Daily OT Security News: July 7, 2026

Daily OT Security News: July 7, 2026

Today’s roundup covers emerging Golang botnets targeting exposed IoT devices, a critical PTC Windchill RCE added to CISA’s KEV list, a long-dormant Linux KVM VM-escape flaw, a Raspberry Pi 5 KASLR bypass, and a sobering forecast for record CVE volume in 2026. These items are particularly relevant to OT and industrial operators managing IoT, virtualized, and edge infrastructures.

Golang-Based Botnets Apex2 and c2c/meow Target Exposed IoT Devices

Nozomi Networks Labs has identified two new Golang-based malware families — Apex2 and c2c/meow — actively targeting internet-exposed IoT and Linux systems this spring. Apex2 is a structured evolution of an earlier botnet supporting both Windows and Linux architectures, capable of multiple DDoS flood attack types including HTTP, UDP, and TLS floods. The c2c/meow campaign uses a simpler design: a separate SSH scanner identifies weak-credential devices, then deploys the payload which establishes persistence by masquerading as a ‘CPU Frequency Daemon’ systemd service. Both families highlight how Golang, reusable open-source components, and automation have dramatically lowered the barrier to building functional botnets. Defenders are urged to eliminate default credentials, restrict internet-facing management services, and monitor for anomalous outbound connections from IoT assets.

Source: Nozomi Networks Labs

CVE-2026-12569: Unauthenticated RCE in PTC Windchill PLM Actively Exploited, Added to CISA KEV

CISA added CVE-2026-12569 — a critical unauthenticated remote code execution flaw (CVSS 9.3) in PTC Windchill and FlexPLM — to its Known Exploited Vulnerabilities catalogue on June 25, 2026. PTC confirmed active exploitation just one day after disclosing the flaw on June 17, with attackers dropping JSP web shells inside Windchill’s login directory. The vulnerability, an improper input validation issue enabling deserialization of untrusted data, requires no credentials and can be triggered remotely at scale. Germany’s BSI contacted administrators directly to urge immediate patching, and US federal agencies were given until June 28 to remediate. Windchill PLM systems hold CAD drawings, bills of materials, supplier data, and engineering IP — making a successful compromise equivalent to the theft of a manufacturer’s crown jewels. This is the second critical RCE in PTC’s PLM platform in 2026, following CVE-2026-4681 in March, signaling that the product has become a recurring high-value target.

Source: Hard2bit Security Research

Januscape (CVE-2026-53359): 16-Year-Old Linux KVM Flaw Enables VM Escape on Intel and AMD

Security researcher Hyunwoo Kim disclosed CVE-2026-53359, dubbed ‘Januscape,’ a use-after-free vulnerability in the Linux KVM hypervisor’s shadow MMU code that lay dormant for 16 years. The flaw is the first known KVM exploit triggerable on both Intel and AMD architectures, allowing a guest VM to corrupt the host kernel’s shadow page state and achieve full host compromise. An attacker renting a single public cloud instance could exploit Januscape to crash every co-tenant VM on the same physical host (DoS) or execute code with root privileges to take over the host entirely (RCE). On RHEL and similar distributions, unprivileged users may also leverage the flaw for local privilege escalation. The vulnerability was patched in mainline Linux on June 19, 2026. OT and ICS environments running virtualized infrastructure or cloud-connected workloads should prioritize kernel updates immediately.

Source: SecurityWeek

Raspberry Pi 5 KASLR Bypass: CVE-2026-13199 Exposes Insufficient Entropy in rpi-eeprom

Nozomi Networks researcher Gabriele Quagliarella disclosed CVE-2026-13199, a CWE-331 insufficient entropy vulnerability in the rpi-eeprom package (versions prior to 28.22-1) on Raspberry Pi 5 and Compute Module 5. The flaw produces non-random KASLR and RNG seed values across reboots, enabling a local attacker to predict the Linux kernel base address and bypass KASLR protection. Raspberry Pi devices are widely deployed in industrial edge computing, building automation, and OT/IoT gateway roles, making this a relevant concern for operational technology environments. The fix is available by updating the rpi-eeprom package to version 28.22-1 or later. The advisory was published on July 6, 2026.

Source: Nozomi Networks Labs

2026 on Track for Record 50,000+ CVEs as IoT Expansion Widens Attack Surface

FIRST (Forum of Incident Response and Security Teams) forecasts that 2026 will break all previous records for vulnerability disclosures, reaching or surpassing 50,000 new CVEs — a dramatic increase from the 10,000–15,000 typical of prior years. The primary drivers include the rapid expansion of the IoT ecosystem (estimated at 20 billion devices in 2026), the proliferation of cloud services, and growing software complexity in critical infrastructure. IoT devices, frequently running outdated firmware with limited visibility and inadequate security controls, represent a disproportionate share of the new attack surface. The surge reinforces the urgency of proactive vulnerability management, asset inventory, and patch prioritization programs — particularly for OT and ICS operators who must balance patching cadence against operational continuity requirements.

Source: Daily Huntline / FIRST

Share this