As operational technology (OT), industrial control systems (ICS), and Internet of Things (IoT) environments grow increasingly interconnected, the security landscape faces both heightened risks and evolving threats. Organizations must remain vigilant as attackers exploit vulnerabilities in critical infrastructure and smart systems, while regulatory pressures continue to tighten.
NSA, CISA, and Allies Warn of Russian FSB Center 16 Attacks on Critical Infrastructure Routers
The NSA, CISA, FBI, and international partners issued a joint advisory highlighting ongoing attacks by Russia’s FSB Center 16 targeting poorly configured routers in energy, healthcare, defense, and government sectors. Threat actors leverage SNMP scanning to extract router configurations, enabling deep network infiltration. The advisory urges upgrades to SNMPv3, disabling Cisco Smart Install, enforcing strong passwords, blocking TFTP, and keeping firmware updated to mitigate risks.
Source: Industrial Cyber
Fortinet 2026 OT Security Report: Maturity Ratings Plunge as Visibility Improves, Intrusions Rise
Fortinet’s 2026 State of OT and Cybersecurity Report reveals a sharp decline in self-assessed OT security maturity, dropping from 49% to 17% at the highest level. The surge in reported intrusions—from 47% to 71% of organizations—reflects enhanced visibility uncovering hidden risks like undocumented assets and weak network segmentation. Expanding IT-OT convergence and longer attacker dwell times continue to broaden the industrial attack surface.
Source: SecurityBuzz / Fortinet
Ubiquiti Patches 25 Critical UniFi OS Vulnerabilities Including CVSS 10.0 Command Injection Flaw
Ubiquiti issued Security Advisory Bulletin 066 addressing 25 vulnerabilities in its UniFi ecosystem, including a critical CVSS 10.0 unauthenticated command injection flaw impacting UniFi Connect Application used for smart building controls. Additional high-severity issues affect UniFi Talk, Access, and Protect, allowing SQL injection and privilege escalation. With prior UniFi OS flaws already in CISA’s Known Exploited Vulnerabilities catalog, administrators are urged to update affected systems immediately.
Source: Security Affairs
‘GodDamn’ Ransomware Deploys Microsoft-Signed Kernel Driver to Disable Security Tools in US Attacks
Symantec researchers uncovered a new ransomware campaign by the Hyadina group targeting US healthcare, manufacturing, and education sectors using the ‘GodDamn’ ransomware. Attackers employed a malicious kernel driver (‘PoisonX’) signed by Microsoft to disable all security processes via a BYOVD technique. The sophisticated attack chain included remote access with AnyDesk, credential harvesting, lateral movement, and ransomware deployment, highlighting gaps in Microsoft’s Vulnerable Driver Blocklist response times.
Source: Dark Reading
CIRCIA Final Rule Expected September 2026: 72-Hour Cyber Incident Reporting Mandate for All Critical Infrastructure
CISA plans to finalize the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule by September 2026, mandating all critical infrastructure sectors report cyber incidents within 72 hours and ransomware payments within 24 hours. Reporting begins upon a “reasonable belief” of an incident, challenging healthcare organizations that average over 300 days to detect and contain breaches. The American Hospital Association seeks clarifications and exemptions to ease compliance burdens on smaller facilities.
Source: Paubox
Maintaining robust OT security remains critical as threat actors continue to exploit system vulnerabilities and regulatory demands intensify. Continuous vigilance, proactive vulnerability management, and comprehensive incident response preparedness are essential to safeguarding critical infrastructure and industrial environments.