Daily OT Security News: July 04, 2026

Welcome to the July 4, 2026 edition of our daily OT security news briefing. Today’s roundup covers critical vulnerabilities and evolving threats impacting IoT, ICS, and industrial environments, highlighting the ongoing challenges facing operational technology security teams worldwide.

Unpatched FatFs Vulnerabilities Expose Millions of IoT and Industrial Devices

Security firm runZero disclosed seven vulnerabilities in FatFs, a widely embedded filesystem library found in devices such as security cameras, industrial controllers, and drones. The most severe, CVE-2026-6682, is an integer overflow in FAT32 mount code that can lead to remote code execution. With no upstream patch for six of these flaws and numerous affected platforms, remediation efforts will be complex and protracted for downstream vendors.

Source: The Hacker News

RustDuck Botnet Rewrites in Rust to Hijack Routers, IP Cameras, and Servers

QiAnXin’s XLab researchers report that RustDuck, a botnet targeting home routers, IP cameras, Android set-top boxes, and servers, is undergoing a major rewrite from C to Rust. The updated malware adds ChaCha20-Poly1305 encrypted command and control communications and advanced sandbox detection. RustDuck exploits known vulnerabilities in devices from TP-Link, ZTE, and Huawei, many of which have reached end-of-life, posing growing risks to distributed enterprise networks with unmanaged edge devices.

Source: The Hacker News

CISA Issues Six ICS Advisories Including Critical CVSS 10.0 Flaw in Gardyn IoT Hub

On July 2, 2026, CISA published six new ICS advisories, notably a critical CVSS 10.0 vulnerability (CVE-2026-13768) in the Gardyn IoT Hub used in food and agriculture sectors. The flaw exposes a hard-coded privileged key that enables unauthenticated attackers to execute arbitrary commands and potentially move laterally within affected networks. Additional advisories address vulnerabilities in ST Engineering iDirect satellite terminals, CubeSpace reaction wheels, and Mitsubishi Electric CNC Series equipment.

Source: CISA

SimpleHelp CVE-2026-48558: CVSS 10.0 RMM Flaw Actively Exploited to Breach MSP Customers

A critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management software is being actively exploited to compromise managed service providers (MSPs) and their customers. The flaw (CVE-2026-48558) allows attackers to forge OpenID Connect tokens and gain full Technician-level access to all endpoints managed by the compromised server. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating remediation by July 2, 2026, as attacks deploy Djinn Stealer to harvest sensitive credentials and AI coding assistant data.

Source: DiSec

Kaspersky Q1 2026 ICS Report: Manufacturing Is the Only Industry Seeing Increased Cyberattacks

Kaspersky’s Q1 2026 Industrial Control Systems Threat Landscape report reveals manufacturing as the sole industry experiencing an increase in ICS cyberattacks globally, with Southeast Asia particularly affected. These findings are consistent with Verizon’s 2026 Data Breach Investigations Report, which ranks manufacturing as the second most targeted sector. Experts warn that the growing convergence of IT and OT networks amid Industry 4.0 adoption significantly expands the attack surface.

Source: Times of India

Thank you for reading today’s briefing. Stay vigilant and proactive to safeguard your OT environments against emerging cyber threats.

Share this