Daily OT Security News: September 07, 2026

Today’s selection covers IoT, OT, ICS and cyber-physical-system security developments that may affect edge networking, management platforms, industrial assets and healthcare devices.

Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting a chain of two MikroTik RouterOS vulnerabilities to take full control of routers whose SSH service is exposed to the internet. MikroTik released fixed RouterOS versions on September 3 and administrators are advised to update, inspect logs and configurations for compromise, isolate and rebuild suspected devices, and rotate credentials and keys.

Source: BleepingComputer

N-able patches max severity N-central flaw amid ongoing attacks

N-able released N-central 2026.3 Hotfix 4 for CVE-2026-86218, described as a maximum-severity unauthenticated remote-code-execution vulnerability that can let attackers run code on internet-exposed N-central systems. Huntress reported a compromised production environment but could not determine which disclosed vulnerability was used; N-able urged immediate patching while Shadowserver tracks nearly 1,500 exposed N-central servers.

Source: BleepingComputer

North Korean Hackers Deploy New Linux Espionage Toolkit

SecurityWeek reports North Korea-aligned actors used a Linux espionage toolkit against automotive and media organizations in South Korea that embeds the ‘ted backdoor’ into HAProxy and combines trojanized system tools, a curl-based RAT, an SSH keylogger, and a stager. Initial access reportedly came via a vulnerability in a Groupware login portal, after which credential harvesting and lateral movement were enabled by the SSH keylogger.

Source: SecurityWeek

Berlin Ransomware Leak Exposes State Secrets

Security Affairs reports the Rhysida ransomware group published data it alleges was stolen from Berlin’s state administrative network after authorities refused a 30 Bitcoin ransom demand. The claimed leak totals 5.79 TB across about 1.44 million files and reportedly includes personal data, plaintext credentials, and vulnerability analyses concerning Berlin’s water supply; the state has launched a central crisis unit to review the data and notify affected parties.

Source: Security Affairs

An intelligent cyber-attack detection framework for healthcare cyber-physical systems using optimized graph-based deep learning

A Scientific Reports article proposes a healthcare CPS attack detector that combines BitonicX Filtering, Gabor Wavelets Hilbert Transform feature extraction, a Clifford Steerable Graph Sample and Aggregate CNN, and Human Memory Optimization. The authors report high accuracy and other performance metrics on simulated and benchmark data, but the results are research claims and not validated in a live healthcare environment.

Source: Scientific Reports

Defenders should quickly assess device and service exposure, prioritize mitigation according to vendor and government guidance, and validate that recovery actions are applied where compromise is suspected.

Share this