Advanced Vulnerability Information Sharing ... A Success Story

Maggie Morganti

S4x24 - ICS Security Conference · Day 2 · Main Stage

Overview

Maggie Morganti's talk at S4x24 details an unprecedented success story in advanced vulnerability information sharing within the Industrial Control Systems (ICS) domain. The presentation chronicles Rockwell Automation's experience in early 2023 when the US government provided early warning about an Advanced Persistent Threat (APT) actively developing an exploit against critical Rockwell communications modules. This talk is not merely about a specific vulnerability, but rather a profound exploration of how a multi-vendor, cross-government collaboration was forged and executed under immense pressure to protect global critical infrastructure.

Watch on YouTube

Visual summary for Advanced Vulnerability Information Sharing ... A Success Story by Maggie Morganti
Visual summary for Advanced Vulnerability Information Sharing ... A Success Story by Maggie Morganti

Key moments

  1. 0:55 Story begins: 'I'm from the government and I'm here to help.'
  2. 1:35 APT developing exploit against Rockwell communication modules.
  3. 2:40 The trade-off: early warning means no attribution or IOCs.
  4. 4:50 Contrasting public and behind-the-scenes incident response.
  5. 5:10 Realizing the necessity for broader industry collaboration.

Advanced Vulnerability Information Sharing ... A Success Story

Speakers: Maggie Morganti

Conference: S4

YouTube: https://www.youtube.com/watch?v=qYcf5qPPi0I

Overview

Maggie Morganti's talk at S4x24 details an unprecedented success story in advanced vulnerability information sharing within the Industrial Control Systems (ICS) domain. The presentation chronicles Rockwell Automation's experience in early 2023 when the US government provided early warning about an Advanced Persistent Threat (APT) actively developing an exploit against critical Rockwell communications modules. This talk is not merely about a specific vulnerability, but rather a profound exploration of how a multi-vendor, cross-government collaboration was forged and executed under immense pressure to protect global critical infrastructure.

Morganti, representing Rockwell Automation, candidly shares the internal anxieties and strategic decisions that led to an expansive, trust-based partnership involving numerous leading security vendors. This initiative aimed to synchronize the development and deployment of patches and mitigations before public disclosure, thereby minimizing the window of opportunity for the APT to leverage its exploit. The narrative highlights the critical role of pre-existing relationships and mutual trust in enabling competitors to work together for a common, higher purpose, setting a new benchmark for coordinated vulnerability response in the ICS landscape.

The significance of this talk extends beyond the immediate incident. It serves as a blueprint for future complex threat scenarios, offering invaluable lessons on how to navigate the intricate challenges of classified intelligence, competitive business incentives, and the imperative to safeguard operational technology. Morganti's story underscores that proactive, collaborative defense is not just an ideal but an achievable reality, even against sophisticated nation-state adversaries targeting the most sensitive industrial environments.

Background

▶ Watch: Story begins: 'I'm from the government and I'm here to help.' (0:55)

The genesis of this extraordinary collaboration traces back to early 2023, when Maggie Morganti, a key figure at Rockwell Automation, received an urgent, cryptic meeting invitation from her boss, Tony Baker, indicating an "external US government" subject. The subsequent call revealed a sobering reality: the US government had observed an Advanced Persistent Threat (APT) actively developing a highly potent exploit targeting Rockwell Automation's widely deployed communications modules. This intelligence, while invaluable, came with significant constraints, including the inability to share specific details about attribution, Indicators of Compromise (IOCs), or the exact discovery methodology. This limitation meant that Rockwell and its partners had to act on high-level intelligence without full visibility into the threat actor's identity or specific tactics.

The targeted products were Rockwell Automation's EN2 and EN3 communications modules, which were vulnerable to a "pretty nasty" Remote Code Execution (RCE) exploit, and EN4 modules, susceptible to a "slightly less nasty but very similar" Denial of Service (DoS) attack. These modules are described as "prolific across Rockwell deployments," meaning a successful exploit could have widespread, severe implications for critical infrastructure globally. The inherent risk in the ICS space is a constant underlying concern for OEMs like Rockwell Automation, as they are acutely aware of continuous efforts by malicious actors to weaponize their products against customers and critical systems.

Initially, Rockwell Automation began its standard response process, collaborating with the US government and established partners like Dragos and Clarity to analyze the exploit, develop fixes, and formulate mitigation rules. However, a critical realization emerged during this phase: this traditional, somewhat limited partnership would not suffice. There was a profound fear that upon public disclosure, the threat actors would have a significant window to execute their exploit before customers could patch or deploy effective mitigations. Morganti highlighted the concern that adversaries might calculate, "it's going to take Mandiant 72 hours to write rules for this. It's going to take... four weeks on a good day for us to patch this. And so we've got, we've got time to actually go use this before we lose it." This acute awareness of the attacker's potential advantage necessitated a radical departure from conventional vulnerability response strategies, pushing Rockwell to propose an unprecedented level of cross-industry collaboration.

