Daily OT Security News — July 25, 2026. This briefing reviews significant OT, ICS, IoT, and critical-infrastructure cybersecurity developments reported during the latest news cycle. Operators should evaluate these developments against their own asset inventories, remote-access pathways, and incident-response procedures.
Iranian-Linked Actors Target Internet-Exposed PLCs Across Critical Infrastructure
New reporting on CISA’s updated AA26-097A advisory underscores an active threat to internet-exposed programmable logic controllers in U.S. government, water and wastewater, and energy environments. CISA says Iranian-affiliated actors have accessed Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other PLCs; observed activity includes altering or deleting project logic, manipulating HMI and SCADA data, and disabling shutdown or alarm logic. Immediate priorities are to eliminate direct PLC internet exposure, validate controller logic and backups, harden remote access with MFA, and monitor for abnormal configuration changes.
Source: CISA Advisory AA26-097A and Security Magazine coverage.
Rockwell Automation Arena Flaws Put Engineering Workstations in Focus
Rockwell Automation has addressed four high-severity out-of-bounds-write vulnerabilities in Arena Simulation Software: CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314. CISA identifies Arena versions through 17.00.00 as affected and warns that successful exploitation can enable arbitrary code execution in the current process. The latest reporting says exploitation requires a user to open a malicious file and identifies version 17.00.01 as the remediated release. Asset owners should identify Arena deployments, upgrade under established change-control procedures, and reinforce controls around untrusted engineering or simulation files.
Source: CISA ICS Advisory ICSA-26-197-01 and SecurityWeek report.
CIRCIA Rulemaking Keeps Incident-Reporting Readiness on the OT Agenda
CyberScoop reports that CISA has released town-hall transcripts as it continues work on the delayed Cyber Incident Reporting for Critical Infrastructure Act rule. The underlying statute calls for covered entities to report substantial cyber incidents within 72 hours and ransomware payments within 24 hours, while industry stakeholders are urging a narrower scope and less burdensome reporting requirements. Although the final rule’s timing and exact obligations remain unsettled, critical-infrastructure operators should continue to map decision rights, evidence collection, legal escalation, and communications processes so that a reportable incident can be assessed and documented rapidly.
Source: CyberScoop.
Connected Video Surveillance Requires the Same Device-Hygiene Discipline as Other IoT Assets
Axis Communications’ current review of video-surveillance cybersecurity highlights how cameras and related physical-security systems can become an entry point into corporate networks. The article emphasizes weak credentials, legacy devices, inconsistent policy adherence, and inadequate training as recurring risk factors. For organizations operating large IoT estates, the practical takeaway is to maintain accurate device inventories, enforce credential and lifecycle-management standards, segment device networks, and prioritize remediation according to exploitability and operational impact.
Source: Axis Communications.
This briefing is intended for informational purposes and should be evaluated alongside vendor guidance, risk assessments, and site-specific operating constraints before implementation.