Below are concise briefs on key industrial cybersecurity developments reported July 22, 2026. Each item highlights operational risk and recommended actions for OT/ICS and enterprise defenders.
CISA issues ICS advisory for Rockwell 1734 POINT I/O (CVE-2026-10573)
CISA released multiple ICS advisories on July 21, calling out CVE-2026-10573 in Rockwell Automation 1734 POINT I/O (v3.023), a flaw that can be exploited to cause denial-of-service. The agency recommends minimizing network exposure of affected devices, using segmented firewalls, and securing or disabling remote access paths until mitigations are applied.
Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09
Nozomi Networks joins Anthropic’s Project Glasswing for AI-assisted vulnerability discovery
Nozomi Networks announced participation in Anthropic’s Project Glasswing to apply large AI models (Claude Mythos) to OT, IoT, and cyber-physical systems vulnerability research. The collaboration surfaced more than 10,000 potential high/critical issues across participating codebases, though the project emphasizes that human validation and OT operational context remain essential to prioritize and safely remediate findings.
Source: https://iottechnews.com/news/anthropic-ai-vulnerability-research-ot-security-nozomi-networks/
Executive order directs mapping of critical defense supply chains
A new executive order directs the Department of War to establish rules requiring contractors to map critical defense supply chains, including software and firmware dependencies, component provenance, and supplier origins. The requirement will broaden third-party risk and compliance obligations for defense suppliers and increase emphasis on software bill-of-materials and supplier traceability.
CISA adds four actively exploited vulnerabilities to KEV catalog, remediation due July 24
CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a critical flaw in Langflow (CVE-2026-0770) and a high-severity buffer overflow in DD-WRT (CVE-2021-27137), a firmware platform used on consumer and enterprise network devices. CISA’s federal remediation deadlines apply to the listed high-risk entries, while all organizations are encouraged to prioritize risk-based remediation of known-exploited vulnerabilities.
Black Kite: 43% of ransomware victims retain unpatched critical vulnerabilities after response
A Black Kite analysis found that 43% of organizations hit by ransomware still had unpatched critical vulnerabilities following incident response activities, indicating persistent remediation gaps. The report also shows manufacturing remains the most targeted sector, accounting for 22% of victims listed on dark-web leak sites over the past year.
Source: https://www.cybersecuritydive.com/news/ransomware-lingering-weaknesses-black-kite/825791/
Closing note: Organizations should prioritize patching and network segmentation for exposed OT/ICS assets, incorporate vendor and software supply-chain mapping into risk programs, and validate AI-discovered findings with operational SMEs before deployment.