top of page
man holding laptop in office

IT / OT Security News

Headlines: 2026

24 May 2026

The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire

On a May afternoon, refrigeration engineers were called to a food-production plant. The cold rooms and freezers were warming up, and the product inside them was fresh. The engineers expected what they usually find: a failed compressor, a leaking valve, a tripped protection. They arrived ready to fix a machine.

FULL ARTICLE

20 May 2026

Real-World ICS Security Tales From the Trenches

Industrial control systems (ICS) and operational technology (OT) environments are often described as quiet, highly controlled worlds. In reality, they contain a range of risks, unexpected configurations, and operational complexities that are difficult to fully uncover through standard penetration testing or conventional risk assessments.

19 May 2026

Critical Vulnerability Exposes Industrial Robot Fleets to Hacking

Universal Robots, a Danish company specializing in collaborative industrial robots, or cobots, has patched a critical vulnerability affecting one of its operating systems.

17 May 2026

State-backed ransomware activity raises new concerns over escalating threats to OT, critical infrastructure operations

Ransomware groups are increasingly being used as proxy weapons in geopolitical cyber warfare, enabling nation-states to exert pressure on their adversaries while maintaining plausible deniability.

13 May 2026

ICS Patch Tuesday: New Security Advisories From Siemens, Schneider, CISA

Only Siemens, Schneider Electric, CISA, and CERT@VDE have published new ICS security advisories for the May 2026 Patch Tuesday.

8 May 2026

Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants

Poland’s Internal Security Agency (ABW) has documented a significant escalation in cyberattacks targeting industrial control systems (ICS) and other operational technology (OT) infrastructure during 2024 and 2025, with state-sponsored threat actors increasingly shifting focus toward the physical disruption of critical services.

7 May 2026

Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion

Cybersecurity firm Dragos has released a threat intelligence report detailing an intrusion into a municipal water and drainage utility in Monterrey, Mexico, in which an unidentified threat actor made extensive use of AI tools to assist its operation.

30 April 2026

EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

Vulnerabilities discovered by Claroty researchers in EnOcean’s SmartServer IoT platform can be exploited to remotely hack building management systems.

29 April 2026

Hundreds of Internet-Facing VNC Servers Expose ICS/OT

Millions of remote access RDP and VNC servers are exposed to the internet, and hundreds of them may provide access to industrial control systems (ICS) and other operational technology (OT), according to research by Forescout.

28 April 2026

Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety

Vulnerabilities in Zero Motorcycles electric motorcycles and Yadea electric scooters can pose physical security and safety risks.

21 April 2026

Serial-to-IP Devices Hide Thousands of Old & New Bugs

The OT devices that translate machine talk into Internet-speak are riddled with vulnerabilities and more frequently targeted for attacks, researchers say

20 April 2026

Serial-to-IP Converter Flaws Expose OT and Healthcare Systems to Hacking

Forescout researchers discovered 20 new vulnerabilities in Lantronix and Silex products and described theoretical attack scenarios.

16 April 2026

ZionSiphon malware designed to sabotage water treatment systems

A new malware called ZionSiphon, specifically designed for operational technology, is targeting water treatment and desalination environments to sabotage their operations.

15 April 2026

$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks

The scale of infection among high-value targets proved particularly concerning. Of the hosts observed, 324 belonged to sensitive networks, including 221 universities and colleges, 41 operational technology (OT) networks, 35 government entities, and three healthcare organizations.

10 April 2026

Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday

The US government has warned that Iran-linked hackers are manipulating PLCs and SCADA systems to cause disruption.

8 April 2026

Iranian Threat Actors Disrupt US Critical Infrastructure Via Exposed PLCs

Iran-affiliated threat actors are disrupting US critical infrastructure through attacks on Internet-exposed operational technology (OT) devices across numerous sectors, the US government is warning.

7 April 2026

Russian Hackers Exploiting Home and Small-office Routers in Massive DNS hijacking Attack

A large-scale campaign by Forest Blizzard, a Russian military-linked threat actor, targeting home and small-office routers to hijack DNS traffic and intercept encrypted communications with over 200 organizations and 5,000 consumer devices already compromised.

7 April 2026

Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks

Several critical infrastructure organizations in the US were disrupted by Iran-linked cyberattacks that impacted operational technology (OT) devices, according to an urgent warning from federal agencies on Tuesday.

2 April 2026

How Iranian hackers pose a threat to US critical infrastructure

Michigan may be more than 6,000 miles away from the war in Iran, but, virtually speaking, it’s well within striking distance.

1 April 2026

Water treatment plant in North Dakota suffered ransomware attack

A ransomware attack last month forced operators of a water treatment facility in Minot, North Dakota, to revert to manual processes while a back-up server could be located.

30 March 2026

Team Cymru warns exposed ICS and OT devices targeted by nation-state actors raise industrial, critical infrastructure risks

Following last month’s post highlighting its capabilities for protecting ICS (industrial control systems) and OT (operational technology) environments, Team Cymru published new research examining three case studies that reveal the extent of exposed ICS and OT devices known to be targeted by hostile nation-state actors. The findings underscore a critical concern: many of these systems remain directly exposed and vulnerable to exploitation.

