Brief updates on recent OT/ICS and cybersecurity developments.
U.S. agencies update PLC threat warning for critical infrastructure
A joint advisory last updated on July 22 warns that Iranian-affiliated cyber actors are exploiting programmable logic controllers across U.S. critical infrastructure. OT owners should treat internet-exposed control assets as a priority for exposure review and apply the advisory’s mitigations to reduce the likelihood of unauthorized process changes.
https://www.ic3.gov/CSA/2026/260722.pdf
Hikvision discloses five vulnerabilities in camera products
Hikvision’s July 22 advisory describes five vulnerabilities in certain cameras, including CVE-2026-57600, a CVSS 7.5 unauthenticated information-disclosure flaw, and two buffer overflows that may cause device malfunction. Organizations should identify affected models and deploy the applicable vendor firmware updates.
OT AI use outpaces mature deployment and tested security controls
New Takepoint Research sponsored by Nozomi Networks and BlastWave reports that 87.7% of respondents are using, evaluating, piloting, or planning AI for OT cybersecurity, yet only 7.9% have deployed it across multiple OT-security functions. The report also finds limited confidence in tested safeguards for AI tools and models, underscoring the need for governance alongside adoption.
GAO highlights potentially duplicative cybersecurity reporting requirements
A July 22 Government Accountability Office report examines cybersecurity regulations across multiple sectors and flags potentially duplicative reporting requirements. For critical-infrastructure organizations, the finding reinforces the importance of maintaining a clear evidence trail for cyber plans, incident processes, and regulatory submissions.