Daily OT Security News — July 5, 2026. Today’s briefing covers newly published ICS advisories, an actively exploited enterprise product added to CISA’s Known Exploited Vulnerabilities list, a large credential exposure at a Japanese ISP, evolving federal mandates for OT/IoT cybersecurity, and fresh evidence of a widespread OT patching crisis. These developments underscore accelerating exploitation timelines and rising regulatory pressure on operational environments.
CISA publishes six new ICS advisories
On July 2, 2026, CISA released six Industrial Control Systems advisories covering a range of devices and vendors, including ST Engineering iDirect iQ-Series terminals, CubeSpace CW0057 reaction wheel, Gardyn IoT Hub and Home Kit updates, Mitsubishi Electric CNC Series (Update D), and WHILL electric wheelchairs (Update B). The advisories include vulnerability details and mitigation recommendations intended for asset owners and service providers to quickly assess exposure and apply compensating controls. Organizations operating heterogeneous OT/IoT inventories should prioritize identification of these affected assets and follow CISA’s guidance to reduce immediate risk.
Source: OpenText Cybersecurity Community
Critical PTC Windchill RCE (CVE-2026-12569) being actively exploited; added to CISA KEV
A critical remote code execution vulnerability in PTC Windchill and FlexPLM (CVE-2026-12569) is under active exploitation, with reports of web shells being deployed on exposed systems. Given Windchill’s widespread use in manufacturing, aerospace, and automotive environments to manage intellectual property and product lifecycle data, the risk to industrial supply chains is substantial. CISA has added the flaw to its Known Exploited Vulnerabilities list after evidence of active campaigns, illustrating how quickly attackers are weaponizing newly disclosed flaws.
Source: Integrity360
KDDI breach exposes roughly 14.2 million credentials, increasing phishing and stuffing risk
Japanese telecom provider KDDI disclosed a breach affecting systems used by multiple internet service providers that may have exposed approximately 14.2 million email/password pairs. The incident was traced to exploitation of a third‑party software vulnerability and raises immediate concern for credential‑stuffing and phishing campaigns that could target OT/ICS personnel and vendor accounts. Operators should assume credential reuse across corporate and industrial accounts and enforce multi‑factor authentication and credential hygiene as mitigations.
Source: Integrity360
OMB M-26-14 and CISA BOD 26-04 bring OT/IoT into federal cybersecurity programs
The Office of Management and Budget’s M-26-14 and CISA’s Binding Operational Directive 26-04 formally bring OT and IoT assets into scope for federal civilian agency cybersecurity programs. BOD 26-04 replaces flat KEV remediation deadlines with a four‑variable, risk‑based remediation model that considers asset exposure, KEV status, exploit automation, and technical impact; Phase 1 compliance is already underway. Agencies and contractors should prepare for full enforcement of tiered remediation timelines, expected to take effect within the next six months.
Source: Nozomi Networks Blog
OT patch management crisis: 85% of organizations not patching regularly
Survey data and threat reporting indicate a serious OT patching shortfall: TXOne Networks’ 2024 OT/ICS survey found 85% of organizations do not perform regular patching in OT environments, and 10% of oil and gas respondents reported stopping patching entirely. Rapid7’s 2026 analysis shows mean time‑to‑exploit dropping to 28.5 days, driven in part by AI‑assisted exploit development, and the EU Cyber Resilience Act’s reporting obligations begin in September 2026, intensifying regulatory and operational urgency. Organizations must reconcile operational availability with accelerated exploitation timelines by improving compensating controls, patch testing, and risk‑based prioritization.
Source: Portainer Blog
Closing note: The convergence of faster exploit timelines, large-scale credential exposures, new federal mandates, and persistent patching deficits makes OT/ICS risk management an urgent priority. Asset owners, integrators, and operators should accelerate discovery, authentication hygiene, segmentation, and risk‑based remediation to reduce the likelihood and impact of operational disruptions.