Firmware 4.21 Alone Won't Close the M580 Safety Bypass
Schneider's notification for CVE-2026-3869 makes the fix a firmware version plus a rebuilt project, and on a SIL3 controller the rebuild is the slow half.
Field Notes · Topic
Articles tagged “OT security” on the Zoniax blog — field notes on industrial operations intelligence.
Schneider's notification for CVE-2026-3869 makes the fix a firmware version plus a rebuilt project, and on a SIL3 controller the rebuild is the slow half.
AI-written exploit scripts now masquerade as OT monitoring on the S7comm wire. Three defensive postures, and where each earns its keep.
Seven U.S. agencies updated their advisory on attackers rewriting the logic inside internet-exposed controllers; read from the control room, it's a story about an open door and a project file you filed as a backup.
Brussels just put AI on both sides of the plant firewall. Read from the control room, the EU's new Cyber-AI Action Plan is part threat model, part toolkit.
ENISA just shipped a five-domain maturity model for the Cyber Resilience Act, and read against a real processing line it works less like a scorecard than a gap list.
From 11 September 2026, the maker of every connected industrial device owes Europe an early warning within 24 hours of an exploited flaw - and the plant is usually where that flaw is seen first.
A field note on putting a language model in the rack: the hardware, the memory-bandwidth wall, the heat, and why the box never closes a control loop.
Six claims that ride in on the agentic AI procurement deck, and why each one breaks against a deterministic control room.
Who owns the data your machines produce, who may see it, and how to keep it trustworthy from the sensor to the boardroom.
How the EU's NIS2 directive turns into concrete OT controls on a processing plant floor, built in the order that actually works.