Daily OT Security News: October 01, 2026

This briefing highlights five new developments affecting cyber risk across transport, federal device security, network infrastructure, and water utilities, with a focus on visibility, remediation, and operational resilience.

Shieldworkz finds Adif web infrastructure served as entry point for Renfe compromise in AI-assisted cyber breach

Shieldworkz’s analysis reconstructed a breach in which attackers compromised Adif’s external-facing web infrastructure and pivoted into interconnected Renfe IT systems. Passenger names and email addresses were exposed while no evidence indicated compromise of payment data, national ID numbers, passwords, or safety-critical rail-control systems. Adif detected abnormal behavior on September 24, took public web services offline on September 25, and services were reportedly restored by September 26; the precise exploitation method, AI role, data volume, attack attribution, and traversal extent remain under investigation.

Source: Industrial Cyber

FDD says Chinese infrastructure footprint, cybersecurity gaps threaten NATO military mobility corridors across Europe

The Foundation for Defense of Democracies analysis warns NATO military mobility depends on civilian roads, railways, ports, airfields and digital systems whose cybersecurity governance is fragmented. The report notes Chinese state-linked holdings in more than 30 European port terminals and stakes in at least 14 of 29 ports near NATO naval facilities or supporting NATO logistics. It recommends aligning NATO spending, cyber assessments, investment screening, logistics capacity, navigation resilience, and workforce development with reinforcement plans and asks the NATO Integrated Cyber Defence Centre to assess operational consequences of dependent transport and energy networks.

Source: Industrial Cyber

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-76504, a Cisco Catalyst SD-WAN Manager hex-encoding vulnerability, to its Known Exploited Vulnerabilities Catalog citing evidence of active exploitation. CISA described KEV items as frequent attack vectors that pose significant risks to the federal enterprise and noted BOD 26-04 requires FCEB agencies to prioritize remediation of specified high-risk KEVs on publicly exposed assets and to assess possible compromise before patching. CISA encouraged all organizations to adopt risk-based vulnerability management and prioritize KEV remediation.

Source: Cybersecurity and Infrastructure Security Agency (CISA)

Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices

GAO found that most of the 22 civilian CFO Act agencies it reviewed had not fully implemented OMB requirements for inventories of networked IoT and OT devices that interact with the physical world. Only seven of 22 agencies had fully addressed all three OMB networked-device requirements; fifteen had established an inventory, eleven were maintaining inventories, and ten had included all required information for each device as of September 2026. GAO recommended that OMB issue updated FY2026 cybersecurity guidance and oversee agency implementation because incomplete inventories can leave sensitive systems and data insufficiently protected.

Source: U.S. Government Accountability Office (GAO)

WaterISAC taps Cyware to strengthen water utility cyber defense

WaterISAC has partnered with Cyware to expand real-time cyber-threat intelligence and information sharing for U.S. water and wastewater utilities using Cyware’s threat-intelligence platform. The partnership aims to improve collection, analysis, and distribution of information about threats and vulnerabilities affecting water infrastructure to reduce manual work and speed utilities’ response to potential threats. The story identifies both IT and OT cyber concerns and notes WaterISAC’s National Rural Water Association partnership extends cybersecurity resources to more than 20,000 smaller water utilities.

Source: Underground Infrastructure

Organizations should assess affected assets, prioritize validated remediation, and coordinate IT and OT teams around operational risk as these developments evolve.

Share this