AI-driven vulnerability management and public-private collaboration took center stage today, alongside concrete U.S. policy moves and a real-world ransomware disruption. New integrations and partnerships aim to accelerate OT risk prioritization and detection at scale, while NIST advances foundational asset management guidance. Meanwhile, lawmakers propose dedicated cybersecurity funding for water infrastructure, and a ransomware attack on a major beverage producer underscores persistent operational risk in cyber-physical environments.
Bastazo and Nozomi Networks Integrate AI to Prioritize OT Vulnerabilities
Bastazo and Nozomi Networks unveiled a technology integration that pulls Nozomi’s asset, vulnerability, and topology data into Bastazo’s attack simulation engine to elevate how OT teams prioritize and remediate risk. The joint capability applies SSVC-based risk scoring, attack path analysis, and automated remediation playbooks aligned to maintenance windows, producing audit-ready documentation to support NERC CIP and NIST CSF obligations. The result is faster, context-aware OT vulnerability reduction focused on the highest-impact paths.
Nozomi Networks Joins Anthropic’s Project Glasswing to Secure OT, IoT, and CPS
Nozomi Networks is partnering with Anthropic’s Project Glasswing to apply Claude AI models to OT/IoT-focused vulnerability discovery within Nozomi’s platform. The collaboration aims to sharpen model understanding of industrial protocols, operational constraints, and cyber-physical risks, bringing frontier AI to threat detection and analysis across ICS, IoT, and broader CPS environments. The initiative signals accelerating AI adoption for industrial-scale defense.
US Senate Committee Advances WRDA 2026, Bolstering Water Sector Cyber Resilience
The Senate Environment and Public Works Committee unanimously advanced the Water Resources Development Act of 2026 with landmark cybersecurity provisions for critical water infrastructure. The bill expands resilience programs to explicitly reduce cyber vulnerabilities, authorizes $25 million annually for FY 2027–2030, mandates vulnerability identification in project proposals, and funds a $10 million annual state-of-the-sector report. Workforce development rises to $15 million annually, adding cybersecurity training for water utilities.
NIST NCCoE Seeks Input on OT Asset Management Project
NIST’s National Cybersecurity Center of Excellence released a draft project description, “Asset Management as a Foundation for OT Cybersecurity,” and is seeking public feedback through July 31, 2026. The effort will demonstrate practical OT asset discovery, inventory, configuration, and change management using commercial tech, addressing legacy systems, diverse protocols, distributed sites, and operational constraints. Outcomes will align with NIST CSF 2.0 and culminate in a NIST SP 1800-series guide, supporting zero trust, post-quantum migration, and AI-era defense.
Coca-Cola Reports Ransomware on fairlife OT Systems, Halts US Production
Coca-Cola disclosed a ransomware incident impacting OT production systems for its fairlife brand, prompting a temporary halt to U.S. manufacturing. Disruption to production control systems required incident response engagement and containment actions, spotlighting the food and beverage sector’s exposure to OT ransomware and the potential for cascading supply chain effects. The case reinforces the need for segmented architectures, tested recovery runbooks, and rapid IR coordination across IT and OT.
Across policy, standards, and operations, today’s developments emphasize the fundamentals: accurate asset inventories, risk-based vulnerability reduction, and prepared recovery. Keep an eye on emerging AI capabilities in OT platforms, contribute to NIST’s asset management effort, and pressure-test ransomware playbooks to reduce blast radius and downtime.