
CVE-2025-67038 in Lantronix EDS5000 serial-to-IP converters is actively exploited in the wild. Forescout confirmed attackers reverse-engineered the firmware patch to build an exploit weeks before public disclosure. CISA added it to the KEV catalog June 23, 2026 with a 72-hour patch deadline.

Nozomi Networks’ analysis of 5.5 million alerts from 10 industrial customers reveals that Sandworm (APT44) systematically exploits already-compromised OT environments. Every infected system gave an average of 43 days of advance warning. After detection, Sandworm escalates — targeting PLCs, HMIs, and engineering workstations directly.

For the first time, Google has confirmed that a cybercrime group used AI to develop a working zero-day exploit. The GTIG AI Threat Tracker reveals autonomous malware, industrialized vulnerability research by nation-states, and polymorphic evasion — with profound implications for OT/ICS defenders.