Key Findings

▶ Watch: APT developing exploit against Rockwell communication modules. (1:35)

The central and most significant finding of this initiative is the resounding success of an advanced, multi-vendor collaboration model for proactive vulnerability information sharing in the face of an imminent APT threat to critical infrastructure. Despite inherent competitive pressures and the absence of formal legal frameworks (operating under "Fight Club rules and good faith"), Rockwell Automation, the US government, and leading security vendors successfully coordinated a comprehensive defensive strategy.

Specifically, the collaboration addressed vulnerabilities involving malicious packet messages that could lead to Remote Code Execution (RCE) on Rockwell EN2 and EN3 communications modules and Denial of Service (DoS) on EN4 modules. The key to success was the ability to bring together a broader ecosystem of security companies, including Dragos, Clarity, and Mandiant, to develop and deploy detection and mitigation capabilities simultaneously with Rockwell's patch development. This synchronized effort drastically reduced the "window of opportunity" for the APT to exploit the vulnerabilities post-disclosure.

A crucial enabler for this collaboration was the existence of pre-established relationships and trust among the participating individuals and organizations. Morganti explicitly states, "I don't think this would have worked had everyone been strangers." Events like S4, where security professionals from competing companies build personal and professional rapport, proved invaluable. This existing network of trust allowed for difficult conversations about risk and sharing sensitive, pre-disclosure information without fear of competitive exploitation or premature leaks, which could have had catastrophic consequences for customers. The successful outcome demonstrated that, under the right circumstances and with a shared understanding of the stakes, the collective defense of critical infrastructure can transcend individual corporate interests.

Technical Deep Dive

▶ Watch: The trade-off: early warning means no attribution or IOCs. (2:40)

The technical core of the vulnerability revolved around malicious packet messages targeting specific Rockwell Automation communications modules. These modules, namely the EN2, EN3, and EN4 series, are described as "prolific across Rockwell deployments," indicating their widespread use in Industrial Control Systems (ICS) environments. Their ubiquity makes them attractive targets for APTs seeking to disrupt or gain control over critical infrastructure.

For the EN2 and EN3 communications modules, the malicious packet messages could lead to a "pretty nasty" Remote Code Execution (RCE) exploit. RCE is one of the most severe types of vulnerabilities, as it allows an attacker to execute arbitrary code on the affected device. In an ICS context, successful RCE on a communications module could grant an adversary deep access into the operational network, potentially enabling them to:

  • Manipulate industrial processes directly.
  • Exfiltrate sensitive operational data.
  • Deploy persistent malware for long-term espionage or sabotage.
  • Pivot to other critical assets within the control system, escalating the attack's scope and impact.

The ability to achieve RCE on these modules signifies a direct threat to the integrity and availability of industrial operations they control.

For the EN4 communications modules, the same type of malicious packet messages could induce a "slightly less nasty but very similar" Denial of Service (DoS) attack. While less severe than RCE, a DoS attack on critical ICS components can still have profound operational consequences, including:

  • Disruption of communication between controllers and other devices, leading to loss of monitoring or control.
  • Halting of production processes, resulting in significant economic losses.
  • Creating unsafe conditions if operators lose visibility or control over critical parameters.
  • Masking more sophisticated attacks by overwhelming defensive systems with noise.

The early warning from the US government indicated that an APT was developing this exploit. This is a crucial detail, implying that the threat was not yet widely deployed or publicly known, essentially a zero-day threat in the making. This pre-emptive intelligence allowed Rockwell and its partners to act proactively, developing patches and mitigation rules before the exploit could be fully operationalized and widely used by the adversary. The nature of "malicious packet messages" suggests that the exploit likely involved malformed or specially crafted network packets designed to trigger vulnerabilities in the modules' firmware or network stack, bypassing standard security controls and exploiting parsing errors or buffer overflows. However, specific details such as CVE numbers, exact protocols, or the precise nature of the packet anomalies were not disclosed due likely to the classified nature of the initial intelligence.

The challenge was not only to fix the vulnerabilities but also to enable the broader ecosystem to detect and prevent exploitation across diverse customer environments without revealing the full extent of the threat prematurely. This required deep technical collaboration on rule development, ensuring that detection logic was robust and effective across various security platforms without exposing the underlying intelligence.

Demo / Proof of Concept

▶ Watch: Contrasting public and behind-the-scenes incident response. (4:50)

The talk focused on the process of information sharing and collaborative defense rather than a technical demonstration of the exploit or a proof of concept. No demo or PoC was described or presented during the session.

