Nozomi Networks Labs

Headquartered in Mendrisio, Switzerland, with honeypots around the globe, the Nozomi Networks Labs team comprises threat hunters and security analysts who are dedicated to reducing cyber risk for industrial and critical infrastructure organizations. We responsibly disclose vulnerabilities and share our research findings the global OT security community.

A room, likely a laboratory or training facility, is filled with numerous black metal racks. Each rack is densely packed with various electronic components, including circuit boards, processors, and other hardware.

What We Do

The icon of an eye with several circles connected to it

Vulnerability Advisories

Nozomi Networks Labs is the first specialized OT and IoT cybersecurity research lab to be named an authorized CVE Numbering Authority. Since 2020 we have worked with authorities to responsibly disclose hundreds of vulnerabilities in critical OT/ICS devices.

View Advisories
The icon of a stopwatch

Threat Research

Our reports assess the OT/IoT threat landscape, cull insights from anonymized telemetry, and analyze malware samples, insecure protocols and other threats to industrial and critical infrastructure environments.

View Research Reports
The icon of a alert sign along with the search icon close to it

Threat Intelligence

Our curated threat and vulnerability insights are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.

Learn More

Vulnerability Advisories

CVE ID
CVE-2025-11243
Vendor
Shelly
Product
Pro 4PM
Date Published
November 18, 2025
Learn More
CVE ID
CVE-2025-12056
Vendor
Shelly
Product
Pro 3EM
Date Published
November 18, 2025
Learn More
CVE ID
CVE-2025-11678
Vendor
warmcat
Product
libwebsockets
Date Published
October 10, 2025
Learn More
CVE ID
CVE-2025-11680
Vendor
warmcat
Product
libwebsockets
Date Published
October 10, 2025
Learn More
CVE ID
CVE-2025-11677
Vendor
warmcat
Product
libwebsockets
Date Published
October 10, 2025
Learn More
CVE ID
CVE-2025-11679
Vendor
warmcat
Product
libwebsockets
Date Published
October 10, 2025
Learn More

Our Mendrisio Lab: Nozomi Networks Global R&D Headquarters

Marty the OT Guy shows you around the Mendrisio R&D headquarters, home to Nozomi Networks Labs researchers. Explore Nozomiville, a cityscape that our security researchers use to demonstrate attack scenarios across common technologies in use in cities across the world, including power distribution, smart metering, traffic light control, Wi-Fi and more.

Latest Labs Blogs

Breaking the Encryption: Analyzing the AutomationDirect CLICK Plus PLC Protocol 

Read

Lights Out: How One Tiny Message Can Crash Your Shelly Pro 4PM and Lock You Out of Your Smart Home

Read

Hacking the Engineer’s Workstation: Compromising AutomationDirect Productivity Suite to Breach the OT Perimeter

Read

Partnerships and Threat Intelligence Communities

Active member of the Cyber Threat Alliance, contributing to real-time threat intelligence sharing and strengthening collective cybersecurity defenses.

Leveraging Mandiant's threat intelligence to enrich our data, enhancing visibility and strengthening protection across our products for an undisputed defense.

Founders of the Elite Cyber Defenders program, collaborating with industry leaders like Mandiant and IBM X-Force to exchange real-time threat intelligence and field-generated telemetry, enhancing cybersecurity visibility and defense.

Partnering with CISA through JCDC and AIS to access and leverage real-time threat intelligence, enhancing proactive defense and resilience against cyber threats.

Partnering with MTS-ISAC to consume and integrate its intelligence, enhancing our threat detection capabilities and providing stronger security for connected operational environments.

Founding partner of ETHOS, driving real-time threat intelligence sharing to enhance early detection and strengthen cybersecurity across critical industries.

"Threat actors love finding new ways to attack critical infrastructure. We love finding new ways to detect their malware before damage occurs."
Andrea Carcano & Moreno Carullo
Co-founders, Nozomi

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.