Viakoo IoT/OT/ICS Security Briefing — July 3, 2026
This briefing highlights five high-priority developments impacting IoT, OT, ICS, and critical infrastructure security. Each item summarizes the immediate risk, affected sectors, and the key mitigation or policy action organizations should prioritize.
CISA issues critical advisory for Gardyn IoT Hub (CVSS 10.0)
CISA published an advisory for Gardyn smart-garden hubs after disclosure of a critical (CVSS v3 10.0) hard-coded credential vulnerability and two additional weaknesses that expose logs and enable clickjacking/XSS. The hard-coded iothubowner credentials permit arbitrary command execution and potential lateral movement across connected devices, elevating risk for food and agriculture operators. Gardyn has patched the cloud infrastructure; operators should ensure devices are online to receive automatic firmware updates and verify remediation.
High-severity flaws in ST Engineering iDirect satellite terminals
CISA disclosed two high-severity vulnerabilities in iDirect iQ-Series terminals that can leak serial numbers, device IDs and terminal private keys via unauthenticated REST endpoints and permit CSRF-driven reboots that disrupt satellite links. These issues affect communications, defense, energy, transportation and government services where iDirect terminals are deployed, enabling terminal impersonation and denial-of-service. Administrators should apply firmware 4.5.2.2 or later and restrict management interfaces to trusted networks immediately.
Source: CISA Advisory ICSA-26-183-01 — ST Engineering iDirect iQ-Series
PTC Windchill RCE (CVE-2026-12569) under active exploitation
A critical remote code execution flaw in PTC Windchill and FlexPLM is being actively exploited, prompting CISA to add CVE-2026-12569 to its Known Exploited Vulnerabilities catalog after web shell deployments were observed. Windchill’s use across manufacturing, aerospace, automotive and engineering organizations makes successful exploitation a severe threat to intellectual property and operational continuity. Impacted organizations should prioritize detection of web shells, isolate exposed instances, and apply vendor mitigations or patches without delay.
DHS launches ANCHOR-CI to restore critical infrastructure cyber coordination
The Department of Homeland Security unveiled ANCHOR-CI to replace the defunct CIPAC framework, restoring legal protections for government-industry information sharing and creating regional and cross-sector councils with CISA oversight of membership. The initiative aims to rebuild collaborative operational resilience as U.S. infrastructure faces persistent targeting, including sustained access attempts by nation-state actors. Organizations should engage with sector and regional councils to improve situational awareness and coordinated response capabilities.
Qilin ransomware emerges as top OT threat in Q1 2026
TXOne Networks’ Q1 2026 analysis identifies Qilin as the most active ransomware group targeting OT environments in manufacturing, automotive, energy and healthcare, exploiting known Fortinet vulnerabilities for initial access and using BYOVD techniques to disable endpoint defenses. Qilin’s campaigns have caused operational disruptions and supply-chain impacts, including postponed surgeries and manufacturing outages, highlighting the danger of IT/OT convergence. OT operators should prioritize patching exposed Fortinet CVEs, harden remote access, monitor for vulnerable driver abuse, and enforce network segmentation between IT and OT domains.
Source: TXOne Networks — Q1 2026 Ransomware OT Analysis (Qilin)