24 March 2026

Iran Built a Vast Camera Network to Control Dissent. Israel Turned It Into a Targeting Tool

The role of Israel’s hijacking of Iran’s street cameras in the killing of the country’s supreme leader underscores how surveillance systems are increasingly being targeted by adversaries in wartime.

24 March 2026

Poland Faced a Surge in Cyberattacks in 2025, Including a Major Assault on the Energy Sector

The attacks included a destructive infiltration of Poland’s energy system in December and was suspected of originating in Russia.

16 March 2026

Hacking Attempt Reported at Poland’s Nuclear Research Center

Poland’s national nuclear research center was recently targeted in a cyberattack that may have been conducted by Iranian hackers.

11 March 2026

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Moxa, Mitsubishi Electric

Industrial giants Siemens, Schneider Electric, Mitsubishi Electric, and Moxa have published new ICS Patch Tuesday advisories.

6 March 2026

Rockwell Vulnerability Allowing Remote ICS Hacking Exploited in Attacks

CISA added the flaw, tracked as CVE-2021-22681, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, instructing federal agencies to address it by March 26.

5 March 2026

State-affiliated hackers set up for critical OT attacks that operators may not detect

Threat groups are weaponizing industrial control access they’ve gained over the years, but critical infrastructure operators remain unprepared for what comes next, research from Dragos suggests.

27 February 2026

APT37 hackers use new malware to breach air-gapped networks

North Korean hackers are deploying newly uncovered tools to move data between internet-connected and air-gapped systems, spread via removable drives, and conduct covert surveillance.

17 February 2026

3 Threat Groups Started Targeting ICS/OT in 2025: Dragos

Three new threat groups started targeting industrial control systems (ICS) and other operational technology (OT) in 2025, according to a new report from cybersecurity company Dragos.

17 February 2026

Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems

The cybersecurity challenge for Industrial Control Systems (ICS) is they were designed in conditions of peace but now operate in a continuous war zone.

12 February 2026

CISA issues new OT security guidance to overcome cost and complexity barriers in critical infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released new guidance aimed at closing long-standing gaps in OT (operational technology) security across critical infrastructure sectors, including water and wastewater, transportation, chemical, energy, and food and agriculture.

11 February 2026

ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, Phoenix Contact

Industrial giants Siemens, Schneider Electric, Aveva, and Phoenix Contact have published Patch Tuesday advisories informing customers about vulnerabilities found in their ICS/OT products.

9 February 2026

Leaked technical documents show China rehearsing cyberattacks on neighbors’ critical infrastructure

China appears to be using a secret training platform to rehearse cyberattacks against the critical infrastructure of its closest neighbors, according to a cache of leaked technical documents reviewed by Recorded Future News.

2 February 2026

Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities

Poland’s computer emergency response team (CERT) has published a report detailing the recent attack by Russia-linked hackers on the country’s power grid.

30 January 2026

ICS Devices Bricked Following Russia-Linked Intrusion Into Polish Power Grid

The recent attack on Poland’s power grid, believed to have been conducted by Russian threat actors, targeted communication and control systems across roughly 30 sites and in some cases resulted in permanent industrial control system (ICS) damage, according to industrial cybersecurity firm Dragos.

26 January 2026

Russian Sandworm Hackers Blamed for Cyberattack on Polish Power Grid

The Russian state-sponsored APT named Sandworm was behind the December 2025 cyberattack targeting Poland’s power grid, cybersecurity firm ESET reports.

26 January 2026

Poland repels data-wiping malware attack on energy systems

According to information shared by the Polish government earlier this month, the attacks happened on 29 and 30 December 2025, and targeted two combined heat and power (CHP) plants and a system enabling the management of electricity generated from wind turbines and photovoltaic farms.

19 January 2026

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking

TP-Link has patched a serious vulnerability that can be exploited to take control of more than 32 of its VIGI C and VIGI InSight series professional surveillance camera models.

15 January 2026

Chinese hackers targeting ‘high value’ North American critical infrastructure, Cisco says

Chinese hackers successfully breached multiple critical infrastructure organizations in North America over the last year using a combination of compromised credentials and exploitable servers, researchers at Cisco Talos found.

15 January 2026

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact

Industrial giants Siemens, Schneider Electric, Phoenix Contact, and Aveva have published a dozen Patch Tuesday advisories to inform customers about vulnerabilities found in their ICS/OT products.

13 January 2026

Massive cyberattack on Polish power system in December failed, minister says

Poland's power system faced its largest cyberattack in years in the last week of December that also followed a different pattern, the country's energy minister said on Tuesday.

8 January 2026

Researchers Expose WHILL Wheelchair Safety Risks via Remote Hacking

Security researchers have demonstrated a critical vulnerability in high-tech electric wheelchairs that allows for unauthorized remote control, highlighting new safety risks for connected mobility devices.

bottom of page