Daily OT Security News: July 09, 2026

Daily OT Security News – July 09, 2026

Welcome to today’s briefing on OT, IoT, and ICS security. Here are the latest updates impacting operational technology environments and networked devices as of July 9, 2026.

Ubiquiti Patches Seven Critical UniFi Flaws Across Multiple Product Lines

Ubiquiti has issued security updates addressing seven critical vulnerabilities affecting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. The vulnerabilities, including CVE-2026-50746 with a CVSS score of 10.0, allow unauthenticated attackers with network access to execute command injection, SQL injection, SSRF, and privilege escalation. Although no active exploitation has been confirmed, previous UniFi OS flaws were recently highlighted by CISA as actively exploited.

Source: The Hacker News

Unpatched Backdoor in Tenda Firmware Grants Admin Access to Networking Devices

CERT/CC has revealed an undocumented backdoor (CVE-2026-11405) in multiple Tenda router firmware versions that enables unauthenticated attackers to bypass authentication and obtain full administrative rights. The vulnerability stems from the device’s login process, which only verifies the password and disregards the username, using a plaintext password stored in configuration files. No patch is available, and users are strongly advised to disable remote web management until further notice.

Source: SecurityWeek

China-Linked APT Expands SOHO Router Malware Arsenal With New ‘Leash’ Backdoors

Cisco Talos researchers have uncovered three new malware families—LongLeash, DogLeash, and JarLeash—deployed by the China-linked UAT-7810 group as part of the LapDogs espionage campaign targeting SOHO routers. Building on prior infections with ShortLeash, the group exploits vulnerabilities in Ruckus and Asus AiCloud devices to create a relay network for espionage operations. This campaign highlights the continued targeting of network edge devices as initial footholds into enterprise and critical infrastructure systems.

Source: SecurityWeek

Nozomi Networks Identifies Apex2 and c2c Golang Malware Accelerating IoT Botnet Attacks on OT Environments

Nozomi Networks’ recent research identifies two novel malware strains—Apex2 and a Golang-based command-and-control framework—that hasten IoT botnet growth impacting operational technology environments. These malware strains facilitate rapid recruitment of vulnerable IoT devices into botnets capable of launching distributed attacks against OT systems across manufacturing, energy, and utilities sectors. The findings underscore the increasing intersection of IoT botnets with targeted OT attack campaigns.

Source: Industrial Cyber

EU Launches AI Cybersecurity Action Plan to Reduce Reliance on Foreign AI and Strengthen Critical Infrastructure

The European Commission has introduced a comprehensive Action Plan focused on cybersecurity and artificial intelligence, centered on making frontier AI safe and accessible, preparing the EU cyber ecosystem, and scaling European AI capabilities. This plan includes nine key measures such as a European Blueprint for advanced AI model access and a new AI evaluation facility expected by 2027. It recognizes the current EU dependence on non-European AI providers, with three foreign hyperscalers dominating over 70% of the European cloud market.

Source: The Record

Thank you for reading today’s briefing. Stay vigilant and proactive in securing your OT and IoT environments against evolving threats.

Share this