< ciso
brief />
Tag Banner

All news with #ot security tag

377 articles

OT Coalition Urges CISA to Mandate Federal OT Security

🔐 The Operational Technology Cybersecurity Coalition (OTCC) urged CISA to issue a binding operational directive requiring mandatory OT security across federal civilian agencies, citing lack of minimum practices and limited visibility into risks. The report highlights OT in over 8,000 GSA-managed facilities and follows a GAO finding that most agencies missed OMB inventory requirements. The proposed directive would set baselines for asset inventory, segmentation, remote access, configuration, incident preparedness and recovery.
read more →

Most Medical Devices Unready for PQC Transition

🔒 A Forescout investigation across 50+ healthcare delivery organizations found most medical devices cannot be upgraded to post-quantum cryptography, leaving sensitive healthcare data at risk of future quantum-enabled decryption. Only 6% of IoMT and 16% of medical OT devices use SSH implementations that could support PQC, compared with around 50% of traditional IT devices. The report highlights exposed systems holding EMRs and PACS and urges immediate inventory, segmentation, TLS 1.3 enforcement and vendor engagement to prepare for quantum threats.
read more →

Cling botnet leverages STUN to hide C2 activity

🔍 Nozomi Networks observed attackers exploiting a patched critical Realtek Jungle SDK RCE (CVE-2021-35394) starting around September 5, 2026, to deploy a botnet named Cling. The malware repurposes ordinary STUN traffic as a covert command-and-control channel, enabling propagation, proxying, tunneling and denial-of-service actions while resembling legitimate NAT-traversal activity. Samples embed multiple exploit payloads targeting routers and DVRs from various vendors and use persistence techniques like replacing wget and modifying init scripts.
read more →

OT Resilience Becomes a Boardroom Imperative

🔒 The long-standing assumption that operational technology (OT) is safe due to physical isolation is no longer valid. Integration of OT with IT and cloud has exposed nearly 20 million OT assets online, increasing risk and making operational resilience a strategic concern. Modern industrial environments require continuous verification, micro-segmentation, and governance to protect safety, availability, and business continuity.
read more →

Mixed Device Segments Increase Lateral Movement Risk

🔍 Forescout's analysis of 47,700 real-world network segments found many contain mixed device types—IT, OT, IoT and IoMT—broadening attack surfaces and increasing lateral movement risk. The study shows only a minority of OT or IoMT segments are isolated, with common co-location like IP cameras alongside workstations enabling single-point compromises. Forescout recommends continuous visibility, device prioritization, tighter segmentation and policy-based controls to prevent breaches spreading to critical systems.
read more →

US agencies investigate cyber intrusion on supertanker

🚢 The US Coast Guard and FBI boarded the Liberian-flagged VL Prosperity after indications its network may have been compromised during a voyage from Egypt to Galveston. The alleged intrusion reportedly affected fuel systems, engine speed and communications for about 30 hours before a specialised team spent four days eradicating the threat. Authorities report no injuries or environmental impact while urging stronger cyber hygiene and network segmentation.
read more →

Securing Unpatchable Systems Amid AI-Driven Finding

🔒 AI-assisted analysis is exposing decades of unpatched technical debt, leaving operational technology and legacy systems with known vulnerabilities that cannot easily be fixed. Inventory and visibility enable identification of at-risk devices, while network controls such as micro-segmentation, VLANs, ACLs, and NGFW/IPS provide compensating protections. Full air-gapping or data diodes can help but are often bypassed in practice, so defenders must assume imperfect isolation and apply layered controls and monitoring.
read more →

Fortinet Joins Project Watershed to Secure Water Systems

💧Fortinet joined federal, state, and industry partners on August 31 to launch Project Watershed 250, a six-month pilot in Texas aimed at strengthening water and wastewater cybersecurity. The program offers participating utilities red-team testing, system assessments, hardening support, threat intelligence, and AI-enabled defenses. It emphasizes proactive, scalable public-private collaboration to protect OT environments and develop a model for broader national adoption.
read more →

Small coin-sized implant can subvert Boeing 737

🔎 Security researchers demonstrated a compact, coin-sized device that can be inserted into an externally accessible hatch on a Boeing 737 to interface with the ARINC 429 bus. The implant, assembled from off-the-shelf parts for under US$100, can inject false signals that alter takeoff/landing calculations, autopilot routes, and displayed data, while potentially hiding changes from pilots. Researchers disclosed the issue to Boeing in 2020 and recommended physical sealing, electrical protection, and cryptographic authentication as mitigations.
read more →

When the patch tsunami meets maintenance windows

🔧 AI-driven vulnerability discovery has collapsed discovery timelines from months to hours, but operational technology (OT) remediation still moves at plant speed. OT systems face physical, economic and contractual constraints that make rapid patching impractical, so defenders must prioritize containment, compensating controls and documented retirement plans. Preparation, vendor engagement and exercised surge plans are essential.
read more →

Defending Water and OT Systems from Internet Risk

🔒 Recent cyberattacks against U.S. water and wastewater systems show that OT impact extends beyond data loss to public health, environment, and community functions. Distributed architectures, legacy controllers, remote cellular sites, and accumulated third-party access increase the attack surface. Government advisories document exploitation of internet-facing PLCs and HMIs, while new legislation seeks to expand EPA cybersecurity authority. Fortinet recommends unified OT architectures, secure cellular connectivity, ZTNA, and IEC 62443-4-2–certified solutions for consistent protection.
read more →

