Daily OT Security News: July 24, 2026

Cybersecurity news briefing — July 24, 2026.

U.S. agencies expand warning on Iranian-affiliated PLC activity

CISA’s revised advisory says Iranian-affiliated actors are exploiting internet-connected operational-technology devices, including PLCs, across U.S. government, water and wastewater, and energy environments. The update names Rockwell Automation/Allen‑Bradley, Schneider Electric, Siemens, and potentially other PLCs, and describes malicious project files, HMI/SCADA data manipulation, project-file exfiltration, and modifications to PLC logic. Operators should prioritize removing direct internet exposure, controlling remote access, reviewing logs and traffic for indicators, changing default credentials, and checking PLC project-file integrity.

CISA Advisory AA26-097A

CISA releases seven ICS advisories, including a high-severity ThinManager flaw

CISA’s July 23 ICS advisory batch covers Johnson Controls, Weintek, Panduit, Rockwell Automation, and MZ Automation products. One item, ICSA-26-204-05, rates a path‑traversal vulnerability in Rockwell Automation ThinManager at CVSS 8.1; in affected versions an authenticated attacker could write arbitrary files to restricted directories outside the intended application path. CISA reported no known public exploitation of this specific issue at publication; asset owners should validate version exposure and apply the vendor remediation in the advisory.

CISA Advisory ICSA-26-204-05

GAO review highlights overlapping cyber-reporting burdens for critical infrastructure

A GAO analysis reviewed 117 cybersecurity rules issued by 37 agencies across nine critical‑infrastructure sectors and found roughly 70% contained redundant reporting requirements; 80 rules overlapped incident, plan, or audit reporting. Water and energy are among the sectors where requirements may duplicate or conflict, making regulatory harmonization a material governance consideration for OT and critical‑infrastructure security leaders.

Cybersecurity Dive

Share this