zip slip

  1. PCM600 Zip Slip Path Traversal: CISA Warns OT Engineering Workstations

    CISA on May 5, 2026 republished Hitachi Energy’s advisory for a path-traversal flaw in PCM600, warning that affected legacy and 3.x versions can mishandle malicious ZIP archives and allow an attacker to write files outside the intended extraction path. The uncomfortable part is not the CVSS...
  2. AutomationDirect Productivity Vulnerabilities: Patch Now to Stop RCE PLC Attacks

    A coordinated set of high-severity vulnerabilities in AutomationDirect’s Productivity Suite programming software and several Productivity-series PLCs has been disclosed, and operators should treat this as an urgent operational risk: the flaws include multiple path-traversal (ZipSlip) issues, an...