Sunday, May 31, 2026

Review - Public ICS Disclosures – Week of 5-23-26 – Part 2

For Part 2 we have 12 additional vendor disclosures from Hitachi Energy (3), JUMO, MB connect (2), METTLER TOLEDO, Moxa, NI, Phoenix Contact, and QNAP (2). 

Advisories  

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their ITT600 Explorer product. 

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that describes a heap-based buffer overflow vulnerability in their MACH HiDraw product. 

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that describes four vulnerabilities in their RTU500 product. 

JUMO Advisory - CERT-VDE published an advisory that discusses an improper input validation vulnerability (with publicly available exploit) in multiple JUMO products. 

MB connect Advisory #1 MB connect published an advisory that describes an SQL injection vulnerability in their mbCONNECT24 and mymbCONNECT24 products. 

MB connect Advisory #2 MB connect published an advisory that describes two vulnerabilities in in their mbNET/mbNET.rokey and mbNET.mini products. 

METTLER TOLEDO Advisory - CERT-VDE published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their EVA Karl Fischer titrator software. 

Moxa Advisory - Moxa published an advisory that discusses the Copy Fail and Dirty Frag vulnerabilities. 

NI Advisory NI published an advisory that describes a missing authentication for critical function vulnerability in their SystemLink Enterprise product. 

Phoenix Contact Advisory Phoenix Contact published an advisory that describes two vulnerabilities in their PLCnext firmware. 

QNAP Advisory #1 QNAP published an advisory that discusses the Dirty Frag vulnerabilities. 

QNAP Advisory #2 - QNAP published an advisory that discusses the Copy Fail vulnerability. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-f0a - subscription required. 

Saturday, May 30, 2026

Chemical Incident Reporting – Week of 5-23-26

NOTE: See here for series background. 

Yates Center, KS – 5-23-26  

Local News Report: Here and here. 

There was a small chlorine gas leak at a water treatment plant. The leak occurred during the change out of a chlorine gas bottle. One person was transported to the hospital with ‘accute chlorine exposure’. 

Possible CSB reportable. 

Fairview, OR – 5-25-26  

Local News Report: Herehere, and here. 

There was an anhydrous ammonia leak at an agricultural facility in town. One person was treated on site for exposure issues. 

Not CSB reportable. 

Bradley County, TN – 5-26-26  

Local News Report: Herehere, and here. 

There was a titanium powder flash fire in a manufacturing facility. The plant plans to be closed for 5 to 6 weeks to address safety issues. No injuries were reported. 

Not CSB reportable. 

Thorntown, IN – 5-26-26  

Local News Report: Herehere, and here. 

There was an anhydrous ammonia release from a portable agricultural tank. A nearby campground was evacuated as a precautionary measure. Two people self-transported to the local hospital for exposure issues. 

Not CSB reportable; this was a transportation related incident. 

Stickney, IL – 5-29-26  

Local News Report: Herehere, and here. 

There was an explosion and a fire at a chemical plant. No reports of injuries. 

Possible CSB reportable. 


For additional incident reports see “Weekly U.S. Hazmat Intelligence Briefing”  

 
/* Use this with templates/template-twocol.html */