Daily OT Security News: July 26, 2026

Today’s OT threat landscape continues to show targeted activity against industrial control systems, persistent ransomware pressure on manufacturing, and exposure from connected devices and management interfaces. Organizations should prioritize detection of unauthorized changes, patching of critical management platforms, and restricting internet-facing administrative access.

U.S. agencies warn of Iranian-affiliated PLC targeting

CISA, FBI, NSA, EPA, DOE, U.S. Cyber Command, and Treasury updated guidance reporting Iranian‑affiliated actors targeting internet‑connected PLCs used by U.S. critical infrastructure, with observed malicious interactions affecting PLC project files and HMI/SCADA displays. The July update expands vendor observations to include Rockwell Automation/Allen‑Bradley, Schneider Electric, and Siemens and adds detection guidance for malicious changes to reusable Rockwell PLC code modules.

Source: Link

SonicWall report finds high IoT, camera, and SCADA exposure in manufacturing

SonicWall’s Manufacturing Protect Brief reports 474 million manufacturing IPS events in H1 2026 despite a reported 56.2% year‑over‑year decline, and identifies manufacturing as having the highest SCADA attack detection rate among tracked verticals. The brief highlights large volumes of IoT and camera-related hits, including continued exploitation attempts tied to a known Hikvision vulnerability, and connects device exposure and IT/OT convergence to rising operational risk.

Source: Link

Black Kite: ransomware incidents rise, manufacturing most-targeted sector

Black Kite reports 7,551 publicly disclosed ransomware victims from April 2025 through March 2026, a 24.9% year‑over‑year increase, with manufacturing the top‑targeted sector for the fourth consecutive year. Its rescans found many disclosed victims remain exposed to high‑severity and known‑exploited vulnerabilities, underscoring gaps in post‑incident remediation.

Source: Link

Check Point urges immediate remediation for exploited management authentication bypass

Check Point warns that CVE‑2026‑16232 is an authentication‑bypass vulnerability (CVSS 9.3) affecting Security Management and Multi‑Domain Management releases and reports observed exploitation against customers whose management interfaces were exposed to the internet without IP restrictions. The vendor recommends installing the July jumbo hotfix and immediately restricting management access to trusted IPs or subnets.

Source: Link

Deadlock ransomware group lists Enedo Power; claim unverified

Threat feeds reported that the Deadlock ransomware group listed Enedo Power (now Inission Power), a supplier of intelligent power solutions serving industrial and transport sectors, as a victim; the listing is presented as a group claim and has not been confirmed by the company. Treat the report as an unverified listing while monitoring for any vendor or victim statements and independent forensic confirmation.

Source: Link

Closing note: prioritize patching and access controls for management interfaces, monitor PLC/HMI integrity, and validate remediations after incidents to reduce persistent exposure in OT environments.

Share this