Viakoo Daily OT Security News — September 01, 2026: concise summaries of five stories affecting OT operators, device manufacturers, and industrial software supply chains.
UK NCSC Warns of Growing Risk From Internet-Exposed OT
The UK National Cyber Security Centre warned that attacks on operational technology systems are increasing and urged operators to inventory OT architecture and ensure PLCs and HMIs are not directly exposed to the internet. The report notes exposed OT and edge devices commonly have outdated firmware or default credentials and describes a July wave of attacks against more than 100 water and wastewater systems involving PLCs connected through mobile-network SIM cards; recommended controls include strong authentication, restricted external access, secure protocols, logging, segmentation, and recovery planning.
Source: GovInfoSecurity
Google Cloud and Mandiant Urge Water Utilities to Harden Internet-Connected PLCs
Google Cloud’s Chris Sistrunk and Stephanie Kiel report increased targeting of internet-connected PLCs at U.S. water utilities and recommend a baseline that includes inventorying assets and exposure, replacing default credentials, hardening access points, backups and spares, segmentation and MFA, incident planning, and auditing third-party remote connections. The post says this advice aligns with guidance from AWWA, NRWA, Water-ISAC, EPA, CISA, and the FBI.
Source: Google Cloud
EU Cyber Resilience Act Reporting Obligations Begin September 11
Freshfields reports that the EU Cyber Resilience Act enters a new implementation phase on September 11, 2026, requiring manufacturers to report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. Obligations include an early warning within 24 hours and a detailed notification within 72 hours, and Freshfields recommends assigned ownership and rapid procedures for assessment, escalation, notification, affected-user communication, and coordination with NIS2 and GDPR duties.
Source: Lexology
Offshore Energy Sector Confronts Ransomware and OT Exposure Risks
Oil & Gas Journal reports that offshore energy infrastructure faces combined cyber and physical threats as digitalization, remote operations, and geopolitical tensions reshape risk, highlighting ransomware, navigation-system interference, supply-chain compromise, and physical sabotage. The report says state-linked and organized criminal actors seek long-term access to critical infrastructure and that greater IT/OT interconnection gives attackers remote-access paths from corporate networks into critical operational systems.
Source: Oil & Gas Journal
Critical JFrog Artifactory Authentication Bypass Reportedly Exploited
SecurityWeek reports that CVE-2026-82329, a critical authentication-bypass vulnerability in JFrog Artifactory, was reportedly exploited days after public disclosure; JFrog said an unauthenticated network attacker could obtain administrative privileges under the default configuration. Cloud instances were patched and self-hosted users were advised to update to patched releases, and observers reported attackers minting administrator tokens; the issue is relevant to industrial organizations that use self-hosted repositories for connected-device or operational-environment software supply chains.
Source: SecurityWeek
End of edition — check back for updates and operational security guidance relevant to OT and connected devices.