Daily OT Security News: July 21, 2026

Today’s OT security landscape is defined by two converging trends: rapid adoption of frontier AI to discover vulnerabilities across critical systems, and continued aggressive activity by state-aligned threat actors that is now producing confirmed physical-process impacts. At the same time, long‑running legacy infections and under-resourced defenders are eroding operational resilience, making coordinated remediation and measured use of AI essential for protecting industrial environments.

Anthropic and Nozomi Networks Bring AI Vulnerability Research to OT/IoT Security

Nozomi Networks has joined Anthropic’s Project Glasswing to apply Claude Mythos Preview to vulnerability discovery in OT, IoT, and cyber-physical systems. Anthropic reports the model has already flagged more than 10,000 potential high or critical severity findings across participating organizations’ codebases, illustrating AI’s ability to scale discovery into industrial software and firmware. Nozomi’s participation — following Dragos’ entry last month — extends AI-assisted research into environments where traditional patching is operationally complex and remediation requires careful orchestration.

Source: IoT Tech News

White House Gold Eagle Initiative Targets CPS/OT Vulnerability Coordination at National Scale

The White House launched the Gold Eagle vulnerability clearinghouse to use frontier AI models for discovery, validation, and remediation recommendations for critical-infrastructure weaknesses at national scale. Triage of incoming reports will be handled by CISA together with Carnegie Mellon’s VINCE platform, creating a centralized pipeline for public‑private coordination. Claroty analysts note that while discovery at scale is a major step forward, the harder problem remains remediation in CPS-heavy sectors — where downtime is unacceptable and organizations often rely on compensating controls rather than rapid patching.

Source: Claroty Blog

Iranian IRGC Actors Confirm OT Disruption at U.S. Water, Energy, and Government Facilities

A joint advisory (AA26-097A) confirms Iranian IRGC‑affiliated actors (CyberAv3ngers / Shahid Kaveh) exploited internet‑exposed Rockwell/Allen‑Bradley PLCs via CVE‑2021‑22681 — a vulnerability with no vendor patch — causing operational disruption and financial loss at U.S. water, energy, and government sites. The advisory links impact to IOCONTROL ICS malware, which has spread into an estimated 60+ affiliated clusters, and marks an escalation from access to confirmed physical‑process effects. This activity follows February 28 Operation Epic Fury strikes and underscores the risk of internet‑exposed control devices that cannot be remediated by simple patching.

Source: VECTR-CAST Threat Forecast (July 20, 2026)

Russian FSB Pre-Positioning Inside U.S. Critical Infrastructure Networking Devices Confirmed

A nineteen‑agency multinational advisory led by the NSA (July 13) attributes systematic router targeting across communications, energy, government, defense‑industrial, financial, and healthcare networks to Russia’s FSB Center 16 (Static Tundra / Berserk Bear). The advisory follows disruption of the APT28 “Frost Armada” router botnet, which infected roughly 18,000 devices across 120 countries, and analysts warn Russian actors are prioritizing durable pre‑positioned access at the network edge. The campaign — coupled with Sandworm (APT44)’s demonstrated destructive intent against NATO‑adjacent energy infrastructure in December 2025 — highlights the strategic focus on resilient footholds that enable long‑term operations against critical services.

Source: VECTR-CAST Threat Forecast (July 20, 2026)

Decades-Old Conficker Worm Still Infecting OT Environments Globally, Dragos Expert Warns

Dragos incident responder Lesley Carhart reports a surge in calls from critical‑infrastructure operators discovering 10‑to‑20‑year‑old infections — including Conficker — still active in OT environments. Legacy systems running Windows XP and older lack antivirus support, EDR/XDR tooling, and modern patching mechanisms, turning remediation into a recurring “whack‑a‑mole” exercise that can destabilize production systems. Carhart warns that accumulated legacy malware and the growing OT cybersecurity skills gap are increasingly causing component failures and complicating recovery efforts.

Source: Protect It All Podcast (Episode 115)

These developments reinforce that protecting industrial ecosystems requires more than discovery alone: organizations must combine scaled detection (including responsibly governed AI), rigorous asset hygiene, resilient compensating controls, and sustained investment in OT cyber skills and coordinated public‑private remediation pathways to reduce both cyber and physical risk.

Share this