This daily briefing summarizes notable cybersecurity developments relevant to operational technology (OT), industrial control systems (ICS), the Internet of Things (IoT), and cyber-physical systems (CPS). Items were selected from reporting published or surfaced during the previous 24 hours, with clear distinctions where a source is analysis or a policy call rather than a confirmed incident.
Johnson Controls reports cyberattack disrupting internal IT infrastructure
Johnson Controls International disclosed that a cyberattack disrupted its internal IT infrastructure, while customer portals for its Simplex and York subsidiaries reportedly displayed technical-outage messages. Dark Angels was reported to have claimed data theft and VMware ESXi encryption, though the company said its applications remained operational and unaffected as it assessed financial impact and implemented its incident-response plan. For OT and connected-building operators, the case underscores the potential exposure created when a supplier serving healthcare, airports, hotels, and stadiums experiences an enterprise compromise; customer-system effects have not been confirmed.
Source: Dark Reading: Johnson Controls International Disrupted by Major Cyberattack
Grid supply-chain order reaches industrial controllers, inverters, and BESS
A new analysis of the U.S. bulk-power-system security order highlights authority for the Department of Energy to review and condition transactions involving foreign-produced equipment used in substations, control rooms, and generating stations. The covered equipment expressly includes industrial control systems such as remote terminal units and programmable logic controllers, as well as grid-connected inverters, battery energy storage systems, generators, and protective relays. The review may consider associated software, firmware, remote access, update mechanisms, and lifecycle dependencies, and can extend to risk-creating equipment already installed.
Source: Baker Donelson: What the New Executive Order Means for Grid Cybersecurity and Supply Chain Risk
AI-generated tooling lowers the barrier for Siemens S7 PLC reconnaissance
A current report on CISA advisory AA26-231A describes AI-generated Python tooling built around snap7.dll and python-snap7 to interact with Siemens S7 controllers through the S7comm protocol on TCP port 102. The activity is characterized as persistent reconnaissance and capability development against S7-200 through S7-1500 and F-series controllers, rather than a newly disclosed Siemens zero-day or a confirmed process-disruption event. The immediate defensive priority is to identify and remove public exposure of OT controllers, block unnecessary perimeter access to TCP/102, patch supported systems, and monitor industrial-protocol traffic for unauthorized interaction.
Industry coalition calls for stronger defense of critical infrastructure
A new collective cyber-defense call warns that AI-enabled attacks are expected to become more widespread and sophisticated and specifically points to services dependent on hospitals, water-treatment plants, and internet infrastructure. Its recommended actions for critical-infrastructure operators and suppliers include remedying high-risk legacy weaknesses, verifying fixes without interrupting essential services, improving access controls and defense in depth, expanding actionable threat intelligence, and providing deployable defensive capabilities to under-resourced organizations.
Source: OpenAI: A call for collective action on cyber defense
OT defenders urged to address visibility gaps with deception controls
A new OT-security analysis argues that PLCs, RTUs, cameras, building-management controllers, and related assets frequently lack the logs, authentication data, telemetry, and forensics needed for conventional detection and investigation. It recommends carefully engineered deception across the IT-to-OT pathway, including decoy credentials, engineering workstations, network documents, and simulated PLCs, to create high-confidence signals of reconnaissance or lateral movement. This is strategic defensive guidance rather than a disclosure of a new vulnerability or a confirmed incident.