Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-18 Β· updated: 2026-09-18 Β· tags: [incident, energy-utilities] Β· confidence: high Β· severity: medium Β· affected_sectors: [energy-utilities] Β· au_impact: false

CISA published a batch of industrial-control-system advisories on 17 September covering devices used in building management, energy and logistics. Schneider Electric items span the PowerChute serial-shutdown, NetBotz 5 750/755, and Modicon M340 controller and communication modules; ABB covers the Ability Edgenius platform; Hitachi Energy covers its FACTS Control Platform (FCP); and Mitsubishi Electric covers GX Works3 and Motion Control settings. The logistics-relevant item is Bransys ELD, an electronic logging device used in trucking β€” an ICS advisory targeted at the same hardware class that has become a favoured bridge from fleet operations into OT in North America. CISA has not flagged any of these as under active exploitation, and none carries a KEV entry; the batch is a patch-now-against-perimeter advisory set rather than an emergency response. The read across the set is consistent with the week's OT cadence this digest has tracked: reachable remote-management interfaces on infrastructure hardware remain the first line attackers probe, and each of these advisories names weaknesses in that interface layer. Australian utilities and transport operators using the affected products should verify patch status against the vendor advisories.

Attribute Detail
Sector Energy & Utilities
Date 2026-09-18
Source CISA
Reliability Tier 1