Cybersecurity firm Trellix has highlighted a growing risk in operational technology (OT) environments, particularly within critical infrastructure, due to an increasing number of cataloged vulnerabilities and persistent delays in patching. Programmable logic controllers (PLCs) are being increasingly targeted by attackers, with insecure remote connectivity devices providing new pathways for exploitation. A notable vulnerability, CVE-2025-7353, was identified in Rockwell ControlLogix Ethernet modules, which could allow remote code execution, enabling attackers to tamper with or halt processor communications, inject malicious logic, or disable safety functions without engineering credentials. The average time from vulnerability disclosure to patch deployment in OT environments now exceeds 180 days, significantly increasing exposure.
Legacy equipment prevalent in critical infrastructure further compounds these risks, as such systems are often difficult to update and maintain. The Trellix report underscores that attackers are exploiting these weaknesses for both political and destructive purposes, emphasizing the urgent need for improved patch management and security controls in OT networks. The situation is exacerbated by the complexity of patching OT devices compared to traditional IT systems, leaving critical infrastructure operators vulnerable to potentially severe disruptions and safety risks.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
To mitigate OT threats, Trellix recommended stronger network segmentation, zero-trust security, threat intelligence sharing, and stricter vendor requirements. These measures were presented as responses to the growing intentional targeting of OT environments.
Trellix said attackers are actively exploiting weaknesses in legacy OT protocols including Modbus, DNP3, proprietary SCADA protocols, and programmable logic controllers. The report also warned that some attacks have targeted safety systems in attempts to corrupt or disable them.
The report described threat actors exploiting weak IT/OT connections using tools and techniques such as Cobalt Strike, PowerShell, stolen credentials, and protocol scanning to move laterally. It said attackers increasingly compromise intermediary devices bridging IT and OT rather than directly targeting industrial controllers.
A Trellix report found that manufacturing accounted for 42% of OT-related detections among critical infrastructure clients, indicating it remained the most targeted sector for operational technology attacks. The report said OT incidents have shifted from accidental IT spillover to deliberate campaigns by criminal and state-backed actors.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.