This week, three very different systems reached the same security boundary. An industrial firewall depends on third-party software. A PLC depends on legitimate engineering access. An automotive head unit depends on infrastructure authorised to install new software. None of those paths is inherently a weakness. The problem appears when a trusted mechanism retains enough authority to change the system after trust in the infrastructure behind it has been lost.
The pattern this week
A legitimate path can become an attack path without changing its function.
RUGGEDCOMThird-party software trustedUpstream vulnerabilities become an industrial lifecycle decision.
→
Siemens S7Engineering path reachableAttack tooling matters when it reaches process authority.
→
Automotive head unitUpdate mechanism trustedCompromised upstream authority can turn distribution into malware delivery.
Common gap: the attack surface includes not only where an attacker can enter, but where trusted authority can still change the system.
01
OT & ICS · Industrial Network Security · Supply Chain
RUGGEDCOM: the vulnerability belongs to FortiOS. The lifecycle decision belongs to the industrial system.
Siemens maps FortiOS vulnerabilities to RUGGEDCOM APE1808 deployments and provides supported remediation paths. That translation matters because an asset owner may know the model, address, network zone and operational function of an industrial appliance while still lacking visibility into the third-party software running inside it. The vulnerability originates upstream, but the operational change risk remains in the plant. SBOM, VEX and supplier advisories become useful only when they can connect a software dependency to an exact deployed product, version and operational role.
DecisionMove software-transparency obligations upstream into procurement. Require maintainable, version-linked composition and vulnerability evidence from the supplier responsible for the delivered industrial product.
Siemens S7: AI changes attacker speed. Process authority determines the consequence.
Recent reporting around Siemens S7 targeting has highlighted AI-assisted attack tooling. That is relevant, but it is not the decisive security property. A generated script only becomes an OT event when it can reach a controller, cross the required engineering or network boundary and exercise authority capable of changing process state. The more useful defensive question is which controllers are reachable, through which conduits, from which identities and with what state-changing capability.
DecisionPrioritise control of process authority. Remove direct PLC exposure, constrain engineering conduits and identities, and detect unauthorised state-changing behaviour before optimising controls around how the attack tooling was generated.
Automotive head units: the updater can work exactly as designed and still deliver malware.
Kaspersky reconstructed a malware chain distributed through built-in firmware-update mechanisms on Android automotive head units. The documented objective was proxy-botnet and advertising-fraud activity, not control of safety-critical vehicle functions. The architectural lesson is still important: the update mechanism did not need to be bypassed. A legitimate mechanism became the delivery path because authority upstream could no longer be trusted. Release approval, supplier identities, distribution infrastructure, signing, provenance and revocation therefore become part of product security.
DecisionTreat automotive update infrastructure as product-security authority. Protect release approval, distribution identities, signing and provenance separately, and design recovery so that it does not depend entirely on the service whose trust may have been lost.
Which trusted path in your architecture can still change the system after you stop trusting it?
Look beyond exposed services. Map the mechanisms with legitimate state-changing authority: engineering access, remote maintenance, update infrastructure, supplier services, management platforms and privileged identities. For each one, define what it can change, how that authority is constrained, how it can be revoked and what independent evidence proves that the resulting state is trustworthy.