Daily OT Security News: October 06, 2026

Today’s Daily OT Security News briefs five verified stories affecting OT, IoT, healthcare, federal policy, and industrial insider threats.

Post-Quantum Cryptography in Healthcare: Forescout Research Reveals Critical Readiness Gaps Putting Patient Data at Risk

Forescout’s Vedere Labs report examined more than 2.5 million devices across over 50 healthcare delivery organizations and found that 6% of IoMT devices and 16% of OT devices used SSH implementations capable of supporting post-quantum cryptography, compared with 50% of IT devices. The release also reported more than 5,500 internet-exposed healthcare systems, including EMR and PACS platforms, and said 31% of the exposed systems supported TLS 1.3; the findings are reported as Forescout/Vedere Labs research results and were not independently audited.

Source: Business Wire / Forescout Technologies

Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data

ATB, Ukraine’s largest grocery chain, confirmed it was hit by a cyberattack and said it temporarily took some online services offline for technical maintenance while denying that customer data had been compromised. The DataSuckers group posted a $400,000 extortion demand on the retailer’s website and claimed to have stolen data on 7.9 million customers; that claim was not independently verified. ATB operates more than 1,300 stores and employs over 60,000 people.

Source: The Record

ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes

FortiGuard Labs tracked ClingSTUN, a Linux back-connect proxy backdoor that exploits known, unpatched vulnerabilities in Internet-facing IoT devices to establish persistence and turn compromised systems into remote proxy nodes. The malware uses public STUN infrastructure to learn externally mapped addresses and ports for NAT connectivity, and FortiGuard found seven hard-coded exploits that support self-propagation; reporting described initial-access exploitation of at least 24 known vulnerabilities across routers, surveillance systems, industrial systems, and other network equipment. The campaign affects exposed networked devices, including surveillance and industrial systems.

Source: Dark Reading

Here’s how experts think CISA should tell agencies to protect OT

The Operational Technology Cybersecurity Coalition urged CISA to issue an OT-specific binding operational directive for federal agencies that would define responsibility, draw on existing guidance, and set minimum security practices. The proposal follows gaps in visibility and policy for federal OT systems and notes a GAO finding that only seven of 22 civilian CFO Act agencies had fully met all three OMB networked-device inventory requirements as of September 2026. The proposal would also consider aligning requirements with CISA cybersecurity performance goals and examining NSA OT guidance.

Source: CyberScoop

Ex-Industrial Firm Worker to Slammer for Extortion

The U.S. Department of Justice announced that former core-infrastructure engineer Daniel Rhyne was sentenced to 32 months in federal prison after pleading guilty to intentionally damaging his former employer’s computer network and extorting employees. In November 2023 he used unauthorized remote-desktop sessions and scheduled tasks that locked Windows administrators out of 254 servers and would have affected 3,284 workstations, then demanded about 20 bitcoin (then valued at about $750,000). The victim was a U.S.-based industrial company headquartered in New Jersey.

Source: ISSSource

End of briefing.

Share this