Defensive Implications

▶ Watch: Realizing the necessity for broader industry collaboration. (5:10)

The success story of this advanced vulnerability information sharing initiative provides several critical defensive implications for organizations operating in the ICS/OT space:

  1. Prioritize Patching and Firmware Updates: The primary defense against vulnerabilities like the RCE and DoS exploits targeting Rockwell EN2, EN3, and EN4 modules is the prompt application of vendor-provided patches and firmware updates. Organizations must maintain robust patch management programs for their OT environments, understanding that these are not merely IT systems but integral to physical operations.
  2. Implement Robust Network Segmentation: The fact that malicious packet messages were the attack vector underscores the importance of network segmentation. By isolating critical ICS assets and communications modules from less trusted networks, organizations can significantly limit the lateral movement of an attacker and reduce the blast radius of any successful exploit.
  3. Deploy Advanced Detection and Prevention Capabilities: The collaboration with security vendors like Dragos, Clarity, and Mandiant resulted in the development of mitigation rules. This highlights the need for organizations to deploy and configure specialized Industrial Intrusion Detection/Prevention Systems (IDPS) and Network Monitoring Solutions capable of identifying and blocking anomalous or malicious packet messages targeting ICS protocols and devices. These systems should be regularly updated with threat intelligence from trusted sources.
  4. Foster Government-Industry Partnerships: The entire initiative was sparked by early warning from the US government. This emphasizes the invaluable role of strong, trusted relationships between critical infrastructure operators, OEMs, and government intelligence agencies. Organizations should actively participate in information sharing and analysis centers (ISACs) and other government-sponsored programs to receive timely and actionable threat intelligence.
  5. Cultivate Cross-Vendor Collaboration and Trust: The talk powerfully demonstrates that even competing security vendors can and must collaborate for the greater good of critical infrastructure. Defenders should advocate for and participate in initiatives that build trust and facilitate information sharing across the industry. This includes attending conferences like S4, which foster personal relationships that are crucial when high-stakes, "Fight Club rules" collaboration becomes necessary.
  6. Develop Proactive Incident Response Plans: The "crippling anxiety" described by Morganti highlights the intense pressure during such events. Organizations need to have well-defined incident response plans that account for complex, multi-party disclosures and potential zero-day threats. These plans should include clear communication protocols, decision-making frameworks, and pre-identified trusted partners.
  7. Understand the Threat Landscape: Recognizing that APTs are constantly developing exploits against ICS products should be a fundamental assumption for any critical infrastructure operator. This understanding should drive continuous security improvements, risk assessments, and a proactive defense posture rather than a reactive one.

Key Takeaways

  • Unprecedented Collaboration is Possible and Essential: The successful multi-vendor and government-industry collaboration demonstrated that competing entities can unite under "Fight Club rules and good faith" to protect critical infrastructure from advanced threats.
  • Early Warning is Invaluable: Pre-emptive intelligence from government partners provides a crucial advantage, allowing for proactive defense development and minimizing the window of opportunity for APTs.
  • Trust and Relationships are Foundational: Pre-existing personal and professional relationships among security leaders are vital for enabling rapid, high-stakes information sharing and collaboration when formal frameworks are insufficient.
  • Synchronized Defense Reduces Risk: Coordinated development and deployment of patches and mitigation rules across an ecosystem, before public disclosure, significantly enhances collective defense capabilities and protects customers.
  • ICS Threats Demand Tailored Responses: The specific nature of vulnerabilities (RCE, DoS via malicious packet messages) in critical communications modules highlights the need for specialized ICS security expertise and targeted defensive strategies.
  • The "So What" is the Process: The true success story lies not just in addressing a vulnerability, but in establishing a viable model for advanced, trust-based information sharing that can be replicated for future complex threats.

About the Speaker(s)

Maggie Morganti is a professional at Rockwell Automation, where she is deeply involved in the company's vulnerability management and security response processes. Her role places her at the forefront of critical industrial cybersecurity initiatives, including interactions with government agencies and industry partners. As evidenced by this talk, she is dedicated to fostering advanced information sharing and collaborative defense strategies to protect critical infrastructure from sophisticated threats. Her boss, Tony Baker, was also mentioned as a key figure in the initial government outreach.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Maggie Morganti's talk is a rare, unvarnished look at how critical infrastructure defenders can, and must, collaborate under extreme pressure. It details an unprecedented multi-vendor, cross-government effort to preemptively counter an APT's zero-day exploit targeting Rockwell's ICS modules. Operating under 'Fight Club rules and good faith,' this initiative didn't just solve a vulnerability; it forged a new, effective blueprint for synchronized, proactive defense against nation-state threats, driven by trust and a shared understanding of the stakes. This isn't just a success story; it's a operational paradigm shift.

Heather Calloway (CISO) — MUST SEE

This talk from Maggie Morganti is a rare and essential account of how advanced, trust-based collaboration can preempt a nation-state threat to critical infrastructure. It is a blueprint for institutional action and collective defense, demonstrating that proactive risk management and synchronized mitigation are achievable, even under immense pressure and without formal frameworks. Every CISO and security leader, particularly those in critical sectors, needs to understand the model it presents.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference