The Cybersecurity and Infrastructure Security Agency (CISA) released seven new advisories detailing vulnerabilities affecting a range of industrial control system (ICS) products from vendors such as Güralp Systems, Johnson Controls, Hitachi Energy, Mitsubishi Electric, ICONICS, and Fuji Electric. Among these, a notable vulnerability in Mitsubishi Electric GT Designer3 (CVE-2025-11009) allows attackers to obtain plaintext credentials from project files, potentially enabling unauthorized operation of GOT2000 and GOT1000 series devices. CISA urges administrators to review the technical details and apply recommended mitigations to protect critical manufacturing and infrastructure sectors.
Additional reporting from the Canadian Centre for Cyber Security highlights the same CISA advisories, emphasizing the need for organizations to address vulnerabilities in products like Johnson Controls iSTAR and others. The advisories provide actionable guidance for mitigating risks associated with these ICS vulnerabilities, underscoring the importance of timely updates and security best practices for operators of affected systems worldwide.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On December 16, 2025, CISA published advisory ICSA-25-350-04 for CVE-2025-11009 in Mitsubishi Electric GT Designer3, affecting all versions for GOT2000 and GOT1000 series. The medium-severity flaw involves cleartext storage of credentials in project files, and Mitsubishi Electric and CISA recommended segmentation, firewalls, VPNs, antivirus, and avoiding untrusted files.
On December 16, 2025, CISA released six new industrial control systems advisories addressing vulnerabilities in products from Güralp Systems, Johnson Controls, Hitachi Energy, Mitsubishi Electric, and Fuji Electric. The advisories provided technical details and recommended mitigations, with no active exploitation noted.
Between December 8 and 14, 2025, CISA released multiple ICS security advisories covering vulnerabilities in products from AzeoTech, Festo, Grassroots, Johnson Controls, several India-based CCTV camera brands, OpenPLC, Siemens, U-Boot on Qualcomm chips, and Varex Imaging. The advisories included mitigation guidance and urged administrators to apply available updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.