Today’s OT/ICS security news highlights persistent ransomware pressure, vulnerabilities in monitoring and engineering tools, a mapped campaign against U.S. water systems with contested attribution, and a U.S. federal R&D strategy that elevates OT/ICS resilience as a priority area.
FBI, CISA, and HHS update Medusa ransomware advisory
The agencies state that Medusa is a ransomware-as-a-service operation using double extortion and say developers and affiliates had affected more than 500 victims across critical-infrastructure sectors, including manufacturing and healthcare, as of April 2026. The update highlights opportunistic exploitation of unpatched vulnerabilities, affiliate/initial-access broker activity, and recommends risk-informed patching, network segmentation, and restricting remote-service access.
Source: IC3
CISA publishes Malcolm network-analysis-suite advisory
CISA says affected Malcolm releases contain six vulnerabilities, including an authenticated arbitrary-code-execution issue (CVE-2026-55676, CVSS 8.8) and authorization-bypass and archive-handling flaws. CISA cites vendor fixes in Malcolm 26.06.1, 26.07.0, and 26.08.0 and reports no known public exploitation specifically targeting these issues.
Source: CISA
CISA republishes Siemens Simcenter Nastran advisory
CISA republishes that Siemens Simcenter Femap and Simcenter Nastran versions earlier than V2606 are affected by CVE-2026-59086, a stack-based buffer overflow with CVSS 7.8 where a malicious file argument may enable code execution in the current process. Siemens and CISA list affected sectors including critical manufacturing, energy, healthcare, transportation, and defense and advise upgrading to V2606 or later.
Source: CISA
CSIS maps Iranian-linked cyberattacks against U.S. water systems
CSIS reports that water systems in at least 12 states were targeted and that open-source research identified the locations of 55 of 100 facilities reported as targeted; it notes no reported water-quality harm but describes a Georgia pump-station shutdown and a resulting boil-water advisory. The report says CyberAv3ngers has claimed responsibility, and it also explicitly states that U.S. agencies have not publicly attributed the campaign.
Source: CSIS
White House National Security Science and Technology Strategy elevates OT/ICS resilience
The strategy, framed as a federal R&D priority framework, identifies four pillars—technology competition, building technological resilience, accelerating innovation, and protecting national-security S&T—and names information management and cybersecurity among 14 critical and emerging technology areas. It includes OT and ICS security among its listed cyber-priority capabilities alongside computing supply-chain security, digital identity, and post-quantum cryptography; the document is presented as guidance for federal research and development priorities rather than an operational mandate for asset owners.
Source: MeriTalk
Watch for follow-ups on exploit activity and vendor- or sector-specific mitigation actions as organizations implement the advisories and the federal strategy matures into funded programs.