Intelligence

Briefs and market perspective.

Short pieces on published advisories affecting the control equipment, protocols, and software that industrial sites and grid connections depend on, and market analysis for energy-intensive buyers across South Africa and the SAPP region, drawn from Oshili Power's SAWEM market model.

01

Threat briefs.

Short pieces on published advisories affecting the control equipment, protocols, and software that industrial sites and grid connections depend on. Each brief works from the primary source and links to it.

  1. 17 September 2026

    A tampered backup file can take over the monitor watching a plant room.

    Schneider Electric has fixed two defects in the small appliances that sit in server rooms, switch rooms and plant rooms and watch the conditions inside them: heat, humidity, water on the floor, smoke, vibration, doors left open, and video.
  2. 15 September 2026

    A common security camera hands over its live video, and its maker is not answering.

    A security camera gets bought once and then forgotten.
  3. 13 September 2026

    Saved files from a pipeline monitoring system can give up their users' passwords.

    The files that a pipeline monitoring product saves its work into can be made to hand over the passwords of the people who use it.
  4. 13 September 2026

    A power monitor's fix ships as two files, and the units in the field accept only one.

    CISA, the United States agency that publishes advisories on industrial equipment, has flagged three faults at once in a small power monitoring unit, the kind that sits at a site nobody visits and reports back over the network.
  5. 06 August 2026

    Eight flaws in a common IEC 61850 library end in the same crash.

    CISA published advisory ICSA-26-211-10 on 30 July, covering libiec61850 from MZ Automation. Eight defects, one outcome.
  6. 06 August 2026

    A crafted telecontrol frame can crash devices running lib60870 2.4.0.

    CISA published advisory ICSA-26-211-11 on 30 July 2026, covering two out-of-bounds read defects in MZ Automation's lib60870, version 2.4.0.
  7. 06 August 2026

    An unauthenticated debug service gives root on two Toptech controllers.

    CISA published advisory ICSA-26-211-03 on 30 July, then reissued it on 5 August with the mitigation section revised.