This briefing summarizes five current OT, ICS, IoT, or critical-infrastructure cybersecurity developments.
NSA, FBI and CNMF Warn That China-Linked QTFY Is Exploiting IoT Devices and Targeting Critical Systems
On August 26, the NSA said it joined the FBI and Cyber National Mission Force in a joint advisory about China-linked QTFY, also known as QT/QTCYBER. The agencies said the group uses QScan to reconnoiter and exploit vulnerable IoT devices, QTRouter to obfuscate activity, and platforms to manage compromised-IoT botnets, and that actors have targeted critical systems; they recommended applying current software and firmware updates, auditing internet-facing assets, isolating critical systems from edge devices, and hunting for provided IOCs.
Source: nsa.gov.
CISA Shares Lessons From Two Red-Team Assessments at Critical-Infrastructure Organizations
CISA’s August 25 advisory reports simultaneous red-team assessments at a Government Services and Facilities Sector organization and a Water and Wastewater Systems Sector organization. In both engagements the red team achieved full domain compromise and accessed sensitive business systems and cloud resources; one organization failed to detect or contain the activity while the other quickly detected attempts and isolated affected systems, and CISA emphasizes baselines for software, accounts and traffic, reducing alert noise, and cross-functional response.
Source: cisa.gov.
Water Utilities Urged to Identify and Secure Internet-Exposed PLCs
A new August 27 report highlights CISA guidance on the dangers of directly connecting PLCs to the internet through cellular modems. CISA said July 2026 activity targeting water and wastewater entities involved remote access to internet-exposed PLCs, IP address and password changes, loss of monitoring and control, and in some cases operational disruption, and recommended routing remote access through centrally managed gateways, unique credentials, phishing-resistant MFA, and monitoring rather than direct PLC, HMI or RTU exposure.
Source: securityaffairs.com.
Kaspersky Reports Shifting Malware Trends Across Industrial Automation Systems in Q2 2026
Kaspersky’s August 27 industrial threat report says malicious objects were blocked on 19.15% of ICS computers in Q2 2026, the lowest level since 2022, while five regions increased quarter over quarter. Kaspersky’s tools blocked 10,904 malware families on industrial automation systems, and the share of ICS computers where ransomware, worms, malicious documents, denylisted resources, and AutoCAD malware were blocked rose over the quarter.
Source: securelist.com.
SentinelOne and Tenable Find Attackers Repeatedly Target Edge-Device Vendor Ecosystems
New joint SentinelOne and Tenable research found their exposure data and runtime/DFIR detection data converged on the same edge-device vendor surfaces 79% of the time, while overlapping on only 21% of individual vulnerabilities. The research says state-backed and criminal actors repeatedly target persistently exposed vendor product lines, the median organization needs five months to remediate known vulnerabilities, and it recommends prioritizing durable attack surfaces alongside detection and attack-surface reduction.
Source: cioinfluence.com.
Maintain asset visibility, device hygiene, timely patch and firmware management, strong credential practices, and continuous monitoring to reduce exposure across OT, ICS and IoT environments.