Daily OT Security News: July 06, 2026

Today’s OT and IoT security landscape continues to evolve rapidly, with emerging vulnerabilities and sophisticated threat campaigns targeting critical infrastructure and industrial environments. As attackers increasingly exploit systemic weaknesses in both hardware and software layers, operators must prioritize proactive defense and rapid response strategies to safeguard operational continuity.

FortiBleed Credential Leak Poses Elevated Risks to Maritime and Energy Critical Infrastructure

The newly uncovered FortiBleed campaign has exposed administrator credentials for tens of thousands of Fortinet firewalls connected to the internet. This credential leak significantly increases risks for maritime and energy sectors that depend on Fortinet devices to segment their OT and IT networks. Security experts warn that attackers could leverage these credentials to bypass perimeter defenses and infiltrate sensitive operational technology systems.

Source: Industrial Cyber

Seven FatFs Vulnerabilities Threaten Millions of IoT and Embedded Devices

Cybersecurity researchers from runZero have disclosed seven vulnerabilities in FatFs, a widely implemented open-source FAT/exFAT filesystem library used in numerous IoT and embedded systems. The flaws, with severity levels from medium to high, affect popular platforms such as Espressif ESP-IDF and Zephyr RTOS and can lead to remote code execution, memory corruption, and denial-of-service conditions. Notably, six of these vulnerabilities remain unpatched due to lack of response from the FatFs maintainer, leaving millions of devices exposed.

Source: Security Affairs

Dragos 2026 OT Report: Ransomware Groups Targeting Industrial Orgs Surged 49% in 2025

The Dragos 2026 OT Cybersecurity Year in Review highlights a dramatic 49% rise in ransomware attacks against industrial organizations in 2025, with 119 distinct groups impacting roughly 3,300 targets. The oil and gas sector saw an alarming 935% increase in such attacks over a 12-month span. Furthermore, the report identifies three new OT-specific threat groups, noting adversaries’ growing sophistication in mapping control systems and physical processes beyond traditional reconnaissance.

Source: Hydrocarbon Engineering

DHS Launches ANCHOR-CI Critical Infrastructure Advisory Councils

The Department of Homeland Security has established ANCHOR-CI, a new advisory council aimed at enhancing cybersecurity collaboration between critical infrastructure operators and government entities. Replacing the disbanded Critical Infrastructure Partnership Advisory Council, ANCHOR-CI will operate under CISA and is exempt from the Federal Advisory Committee Act’s transparency rules due to the sensitive nature of its risk assessments. This move underscores the government’s commitment to strengthening national operational resilience.

Source: BankInfoSecurity

Bad Epoll (CVE-2026-46242): Linux Kernel Flaw Grants Root Access on Linux and Android

The recently disclosed Bad Epoll vulnerability allows local attackers to achieve full root privileges on Linux and Android devices through a race-condition use-after-free in the epoll subsystem. A proof-of-concept exploit demonstrates a near 99% success rate, including execution from within Chrome’s sandbox environment. This critical flaw affects Linux kernels version 6.4 and later, posing a significant threat to OT environments reliant on Linux-based HMIs, historians, and edge computing systems.

Source: Security Affairs

As threat actors continue to advance their tactics, it is essential for OT and IoT stakeholders to remain vigilant and implement layered security controls. Continuous monitoring and timely patching are critical to defending the integrity of operational environments.

Share this