The OT/ICS/IoT security landscape remains highly dynamic and risk-prone, with rapid exploit activity, rising ransomware pressure, and growing regulatory demands. Today’s briefing highlights urgent vulnerabilities, major vendor announcements, and policy changes that directly affect industrial operators, manufacturers, and critical infrastructure owners.
CISA Issues Critical Advisory for Naxclow IoT Platform (CVSS 9.8)
On June 11, 2026, CISA published an ICS advisory covering Naxclow IoT Platform products — including Smart Doorbell X3, X Smart Home, V720, and ix cam — affecting all versions worldwide and rated CVSS 9.8. The flaws include authorization bypass via user-controlled keys, missing authorization checks, hard-coded cryptographic keys, and predictable identifiers, which could enable device impersonation, interception or manipulation of communications, credential harvesting at scale, and unauthorized access; CISA recommends immediate inventory, network segmentation, credential rotation, and enhanced monitoring for all affected devices.
Source: Windows Forum / CISA Advisory
Ivanti Sentry Max-Severity Flaw (CVE-2026-10520, CVSS 10) Exploited Within 24 Hours
A maximum-severity OS command injection flaw in Ivanti Sentry (CVE-2026-10520, CVSS 10.0) was actively exploited within 24 hours of public disclosure on June 11, 2026, enabling unauthenticated remote code execution with root privileges on affected versions prior to R10.5.2, R10.6.2, and R10.7.1. Shadowserver observed large-scale exploitation leveraging a public proof-of-concept and confirmed at least two backdoored instances; because Sentry functions as an in-line gateway for mobile-to-enterprise access, compromised appliances present an acute risk to OT and enterprise environments, and organizations should patch immediately and assume compromise where updates were not applied before exploitation was observed.
Source: Dark Reading
Honeywell Expands OT Cybersecurity Suite with AI-Powered Industrial Defense
At its User Group Meeting on June 12, 2026, Honeywell announced five new capabilities for its OT Cybersecurity Suite: a Secure Media Exchange (SMX) Portable Scanner for USB inspection in air-gapped systems, Cyber Proactive Defense (CPD) — an AI-powered OT monitoring solution, automated Cyber GRC functionality, a Data Diode for unidirectional transfers, and a 24/7 OT Security Operations Center. The launch arrives amid World Economic Forum data showing only 32% of industrial organizations actively monitor OT systems and just 20% maintain dedicated OT security teams, and the suite is available now for manufacturing, energy, and other critical infrastructure sectors.
Source: ARC Advisory Group
EU Cyber Resilience Act: 24-Hour IoT Vulnerability Reporting Clock Starts September 11, 2026
With the September 11, 2026 deadline 92 days away, the EU Cyber Resilience Act will require manufacturers selling connected devices into the EU to file an early warning with ENISA within 24 hours of detecting an actively exploited vulnerability, followed by a 72-hour full notification and a 14-day final report. Non-compliance can trigger product withdrawal from the EU market and penalties up to €15 million or 2.5% of global annual turnover; ENISA’s Single Reporting Platform will go live by September 11 with registration and dry-run support available in June 2026, while broader CRA obligations including CE marking and secure-by-design rules take effect December 11, 2027.
Source: TechTimes
Ransomware Attacks Surge 48% Year-Over-Year; Industrial Manufacturing Among Hardest Hit
Check Point Research’s May 2026 report found ransomware incidents rose 48% year-over-year to 698 incidents, with industrial manufacturing victims increasing 50% and business services representing 35% of victims after a 359% spike. The ecosystem is fragmented with 61 active groups in May — Qilin accounted for 14% of published attacks — North America absorbed 49% of incidents (the U.S. alone 43%), and legislative responses are emerging: Senator Mark Warner introduced the Combat Emerging Threats to Critical Infrastructure Act of 2026 to require CISA updates to sector plans and assessments of AI-driven threats across all 16 critical infrastructure sectors.
Source: Industrial Cyber
Overall, the briefing underscores a fast-moving threat environment where high-severity vulnerabilities are weaponized in hours, ransomware activity targets industrial operators aggressively, and regulators are imposing tighter, time-critical disclosure and security requirements. Operators should prioritize immediate patching, aggressive network segmentation, inventory and credential hygiene, and operational readiness for mandatory reporting to reduce exposure and comply with evolving legal obligations.