•
Three CODESYS vulnerabilities (CVE-2025-41658/59/60) let attackers backdoor Soft PLCs from hundreds of manufacturers. Full attack chain analysis and defensive playbook for OT security teams.