Sector

water

8 posts

vulnerability-disclosure

Schneider Modicon CVE-2026-3041: Why EU Substations Should Patch in Fourteen Days

Schneider Electric disclosed a CVSS 9.8 pre-authentication remote code execution flaw in Modicon M340 and M580 PLCs on 22 April. Working exploit code appeared seventy-two hours later. EU operators should patch within fourteen days, not the ninety-day cycle NIS2 minimum language permits.

9 min read
ransomware

European Water Sector Ransomware: Six Disclosed Incidents in H1 2026

Six European water utilities disclosed ransomware between January and mid-April 2026, against three in the same period of 2025. The doubling reflects three distinct criminal ecosystems pivoting toward critical infrastructure with operational impact pricing in their negotiation logic.

10 min read