White House launches Project Watershed 250 pilot

🛡️ The White House has launched Project Watershed 250, a pilot program in Texas to provide water and wastewater utilities with federal and private-sector cybersecurity resources at no cost. Announced jointly by Governor Greg Abbott and National Cyber Director Sean Cairncross, the six-month initiative will deploy expertise from vendors including Microsoft, Google, AWS, Cloudflare, Palo Alto Networks, Forescout and Dragos. Supported by Texas Cyber Command, the pilot aims to identify vulnerabilities and strengthen defenses for rural and urban water providers amid growing OT-targeted threats tied to nation-state actors.
read more →

Securing Water Sector Infrastructure in the AI Era

🔒 This Cloud CISO Perspectives issue outlines the rising cyber risks to water utilities and presents practical, prioritized steps for OT and IT leaders. It emphasizes basic cybersecurity hygiene—asset inventory, replacing default credentials, backups, segmentation, and vendor access controls—while urging incident planning integration with existing all-hazards systems. The piece also highlights the role of AI as a force multiplier for defenders and the need for unified governance between IT and OT.
read more →

Small generators expose critical infrastructure risk

🔒 A recent cyber incident that took a small UK electricity generator offline for days — without causing national outages — highlights a weakness across Western critical infrastructure: thousands of small, internet-exposed industrial control devices lack the security protections of larger utilities. Governments and security firms are investigating attribution and impacts while urging operators to remove PLCs from direct internet access, secure cellular modems, and test manual-operation procedures. The episodes mirror attacks on US water systems and underscore how modest targets can create disproportionate disruption.
read more →

AI-Generated Exploits Target Siemens PLCs, Risking ICS Safety

🛡️ U.S. agencies warned of an active threat using AI-generated exploit scripts to target Siemens S7 Series PLCs and other industrial controllers, posing risks to Critical Manufacturing, Energy, Water, and related sectors. The campaign leverages internet scanning services to find exposed devices and uses custom Python tools integrating snap7.dll or python-snap7 to mimic legitimate monitoring utilities. Agencies urge patching, network isolation, strong access controls, and enhanced ICS monitoring to mitigate potential disruption, data compromise, and safety incidents.
read more →

AI-assisted attacks target Siemens S7 PLCs

🚨 A joint US government advisory warns that threat actors are using AI to generate exploitation scripts and tools targeting Siemens S7 Series programmable logic controllers (PLCs), placing critical sectors such as water, energy and manufacturing at heightened risk. The agencies say attackers are leveraging public scanning services to find internet-exposed PLCs, using AI to assist lateral movement and to craft tools that mimic legitimate OT monitoring, enabling read/write access via the S7comm protocol. Operators are urged to inventory systems, patch devices, block internet access to PLCs, segregate OT/IT networks, restrict remote access with MFA, disable unused services and engage with vendors for model-specific hardening to mitigate disruption, safety incidents and data compromise.
read more →

U.S. warns of AI-driven attacks on Siemens PLCs

🔒 U.S. cybersecurity agencies issued a joint advisory warning that threat actors are using AI-generated Python scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) within U.S. critical infrastructure. The agencies—NSA, CISA, FBI, DOE, and EPA—noted ongoing activity that targets exposed PLCs by abusing vulnerabilities, outdated software, and weak authentication to gain read/write access and disguise tools as legitimate OT monitoring software. Operators are urged to inventory devices, apply updates, block internet access, and strengthen monitoring and access controls to reduce risk.
read more →

Over 4,400 Rockwell PLCs Exposed on Internet

🔍 Forescout's August 3 scan found 4,407 internet-exposed Rockwell Automation PLCs worldwide, including 2,844 in the US; 22 were in cities hit by recent water utility attacks. The firm noted attackers can alter IPs and set passwords on reachable controllers without exploiting a vulnerability, and 19 of 22 in affected cities used the same mobile carrier network. The FBI and EPA urge strong authentication, firmware updates and isolation of remote access to reduce public exposure.
read more →

FortiOS v7.6.x Achieves IEC 62443-4-2 SL4

🔒 Fortinet announces that FortiOS v7.6.x has achieved IEC 62443-4-2 Security Level 4 (SL4) certification, the highest component assurance level for industrial automation and control systems. This complements the company’s IEC 62443-4-1 ML2 accreditation for secure product development and validates FortiOS technical capabilities across identification, integrity, confidentiality, availability, and response requirements. The certification applies across FortiGate platforms running v7.6.x, reinforcing operational resilience for OT and critical infrastructure environments.
read more →

Minnesota water cyberattack exposes OT backup gaps

🔒 The July 26–27 coordinated cyber activity against more than 30 Minnesota community water systems targeted operational technology, disrupting remote control and forcing manual operations in some places. Advisories from CISA and vendors document exfiltration of PLC project files and recovery procedures that assume operators possess current offline project backups. The article emphasizes immediate, low-cost countermeasures: verify offline, versioned project archives, reconcile SIM-equipped devices via carrier invoices, restrict integrator remote access, and test time-to-manual recovery.
read more →