#gainetconsult โ Public Fediverse posts
Live and recent posts from across the Fediverse tagged #gainetconsult, aggregated by home.social.
-
๐ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐ถ๐ป ๐ฆ๐ถ๐ฒ๐บ๐ฒ๐ป๐ ๐ฆ๐๐ฃ๐ฅ๐ข๐ง๐๐ ๐ฑ ๐๐ฑ๐ฒ๐ป๐๐ถ๐ณ๐ถ๐ฒ๐ฑ
Our Technical Security Audit team has identified a vulnerability in ๐ฆ๐ถ๐ฒ๐บ๐ฒ๐ป๐ ๐ฆ๐๐ฃ๐ฅ๐ข๐ง๐๐ ๐ฑ ๐ฑ๐ฒ๐๐ถ๐ฐ๐ฒ๐:
โ ๏ธ The USB port may allow attacks due to improper bandwidth limitation.๐ Description:
Affected SIPROTEC 5 devices do not properly limit the bandwidth for incoming network packets over their local USB port. This could allow an attacker with physical access to send specially crafted packets with high bandwidth to the affected devices thus forcing them to exhaust their memory and stop responding to any network traffic via the local USB port. Affected devices reset themselves automatically after a successful attack. During this restart the protection function is not available.๐ The full advisory is available here: https://www.gai-netconsult.de/wp-content/uploads/2025/09/Advisory-GAINC-2025-001-1.0.pdf
โ ๏ธ Please follow the manufacturerโs guidance and updates.
๐ An overview of further advisories can be found on our website: www.gai-netconsult.de/advisories
๐ Congratulations to our colleagues ๐ ๐ฎ๐ฟ๐ฐ ๐๐๐ป๐ and ๐ง๐ผ๐ฟ๐ฎ๐น๐ณ ๐๐ถ๐บ๐ฝ๐ฒ๐น for this discovery.
#CyberSecurity #SecurityAdvisory #Vulnerability #ITSecurity #GAINetConsult #SecurityNotice
-
๐ Practical Industrial Security: Real-World Lessons from Complex HVDC Projects
Weโre excited to announce that our colleague Jan Grotelรผschen (GAI NetConsult GmbH) will be speaking at the Industrial Security Conference 2025 in Copenhagen, alongside Simon Gustafson (Amprion GmbH) and co-author Stephan Beirer (GAI NetConsult GmbH).
๐ค Topic of the presentation:
Staying on course in a volatile environment: OT security in complex large-scale HVDC projects โ a real-life exampleโก At a glance:
Amprion is currently implementing massive offshore grid connection projects such as BorWin4/DolWin4 and BalWin1/BalWin2. These high-voltage direct current (HVDC) lines span up to 380 km and deliver 5.8 GW of power per project โ enough to supply electricity to nearly 6 million people.
In this presentation, the speakers, who are largely responsible for the specification and monitoring of the implementation of OT security for this HVDC project, will present the projects itself and report on the cyber security challenges and lessons learnt.๐ Key OT Security Challenges Covered:
โข Dynamic regulation: Adapting to evolving frameworks like NIS-2, RCE, CRA โ even mid-project
โข Technology vs. longevity: IT/OT convergence meets decades-long system life cycles
โข Managing uncertainty: Constant change in technologies, requirements, and stakeholders๐ This session provides real-world insights into securing critical infrastructure under real conditions โ including what worked, what didnโt, and how lessons learned are shaping better security strategies.
๐ More about the industrial security conference: https://www.linkedin.com/company/industrial-security-conference-cph/posts/?feedView=all
#OTSecurity #CriticalInfrastructure #HVDC #CyberSecurity #EnergyTransition #ICSCPH #GAINetConsult #Amprion #NIS2 #CRA #IndustrialSecurity