Daily OT Security News: July 28, 2026

Tengu expands the Mirai playbook for exposed IoT devices

Nozomi Networks Labs describes Tengu as a Mirai-derived IoT malware family that targets exposed Linux-based devices. The analysis documents Telnet brute-force delivery, encrypted command-and-control, proxy functionality, network and system discovery, payload updates, persistence, self-defense measures, and multiple denial-of-service capabilities. The report highlights operational indicators and stresses defensive controls including timely patching, removal of default credentials, network segmentation, and enhanced monitoring of exposed devices to reduce compromise and limit abuse.

Read the source report

Dysphoria botnet shifts command-and-control to blockchain naming services

The Hacker News reports that the Dysphoria IoT botnet shifted its command-and-control to blockchain-based naming services and added compromised-device relay capability following disruption of JackSkid infrastructure. Citing XLab and CNCERT, the coverage says Dysphoria propagates via Telnet and SSH weak-password guessing and exploits known remote-code-execution vulnerabilities in routers, gateways, and cameras. The change in C2 approach leverages decentralized name resolution to complicate takedown and to route commands through compromised relays.

Read the source report

Automotive vulnerability volume and severity rise in the second quarter

SecurityBrief UK summarizes PCA Cyber Security’s Q2 analysis that found 345 unique automotive vulnerabilities, including 161 classified as high severity, up from 75 high-severity findings in Q1. The analysis reports that 94% of cases involved low attack complexity and lists local-shell access as the most common of fourteen documented attack methods. The coverage notes that the vulnerabilities affect vehicles as well as charging networks, mobility platforms, and supply chain components, indicating a broad exposure vector set across the automotive ecosystem.

Read the source report

EU Cyber Resilience Act reporting obligations approach for connected products

The European Commission’s Cyber Resilience Act guidance states that, from September 11, 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents. The guidance requires an early warning within 24 hours of awareness and a full notification within 72 hours, with reports submitted via the CRA Single Reporting Platform to the relevant CSIRT. The Commission indicates that information submitted will generally be made available simultaneously to ENISA. The guidance was updated on June 8, 2026.

Read the source report

Share this