Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • US Department of Homeland Security alert Malware Targeting Industrial Safety Systems
  • Malware

US Department of Homeland Security alert Malware Targeting Industrial Safety Systems

Do Son December 21, 2017 3 minutes read
Industrial Safety Systems
Add Daily CyberSecurity as a preferred source on Google

Network security companies FireEye and Dragos reported last week that the new malware, Triton, and Trisis, shut down some Middle East agencies by damaging the widely used Schneider Electric Triconex safety controller in key infrastructure. It is reported that Cyber Cyber company CyberX speculated on the basis of speculation that the behind-the-scenes blackmailing of this cyber attack may be planned by Iran and its target is an important agency suspected of being in Saudi Arabia. The National Security and Communications Integration Center (NCCIC) of the Department of Homeland Security (DHS) released an analysis of malware for the industrial security system on Monday.

the US Department of Homeland Security ( DHS ) researchers have found another new malware in the investigation in the near future Hatman, aimed against the state industrial control system ( ICS launched attacks). Subsequently, the National Network Security and Communications Integration Center ( NCCIC ) provided mitigation and YARA rules in a malware analysis released this Monday to reduce the loss of national industrial control systems. 

Surveys show that HatMan malware written in Python is primarily targeted at Schneider Electric’s Triconex Safety Instrumented System (SIS) controllers and is designed to monitor processes and restore them to a safe state or perform safety shutdowns when potentially dangerous situations are identified. In addition, HatMan communicates with SIS controllers via proprietary TriStation protocols and allows attackers to manipulate devices by adding new ladder logic. However, as the hacker terminated the operation after triggering the SIS controller to start the “Safe Shutdown” feature, FireEye experts speculated that the attacker could inadvertently trigger the controller during the detection phase, with the ultimate goal being to simply inflict high SIS physical damage Interested.

Schneider Electric’s Triconex Safety Monitoring System (SIS) controller is designed to provide continuous safety interlocking and protection, process monitoring and safe parking where necessary, for safety and critical units in nuclear, oil refining, petrochemical, chemical and other process industries.

It is noteworthy that NCCIC pointed out in its report that the malware mainly has two components: one is to interact with the safety controller after the damaged PC is running, and the other is to run directly on the controller. The researchers said that although HatMan itself did not do any dangerous actions and the downgraded infrastructure security system did not directly manipulate the entire control process, it could be extremely harmful if flawed security systems were infected with malware. In addition, it is safe to say that although HatMan may become an important tool for monitoring ICS in the future, it may only be used to affect industrial processes or other dangerous operations. All in all, the building of different components in malware means that an attacker needs to be very familiar with the ICS environment, especially with Triconex controllers, and it needs a longer development cycle to refine this sophisticated attack.

Schneider Electric has investigated the incident. Officials said there is currently no evidence that the malware exploits any loopholes in the product. However, security experts advise customers not to easily place the device in “Program” mode because an attacker could potentially send the payload via malware when the controller is set to “Program” mode.

Emily S. Miller, director of the National Security Agency, said: “Attackers have the ability to access critical infrastructure security instrumentation and are likely to make potential changes to device firmware, so this reminder gives key owners and operators critical infrastructure The warning. ”

Source: Securityweek 

Related coverage

  • GhostHook Framework: A New Fileless Malware Threatens Android Devices
  • DNS hijacker Roaming Mantis malware target OS, Android and Desktop users worldwide
  • CUPS Exploit Turns Common Devices into DDoS Weapons
  • Iran APT SpearSpecter Uses Weeks-Long WhatsApp Lures and Fileless TAMECAT Backdoor to Hit Defense
  • EDRKillShifter: A New EDR-Killing Tool in Ransomware Attack
  • Dragon RaaS: Pro-Russian Hacktivist Group Walks the Razor’s Edge Between Cybercrime and Propaganda
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Industrial Safety Systems

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-107459CVSS 9.3
    The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary...
    📅 Updated: Oct 8, 2026
  • CVE-2026-14990CVSS 9.3
    IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed...
    📅 Updated: Oct 8, 2026
  • CVE-2026-14991CVSS 9.8
    IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable...
    📅 Updated: Oct 8, 2026
  • CVE-2026-17635CVSS 9.1
    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102106CVSS 9.1
    Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102105CVSS 9.1
    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102104CVSS 9.1
    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102103CVSS 9.1
    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery...
    📅 Updated: Oct 8, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.