Daily OT Security News: September 06, 2026

Briefing for OT, ICS, IoT, and cyber-physical-security leaders: concise summaries of verified developments and recommended follow-up actions from the named sources below.

CISA Scraps Six Free Cybersecurity Assessments for Critical Infrastructure Operators

Cybersecurity Dive reports that CISA is ending six free cybersecurity assessment services: Cyber Resilience Reviews, External Dependencies Management Assessments, Cyber Infrastructure Surveys, Ransomware Readiness Assessments, Incident Management Reviews, and facilitated use of the Cyber Security Evaluation Tool (CSET). The report says CISA will direct organizations toward its Cross-Sector Cybersecurity Performance Goals, and notes CSET remains open source; these services had supported water utilities, hospitals, local governments, and other critical-infrastructure operators via regional-adviser assistance.

Source: Cybersecurity Dive

Project Watershed 250 Adds OT Monitoring and Visibility Support for Water Utilities

Futurum Group reported on September 5 that Forescout announced participation in Project Watershed 250, which Futurum describes as a White House- and Texas-backed public-private initiative for water and wastewater utilities. Futurum and Forescout describe capabilities including continuous monitoring, OT/IT asset visibility, adversary-focused assessments, vulnerability prioritization, network segmentation, and automated threat response; Futurum attributes the initiative’s scope to its coverage and Forescout’s announcement.

Source: Futurum Group

PaperCut Vulnerabilities Are Being Exploited to Gain Privileged Access

Security Affairs reports active exploitation of CVE-2026-81578 and CVE-2026-82078 in PaperCut servers, citing Arctic Wolf observations that attackers chain an authentication bypass with remote code execution to conduct reconnaissance, create privileged accounts, collect credentials, and discover PaperCut configuration secrets. The report says PaperCut disclosed active exploitation on August 27 and that CISA added both CVEs to its Known Exploited Vulnerabilities catalog on August 31; Security Affairs and Arctic Wolf recommend applying vendor fixes, reviewing server logs, and keeping management interfaces off the public internet. This concerns connected enterprise management infrastructure and is not presented as an ICS-specific vulnerability.

Source: Security Affairs

MikroTik Calls for RouterOS Updates and Post-Compromise Configuration Review

Security Online reports that the relevant RouterOS security-fixed releases are 7.24.2, 7.23.4, 6.49.21, and 7.25 beta 3, and cautions that applying an update does not remove unauthorized configuration changes, accounts, or scripts that may have been left by an intruder. The report recommends reviewing logs, users, scripts, and configuration; deleting unfamiliar content; resetting credentials; and restricting WinBox, WebFig, and SSH behind a firewall, VLAN, and VPN.

Source: Security Online

Cyber Resilience Act Reporting Duty Takes Effect September 11 for Connected-Device Makers

Teldat’s current Article 14 explainer says the EU Cyber Resilience Act reporting duty begins on September 11, 2026, and that manufacturers of products with digital elements must report actively exploited vulnerabilities and severe product-security incidents, including for products already on the EU market. According to Teldat, the process includes an early warning within 24 hours of awareness, a full notification within 72 hours, a final report for vulnerabilities within 14 days of a fix being available, and filing through ENISA’s Single Reporting Platform and the relevant national CSIRT; this item is presented as regulatory information, not legal advice.

Source: Teldat

Monitor the named vendor advisories, government guidance, and your organization’s logging and access controls to prioritize mitigations and compliance steps indicated by these reports.

Share this