Daily OT Security News: July 23, 2026

Brief updates on recent OT/ICS and cybersecurity developments.

U.S. agencies update PLC threat warning for critical infrastructure

A joint advisory last updated on July 22 warns that Iranian-affiliated cyber actors are exploiting programmable logic controllers across U.S. critical infrastructure. OT owners should treat internet-exposed control assets as a priority for exposure review and apply the advisory’s mitigations to reduce the likelihood of unauthorized process changes.

https://www.ic3.gov/CSA/2026/260722.pdf

Hikvision discloses five vulnerabilities in camera products

Hikvision’s July 22 advisory describes five vulnerabilities in certain cameras, including CVE-2026-57600, a CVSS 7.5 unauthenticated information-disclosure flaw, and two buffer overflows that may cause device malfunction. Organizations should identify affected models and deploy the applicable vendor firmware updates.

https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-some-hikvision-cameras/

OT AI use outpaces mature deployment and tested security controls

New Takepoint Research sponsored by Nozomi Networks and BlastWave reports that 87.7% of respondents are using, evaluating, piloting, or planning AI for OT cybersecurity, yet only 7.9% have deployed it across multiple OT-security functions. The report also finds limited confidence in tested safeguards for AI tools and models, underscoring the need for governance alongside adoption.

https://www.nozominetworks.com/press-release/less-than-8-of-ot-and-ics-companies-have-robust-ai-deployment-according-to-new-nozomi-networks-and-blastwave-sponsored-takepoint-research

GAO highlights potentially duplicative cybersecurity reporting requirements

A July 22 Government Accountability Office report examines cybersecurity regulations across multiple sectors and flags potentially duplicative reporting requirements. For critical-infrastructure organizations, the finding reinforces the importance of maintaining a clear evidence trail for cyber plans, incident processes, and regulatory submissions.

https://www.gao.gov/assets/gao-26-108606.pdf

Share this