When Compiling Becomes the Payload: The OpenPLC Supply Chain Trap episode artwork

EPISODE · Jul 22, 2026 · 34 MIN

When Compiling Becomes the Payload: The OpenPLC Supply Chain Trap

from Cybersecurity Under Pressure. Real Attacks, Real Lessons · host Antonio Gonzalez

What if the attacker does not deliver malware to your industrial controller? What if your own engineering pipeline builds and deploys it for them?In this episode of Cybersecurity Under Pressure, we examine public research affecting OpenPLC and a more significant problem behind it: the moment when trusted source code, engineering repositories and automated compilation processes become part of the attack path.The research demonstrates a proof-of-concept scenario, not evidence of a confirmed campaign against production environments. However, the implications extend far beyond a laboratory. Industrial integrators increasingly use shared repositories, reusable libraries, automated builds and remote deployment workflows to move control logic from engineering workstations into operational systems.An attacker who compromises source code, an intermediate repository, a dependency or the build environment may not need direct access to the final PLC. The legitimate compiler and deployment process can transform the attacker’s changes into trusted operational code.We explore why scanning the finished binary is not enough, where traditional IT security controls fail to account for industrial engineering workflows, and how signed commits, protected repositories, isolated build environments, reproducible builds, software provenance, deployment approval and runtime monitoring can reduce the risk.The central lesson is uncomfortable: in modern industrial environments, the payload may not arrive from outside. It may be compiled, approved and deployed by the victim’s own trusted process.Follow Cybersecurity Under Pressure: Real Attacks, Real Lessons for practical analysis of the vulnerabilities, engineering decisions and operational dependencies shaping industrial cybersecurity.

Episode metadata supplied by the publisher feed · Published Jul 22, 2026

Embed this episode

Ready to play

When Compiling Becomes the Payload: The OpenPLC Supply Chain Trap

0:00 34:47

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Cybersecurity Under Pressure. Real Attacks, Real Lessons?

This episode is 34 minutes long.

When was this Cybersecurity Under Pressure. Real Attacks, Real Lessons episode published?

This episode was published on July 22, 2026.

Can I download this Cybersecurity Under Pressure. Real Attacks, Real Lessons episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!