Critical

What stops attackers wrecking industrial plants is knowing how

Help Net Security
Actively Exploited

Overview

Engineers at an Israeli food company faced a major setback when an intruder tampered with their refrigeration system. The attacker switched the gas cooler and receiver valves to manual and left them open, causing liquid carbon dioxide to flood the compressors and ultimately destroying them. The repair process took a week, as the new compressors were incompatible with the existing system, requiring a complete rework and gas recharge. This incident is part of a larger trend, with Kaspersky ICS CERT reporting around forty similar attacks recently. Such breaches highlight the vulnerabilities in industrial control systems and the potential for significant operational disruptions.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Refrigeration systems at an Israeli food producer
  • Action Required: Implement stricter access controls and monitoring on industrial control systems; consider regular security assessments and incident response planning.
  • Timeline: Ongoing since recent months

Original Article Summary

Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The replacement units did not match the originals, so the whole system had to be reworked and recharged with gas. That incident is one of roughly forty in Kaspersky ICS CERT’s quarterly roundup of attacks on … More → The post What stops attackers wrecking industrial plants is knowing how appeared first on Help Net Security.

Impact

Refrigeration systems at an Israeli food producer

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since recent months

Remediation

Implement stricter access controls and monitoring on industrial control systems; consider regular security assessments and incident response planning.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Kaspersky.

Related Coverage

Silent Patches Don’t Stop Attackers—They Blind Defenders

SecurityWeek

The article discusses the issue of silent patches, which are updates made to software to fix vulnerabilities without publicly disclosing the details. While these patches can help secure systems, they also create a problem for defenders. Attackers can exploit these vulnerabilities without defenders knowing the full context of the risks they face. This lack of transparency can lead to misprioritization of security efforts, leaving organizations vulnerable. The piece emphasizes the need for better communication about vulnerabilities and updates to ensure that defenders have the information they need to protect against potential exploits.

Aug 25, 2026

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

Infosecurity Magazine

ReliaQuest has addressed a recent social engineering attack associated with the hacking group ShinyHunters. The company clarified that while there were attempts to compromise its systems, the attackers did not succeed in breaching their defenses. This incident serves as a reminder of the growing threat posed by social engineering tactics, where attackers manipulate individuals into divulging confidential information. Despite the denial of a successful compromise, the event raises concerns about the effectiveness of security measures and the importance of employee awareness training. Companies must remain vigilant against such tactics to protect sensitive data and maintain trust with their clients.

Aug 25, 2026

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

Infosecurity Magazine

The U.S. government has imposed sanctions on several individuals linked to the Mabna Institute, a hacking group based in Iran known for cyber-attacks. This group has been involved in various hacking activities, including stealing data from universities and businesses around the world. The sanctions target the group's members to disrupt their operations and deter similar actions in the future. By penalizing these individuals, the U.S. aims to hold them accountable for their cyber activities that threaten both national security and economic interests. This move also signals to other state-sponsored hacking groups that there are consequences for such cyber crimes.

Aug 25, 2026

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

Security Affairs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious vulnerability in Oracle's HTTP Server and Weblogic Server Proxy Plug-in to its Known Exploited Vulnerabilities catalog. This flaw, identified as CVE-2026-21962, carries a maximum severity score of 10.0, indicating it is a critical risk for users. The vulnerability allows unauthenticated attackers to exploit the affected systems, which could potentially lead to unauthorized access and control. Organizations using these Oracle products should take immediate action to assess their systems and implement necessary security measures to mitigate this risk. The inclusion in CISA's catalog suggests that this vulnerability is being actively targeted by malicious actors, making swift remediation essential.

Aug 25, 2026

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News

Attackers are exploiting two serious vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing unauthorized users to log in as any WordPress user, including those with administrative privileges. These vulnerabilities, identified as CVE-2026-61979, have a CVSS score of 8.1, indicating a high severity level. This situation puts numerous WordPress sites at risk, as it could enable attackers to gain complete control over these sites without needing valid credentials. The vulnerabilities were disclosed by Patchstack, underscoring the need for site administrators to take immediate action. Promptly addressing these flaws is crucial to prevent unauthorized access and potential data breaches.

Aug 25, 2026

Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff

SecurityWeek

Taiwan has charged nine individuals, including staff from Nvidia and Super Micro, for illegally exporting AI servers to China. These exports involved advanced semiconductors that are primarily manufactured in Taiwan, which are crucial for AI infrastructure. The Taiwanese government is taking a strong stance against these actions, reflecting ongoing tensions between the U.S. and China over technology and trade. This case highlights the sensitive nature of semiconductor technology and its role in global competition. The individuals involved face serious legal repercussions, emphasizing the importance of compliance with export regulations in the tech industry.

Aug 25, 2026