Daily OT Security News – July 09, 2026
Welcome to today’s briefing on OT, IoT, and ICS security. Here are the latest updates impacting operational technology environments and networked devices as of July 9, 2026.
Ubiquiti Patches Seven Critical UniFi Flaws Across Multiple Product Lines
Ubiquiti has issued security updates addressing seven critical vulnerabilities affecting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. The vulnerabilities, including CVE-2026-50746 with a CVSS score of 10.0, allow unauthenticated attackers with network access to execute command injection, SQL injection, SSRF, and privilege escalation. Although no active exploitation has been confirmed, previous UniFi OS flaws were recently highlighted by CISA as actively exploited.
Source: The Hacker News
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Networking Devices
CERT/CC has revealed an undocumented backdoor (CVE-2026-11405) in multiple Tenda router firmware versions that enables unauthenticated attackers to bypass authentication and obtain full administrative rights. The vulnerability stems from the device’s login process, which only verifies the password and disregards the username, using a plaintext password stored in configuration files. No patch is available, and users are strongly advised to disable remote web management until further notice.
Source: SecurityWeek
China-Linked APT Expands SOHO Router Malware Arsenal With New ‘Leash’ Backdoors
Cisco Talos researchers have uncovered three new malware families—LongLeash, DogLeash, and JarLeash—deployed by the China-linked UAT-7810 group as part of the LapDogs espionage campaign targeting SOHO routers. Building on prior infections with ShortLeash, the group exploits vulnerabilities in Ruckus and Asus AiCloud devices to create a relay network for espionage operations. This campaign highlights the continued targeting of network edge devices as initial footholds into enterprise and critical infrastructure systems.
Source: SecurityWeek
Nozomi Networks Identifies Apex2 and c2c Golang Malware Accelerating IoT Botnet Attacks on OT Environments
Nozomi Networks’ recent research identifies two novel malware strains—Apex2 and a Golang-based command-and-control framework—that hasten IoT botnet growth impacting operational technology environments. These malware strains facilitate rapid recruitment of vulnerable IoT devices into botnets capable of launching distributed attacks against OT systems across manufacturing, energy, and utilities sectors. The findings underscore the increasing intersection of IoT botnets with targeted OT attack campaigns.
Source: Industrial Cyber
EU Launches AI Cybersecurity Action Plan to Reduce Reliance on Foreign AI and Strengthen Critical Infrastructure
The European Commission has introduced a comprehensive Action Plan focused on cybersecurity and artificial intelligence, centered on making frontier AI safe and accessible, preparing the EU cyber ecosystem, and scaling European AI capabilities. This plan includes nine key measures such as a European Blueprint for advanced AI model access and a new AI evaluation facility expected by 2027. It recognizes the current EU dependence on non-European AI providers, with three foreign hyperscalers dominating over 70% of the European cloud market.
Source: The Record
Thank you for reading today’s briefing. Stay vigilant and proactive in securing your OT and IoT environments against evolving threats.