Daily OT Security News – July 15, 2026
Welcome to today’s briefing on the latest developments in operational technology security. We cover critical patches, threat actor campaigns, government actions, and industry responses impacting the OT and IoT landscape.
ICS Patch Tuesday: Siemens, Schneider Electric, and Rockwell Automation Fix Critical Vulnerabilities
Siemens released nine new advisories addressing severe vulnerabilities, including a CVSS 10.0 authentication bypass in Opencenter X and critical flaws in Mendix, Simatic S7-1500, and Desigo CC. Schneider Electric patched a high-severity code execution issue in IGSS SCADA and an authentication bypass in EcoStruxure Cybersecurity Admin Expert. Rockwell Automation fixed 12 vulnerabilities, notably a critical unauthenticated CLI access flaw in the 1715 Redundant IO product and denial-of-service vulnerabilities in CompactLogix, ControlLogix, and GuardLogix controllers.
Source: SecurityWeek
NSA, CISA, and 12 Nations Warn of Russian FSB Center 16 Router Exploitation Campaign
A joint advisory from NSA, CISA, FBI, DC3, and 12 allied countries attributes a decade-long router compromise campaign to Russian FSB Center 16 (Berserk Bear/Static Tundra). The threat actors exploit weak SNMP community strings and the critical CVE-2018-0171 Cisco Smart Install vulnerability (CVSS 9.8) to exfiltrate device configurations and maintain persistent access to critical infrastructure networks. Defenders are urged to disable Cisco Smart Install, upgrade to SNMPv3 authentication, and block TFTP at network edges.
Source: Picus Security
CISA Issues Critical Advisory for ABB T-MAC Plus Terminal Management System (CVSS 9.9)
CISA’s advisory ICSA-26-195-03 highlights four vulnerabilities in ABB’s T-MAC Plus terminal management system used widely in petroleum, chemical, and pipeline sectors. The most severe flaw (CVSS 9.9) allows authenticated users to exfiltrate sensitive files via crafted HTTP requests. Additional issues include privilege escalation, stored cross-site scripting, and denial-of-service conditions targeting card reader services. ABB recommends immediate upgrade to version 4.0-25 to mitigate these risks.
Source: CISA
Bipartisan Congress Urges CISA to Protect U.S. Manufacturing from Russian Cyber Sabotage After Jaguar Land Rover Attack
Congressmen Austin Scott and Raja Krishnamoorthi sent a bipartisan letter to CISA Acting Director Nick Andersen requesting a robust strategy to safeguard U.S. manufacturing and defense supply chains. This follows a Russian-linked cyberattack on Jaguar Land Rover and raises concerns about potential shutdowns of U.S. defense production and disruptions to critical infrastructure sectors such as communications, electricity, transportation, and water. CISA is expected to respond by July 28, 2026, with a cybersecurity posture assessment and mitigation plans.
Source: Office of Congressman Raja Krishnamoorthi
Treasury OFAC Sanctions VPN Provider and Cryptor Supplier Enabling Ransomware Attacks on U.S. Critical Infrastructure
The U.S. Treasury Department’s OFAC sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and cryptor provider Yegeniy Silayev for supporting ransomware attacks targeting U.S. businesses, hospitals, financial institutions, and critical infrastructure. Operating since 2014 and advertised on cybercriminal forums, 1VPNS supplied anonymized infrastructure facilitating ransomware campaigns that caused billions in damages. This action follows a May 2026 international takedown coordinated with the FBI and European law enforcement.
Source: U.S. Department of the Treasury
Stay informed and vigilant as threat actors continue to target OT environments. Regular patching, monitoring, and adherence to cybersecurity best practices remain essential to defend critical infrastructure.