, 56 vulnerabilities affecting devices from 10 operational technology (OT) vendors. This is one of the single largest vulnerability disclosures that impact OT devices and directly addresses insecure-by-… Continue reading Researchers disclose 56 vulnerabilities impacting thousands of OT devices

Nozomi Networks extends partnership with Siemens to bring scalable cybersecurity to industrial automation

Nozomi Networks and Siemens have extended their partnership by embedding Nozomi Networks’ Guardian Remote Collector software into the Siemens Scalance LPE local processing engine, a hardware platform designed for data processing for edge and cloud appl… Continue reading Nozomi Networks extends partnership with Siemens to bring scalable cybersecurity to industrial automation