LIVE · cybersecurity feed
Live wire
industrial automationmedium

Threat landscape for industrial automation systems. Q1 2026

In the first quarter of 2026, the overall percentage of industrial control systems (ICS) computers experiencing malware infections continued its downward trend, reaching a three-year low. However, certain regions and industries, particularly biometric systems and manufacturing, saw increases in specific threat categories like spyware and internet-based threats. While ransomware and malicious documents saw significant decreases, malicious scripts, phishing pages, and denylisted internet resources remained prevalent.

zeroday.news · 25d ago

The first quarter of 2026 saw a continued decline in the overall percentage of industrial control systems (ICS) computers affected by malicious objects, hitting a low of 19.6%. This marks the lowest figure in three years, a significant decrease from previous periods. Regionally, Northern Europe reported the lowest infection rate at 9.1%, while Africa experienced the highest at 27.4%. Despite the overall downward trend, five regions, including Southern Europe, Northern Europe, and Russia, observed an increase in blocked malicious objects. Southern Europe, in particular, saw notable growth in internet and email threats, as well as spyware and phishing pages.

Biometric systems consistently ranked highest among industries for ICS computer infections, with 26.4% of systems affected. This vulnerability is attributed to their internet connectivity, extensive email usage for data exchange, and often minimal cybersecurity controls. Biometric systems also led in email threats, surpassing internet threats, a unique characteristic compared to other industries. While most industries followed the global downward trend, the manufacturing sector experienced a slight increase of 1.0 percentage point in infections, with notable rises in Western Europe, Northern Europe, and Russia.

Kaspersky security solutions blocked malware from over 10,000 families on ICS in Q1 2026. Denylisted internet resources saw an increase after a prior decline, alongside a slight rise in AutoCAD malware. Malicious scripts and phishing pages remained a significant threat category, with a global average of 6.56% of ICS computers affected. Southern Europe showed the most substantial increase in these threats. Biometric and building automation systems, particularly in Southern Europe, recorded the highest percentages for malicious scripts and phishing pages.

Spyware, despite a recent decline to 3.73%, maintained its position as the second-highest threat category. Increases in spyware infections were observed in Southern Europe and Russia, affecting most industries except manufacturing in Southern Europe and construction in Russia. The oil and gas industry, along with engineering and ICS integration sectors, have seen consistent increases in spyware over the past six months and three quarters, respectively.

Denylisted internet resources saw an increase to 3.54%, with Southeast Asia experiencing the most significant rise. Electric power and construction industries in Southeast Asia reported the highest percentages for this threat. North America also noted a substantial increase in denylisted internet resources. Malicious documents, including Microsoft Office and PDF threats, reached a record low of 1.56%, with only Australia/New Zealand and Russia showing slight increases. Ransomware infections also dropped to a low of 0.14%, with minimal increases reported in North America and Northern Europe.

Miners in the form of executable files for Windows decreased to 0.59%, though several regions, including Africa, saw increases. Construction, biometric systems, and the oil and gas industry in Central Asia and the South Caucasus reported the highest percentages for these miners. Web miners continued their year-long decline, reaching 0.22%, but saw increases in South Asia, the Middle East, and Africa. Worm infections decreased to 1.33% across all regions, following a previous increase attributed to a widespread backdoor worm. Biometric systems in Central Asia and the South Caucasus reported the highest percentage for worms.

industrial automationics securitymalware trendsthreat landscapecyber threats
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.