<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>OT Briefing</title><link>https://www.otbriefing.com</link><description>Independent intelligence platform for European OT and ICS cybersecurity.</description><language>en</language><atom:link href="https://www.otbriefing.com/rss.xml" rel="self" type="application/rss+xml"/><item><title>ABB OPTIMAX Authentication Bypass and the Cost of Azure AD SSO in OT Environments</title><link>https://www.otbriefing.com/posts/2026-05-18-abb-optimax-auth-bypass-azure-ad-sso-7dui</link><guid isPermaLink="true">https://www.otbriefing.com/posts/2026-05-18-abb-optimax-auth-bypass-azure-ad-sso-7dui</guid><pubDate>Fri, 15 May 2026 12:58:02 GMT</pubDate><description>CVE-2025-14510 in ABB Ability OPTIMAX allows full authentication bypass when Azure Active Directory SSO is enabled, with no fix available for version 6.1 or 6.2 - part of a six-advisory ABB batch published 30 April 2026 affecting EU water and energy operators.</description></item><item><title>Siemens releases six critical OT patches amid growing NIS2 vulnerability pressure</title><link>https://www.otbriefing.com/posts/2026-05-18-siemens-six-critical-ot-patches-plr1</link><guid isPermaLink="true">https://www.otbriefing.com/posts/2026-05-18-siemens-six-critical-ot-patches-plr1</guid><pubDate>Thu, 14 May 2026 04:46:24 GMT</pubDate><description>Siemens issued six security advisories affecting critical OT infrastructure, highlighting accelerating patch burdens under NIS2 vulnerability management obligations.</description></item><item><title>ABB OPTIMAX authentication bypass exposes Azure AD integration risks in EU critical infrastructure</title><link>https://www.otbriefing.com/posts/2026-05-18-abb-optimax-azure-ad-bypass-risk-i9ht</link><guid isPermaLink="true">https://www.otbriefing.com/posts/2026-05-18-abb-optimax-azure-ad-bypass-risk-i9ht</guid><pubDate>Wed, 13 May 2026 08:00:14 GMT</pubDate><description>CVE-2025-14510 enables complete authentication bypass in ABB OPTIMAX systems using Azure AD integration, demonstrating cloud identity risks in OT environments.</description></item><item><title>Siemens CPCI85 Path Traversal in SICAM A8000: Configuration State Determines Exposure</title><link>https://www.otbriefing.com/posts/2026-05-18-sicam-a8000-cpci85-path-traversal-ssa-770890-s2o0</link><guid isPermaLink="true">https://www.otbriefing.com/posts/2026-05-18-sicam-a8000-cpci85-path-traversal-ssa-770890-s2o0</guid><pubDate>Wed, 13 May 2026 06:31:21 GMT</pubDate><description>SSA-770890 discloses a path traversal flaw in CPCI85 firmware of SICAM A8000 CP-8031 and CP-8050 substation RTUs; exposure depends on debug support activation state, making configuration audit the first step before patching.</description></item><item><title>AI-Assisted Reconnaissance in OT Networks: What Monterrey Tells European Sectoral SOCs</title><link>https://www.otbriefing.com/posts/2026-04-29-ai-assisted-reconnaissance-monterrey</link><guid isPermaLink="true">https://www.otbriefing.com/posts/2026-04-29-ai-assisted-reconnaissance-monterrey</guid><pubDate>Sat, 02 May 2026 08:00:00 GMT</pubDate><description>A Mexican water utility disclosed eleven days of read-only access enabled by LLM-assisted reconnaissance. European sectoral SOCs face the same threat class within months. Behavioral baselines tuned to manual probing no longer detect the new tempo.</description></item><item><title>Schneider Modicon CVE-2026-3041: Why EU Substations Should Patch in Fourteen Days</title><link>https://www.otbriefing.com/posts/2026-04-22-schneider-modicon-cve-2026-3041</link><guid isPermaLink="true">https://www.otbriefing.com/posts/2026-04-22-schneider-modicon-cve-2026-3041</guid><pubDate>Sun, 26 Apr 2026 07:30:00 GMT</pubDate><description>Schneider Electric disclosed a CVSS 9.8 pre-authentication remote code execution flaw in Modicon M340 and M580 PLCs on 22 April. Working exploit code appeared seventy-two hours later. EU operators should patch within fourteen days, not the ninety-day cycle NIS2 minimum language permits.</description></item><item><title>European Water Sector Ransomware: Six Disclosed Incidents in H1 2026</title><link>https://www.otbriefing.com/posts/2026-04-18-ransomware-eu-water-h1-2026</link><guid isPermaLink="true">https://www.otbriefing.com/posts/2026-04-18-ransomware-eu-water-h1-2026</guid><pubDate>Wed, 22 Apr 2026 09:00:00 GMT</pubDate><description>Six European water utilities disclosed ransomware between January and mid-April 2026, against three in the same period of 2025. The doubling reflects three distinct criminal ecosystems pivoting toward critical infrastructure with operational impact pricing in their negotiation logic.</description></item><item><title>NIS2 Article 21 Implementation: Three Patterns from Q1 2026 Sectoral Audits</title><link>https://www.otbriefing.com/posts/2026-04-10-nis2-article-21-implementation-patterns</link><guid isPermaLink="true">https://www.otbriefing.com/posts/2026-04-10-nis2-article-21-implementation-patterns</guid><pubDate>Wed, 15 Apr 2026 08:30:00 GMT</pubDate><description>Q1 2026 NIS2 Article 21 audits across nine EU member states surfaced three implementation patterns: supply-chain flow-down versus technical validation, encryption-at-rest scope, and governance documentation depth. The divergences will narrow with ENISA Q4 guidance.</description></item><item><title>Siemens SIMATIC S7-1500 Firmware Update: Operational Reasoning for the Patch Window</title><link>https://www.otbriefing.com/posts/2026-04-03-siemens-simatic-s7-1500-firmware-2026-q2</link><guid isPermaLink="true">https://www.otbriefing.com/posts/2026-04-03-siemens-simatic-s7-1500-firmware-2026-q2</guid><pubDate>Wed, 08 Apr 2026 07:00:00 GMT</pubDate><description>Siemens ProductCERT released the Q2 2026 firmware bundle for SIMATIC S7-1500 controllers, containing five CVEs from CVSS 5.4 to 8.2. None are pre-authentication remote code execution. Thirty-day deployment window with internet-reachable units prioritized.</description></item></channel></rss>