Today’s OT and ICS security landscape continues to evolve amid rising threats targeting critical infrastructure and industrial environments. From sophisticated multi-family malware to vulnerabilities in widely deployed control system software, organizations must remain vigilant to protect operational technology assets.
GigaWiper: Destructive Backdoor Assembles Three Malware Families Into One Unified Threat
Microsoft’s threat intelligence team has revealed GigaWiper, a complex Go-based backdoor discovered in October 2025 that integrates code from three distinct malware families: Crucio ransomware, FlockWiper, and an additional destructive component. This modular implant supports 20 commands, including raw disk wiping, fake ransomware encryption without recovery, and full event log erasure, posing a severe risk to critical infrastructure sectors.
Source: Security Affairs
CISA, FBI, DOE, and EPA Issue Joint Advisory: Attackers Breaching Oil & Gas Control Systems With Default Passwords
A joint advisory from CISA, FBI, DOE, and EPA warns that attackers, including unsophisticated actors, are breaching oil and gas control systems by exploiting unchanged default credentials. The advisory highlights that many devices remain exposed on public networks without multi-factor authentication, urging operators to change default passwords immediately and secure remote access pathways.
Source: CISA / FBI / DOE / EPA Joint Advisory
CISA Issues ICS Advisory ICSA-26-190-02: Seven Vulnerabilities in Schneider Electric PowerChute Serial Shutdown
CISA released advisory ICSA-26-190-02 detailing seven vulnerabilities affecting Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier. Exploitation could enable attackers to overwrite files, forge logs, gain unauthorized access, cause denial-of-service, reset credentials, or leak sensitive data. Schneider Electric has addressed these issues in version 1.5 of the software.
Source: CISA ICS Advisory ICSA-26-190-02
CISA and Five Eyes Publish Guidance on Securing AI Agent Access to Operational Technology Environments
A new joint guide from CISA, NSA, NCSC-UK, and Five Eyes partners addresses risks posed by AI agents accessing OT systems. The guidance recommends treating AI agents as untrusted connections, enforcing least-privilege network segmentation, maintaining distinct agent identities, and ensuring human oversight for critical actions to mitigate unintended impacts on industrial environments.
Source: Zentera / CISA Five Eyes Guidance
Doommageddon Ransomware Targets Manufacturing and Industrial Sectors With Double-Extortion Model
CYFIRMA’s weekly intelligence report highlights Doommageddon, a ransomware family targeting manufacturing, financial services, and retail sectors in Brazil, India, Paraguay, and Turkey. Employing asymmetric encryption and deleting Volume Shadow Copies, the malware also operates a hidden data leak portal to pressure victims with double extortion, with continued evolution expected in persistence and evasion techniques.
Source: CYFIRMA Weekly Intelligence Report
Maintaining robust OT security practices remains critical as threat actors continue to innovate and exploit vulnerabilities in industrial environments. Continuous vigilance and proactive defense measures are essential to safeguard operational technology assets.