Daily OT Security News: July 20, 2026

As operational technology (OT), industrial control systems (ICS), and IoT environments continue to evolve, so do the cyber threats targeting them. Today’s landscape is marked by increasing sophistication in attacks, driven by AI and exploiting legacy vulnerabilities, underscoring the critical need for enhanced security measures across industries.

AI-Generated Ransomware Drives 56% Surge in Manufacturing Attacks

Manufacturing has become the most targeted sector for ransomware, experiencing a 56% increase in attacks year-over-year according to OPSWAT. Up to 80% of new ransomware strains are AI-generated, exploiting emerging smart factory technologies like Unified Namespace (UNS), MQTT, and agentic AI, which expand OT/IT convergence attack surfaces. Additionally, about 25% of OT incidents still involve removable media, with attackers focusing more on data theft and extortion than encryption alone.

Source: IIoT World

CISA Adds KNX Smart Building Protocol Vulnerability to Known Exploited Vulnerabilities Catalog

On July 15, 2026, CISA added CVE-2023-4346—a critical flaw in the KNX smart building automation protocol—to its Known Exploited Vulnerabilities catalog, confirming active exploitation. This vulnerability allows attackers to permanently brick building automation devices such as lighting, HVAC, and access control by locking out administrators with no factory reset option. Federal agencies must mitigate the risk by July 29, while over 16,000 vulnerable systems remain exposed online in Europe.

Source: Tech Times

Nozomi Networks Joins Anthropic’s Project Glasswing to Advance AI-Driven OT/IoT Vulnerability Discovery

Nozomi Networks has partnered with Anthropic’s Project Glasswing, an initiative focused on applying advanced AI models to uncover vulnerabilities in OT, IoT, and cyber-physical systems. This collaboration aims to enhance vulnerability discovery within Nozomi’s platform, contribute to Anthropic’s research, and share insights with the cybersecurity community. The project addresses unique OT challenges such as long device lifecycles, patching constraints, and the physical impact of cyber incidents.

Source: Cybersecurity Asia

Manufacturers Accelerate OT Security Investment as Cyber Threats Intensify

Industrial organizations are increasing investments in OT security amid rising cyber threats, with Rockwell Automation emphasizing the need for distinct strategies between OT and IT networks. A major hurdle is the lack of comprehensive asset inventories, as many legacy devices remain connected to operational networks. Security efforts are now prioritizing asset discovery and network assessments, while AI both enhances defense capabilities and enables more complex attacks.

Source: Security Brief

Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances with Root-Level Access

Volexity researchers revealed an active zero-day campaign by threat actor UTA0533 targeting SonicWall SMA 1000 series VPN appliances, exploiting two vulnerabilities (CVE-2026-15409 and CVE-2026-15410) to gain root-level access. The campaign, starting as early as June 22, 2026, used custom malware tailored for SonicWall environments, indicating a highly targeted threat. SonicWall has since released patches, highlighting ongoing risks to network edge devices critical to OT and enterprise security.

Source: Security Affairs

As cyber threats targeting OT and IoT environments continue to grow in complexity, staying informed and proactive is essential. Organizations must remain vigilant and prioritize robust security strategies to protect critical infrastructure.

Share this