Daily OT Security News — July 25, 2026. Today’s briefing covers a vendor patch for simulation software, a multi-agency advisory on PLC targeting, a new measurement of internet-exposed ICS hosts, a policy proposal for OT standards, and a supplier certification for secure product development.
Rockwell Patches Four High-Severity Arena Simulation Vulnerabilities
SecurityWeek reported that Rockwell Automation patched four high-severity memory-corruption vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314) in Arena Simulation. Versions through 17.00.00 are affected and version 17.00.01 contains the fixes; a successful attack requires a user to open a malicious Arena experiment or model file and could run code in the Arena process context. CISA and Rockwell reported no evidence of in-the-wild exploitation.
Source: SecurityWeek
U.S. Agencies Warn of Continued Iran-Linked Targeting of Internet-Exposed PLCs
SC Media reported that seven U.S. federal agencies updated a warning about Iran-linked activity targeting operational-technology devices from Siemens, Schneider Electric, and Rockwell Automation. The underlying CISA advisory says actors used vendor programming software and foreign-hosted infrastructure to access misconfigured internet-facing PLCs, exfiltrate project files, and in reported cases alter or delete logic and manipulate HMI/SCADA displays. Recommended actions include removing PLCs from direct internet exposure, using secure gateways and firewalls, and reviewing logs for suspicious traffic and unauthorized changes.
Source: SC Media
Censys Finds 138,000 Internet-Exposed ICS Hosts in Early 2026
Cybersecurity Dive reported on a Censys preview showing an average of 138,000 distinct hosts running internet-exposed ICS services and tooling in early 2026, up from about 129,000 in 2024. Censys said North America represented roughly 38% of exposures, Asia’s share grew from 22.9% to 27%, and approximately 70% of hosts running ICS devices and services were consistently found on consumer and mobile networks over the prior 2.5 years.
Source: Cybersecurity Dive
OT Cybersecurity Coalition Urges ISA/IEC 62443 as a U.S. Policy Foundation
Inside Cybersecurity reported that the Operational Technology Cybersecurity Coalition released a position paper advocating ISA/IEC 62443 as a single, globally interoperable framework for industrial and operational technology cybersecurity policy. The coalition argued that overlapping rules can create duplicative compliance work and recommended recognition of ISA/IEC 62443, interoperability-focused adoption, sector guidance and capacity building, and investment in the OT workforce.
Source: Inside Cybersecurity
Panasonic Industry Receives IEC 62443-4-1 Certification for Industrial Automation Products
EEJournal reported that Panasonic Industry’s Industrial Device Business Division achieved IEC 62443-4-1 certification for relevant industrial automation and control-system products, with TÜV SÜD confirming the supplier’s secure product-development lifecycle processes. Panasonic also published product-security policy and vulnerability-information resources in connection with its response to the EU Cyber Resilience Act.
Source: EEJournal
More updates will follow as agencies, vendors, and researchers publish additional details.