Threat landscape for industrial automation systems. Q2 2026
B Securelist ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
The report provides a quarterly overview of the threat landscape for industrial automation systems and documents new APT malware attributed to Mirage Kitten, which is strategically relevant for production environments.
Description
The Securelist report describes the threat landscape for industrial automation systems in the second quarter of 2026. It summarizes attack vectors such as malicious scripts, phishing pages, malicious documents, spyware, ransomware, and worms, and categorizes them by industry and region. It also presents new campaigns, including an Armored Likho campaign with a Still Toolkit for stealing Telegram data, as well as backdoors and tunneling tools attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore). The analysis is based on telemetry from ICS computers and shows regional focuses such as East Asia and the biometrics sector. No specific vulnerabilities or patch information are named.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.10
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 15.00
- vendor mismatch penalty
- 0.00
Path: operational