Daily OT Security News: September 08, 2026

Daily OT Security News — September 08, 2026. Concise operational summaries of the latest OT/ICS cybersecurity developments.

MikroTik patches actively exploited RouterOS attack chain

MikroTik released fixes for six RouterOS vulnerabilities after CERT Poland confirmed two flaws, collectively dubbed MikroTrick, are being chained in attacks that can bypass authentication, overwrite configuration files and take over devices with SSH exposed to public networks. Operators should apply the latest RouterOS release and restrict SSH access to trusted sources.

Source: SecurityWeek

DOE and Sandia advance AI-assisted grid threat detection

DOE CESER and Sandia are advancing the C2E2 work under AI-FORTS, using generative AI and machine learning to automate grid data engineering, detect and localize cyber-physical threats and deliver actionable intelligence. Sandia reports model training now takes hours instead of roughly two months and that testing achieved 95% detection-and-localization accuracy; the team is working to make AI errors visible and measurable.

Source: Industrial Cyber

CISA retires six legacy critical-infrastructure cyber assessments

CISA is ending regional staff support for six legacy assessment offerings — Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys — to reduce duplication and direct organizations to cross-sector Cybersecurity Performance Goals. The change removes adviser-supported reviews used by smaller operators; organizations can still use the open-source CSET tool alongside CPGs for self-assessment and prioritization.

Source: Industrial Cyber

Project Watershed 250 expands OT support for water utilities

Forescout joined Project Watershed 250, a White House, Texas, utility and technology-provider initiative to strengthen water and wastewater cybersecurity. Its planned contributions include continuous monitoring and asset visibility, adversary-focused assessments, vulnerability prioritization, segmentation and AI-enabled defense, and the initiative is designed to trace attack paths from internet exposure into enterprise IT, OT, ICS, SCADA, treatment facilities, pump stations and remote telemetry environments.

Source: Industrial Cyber

Marlink launches managed OT security suite for maritime and industrial operations

Marlink introduced a managed OT security offering for maritime and land-based industrial environments that combines passive asset monitoring, network communication mapping, anomaly detection, automated containment safeguards and 24/7 SOC oversight. The company says the service is intended for vessel navigation, propulsion and cargo operations as well as energy, water treatment and industrial automation, and to help organizations align with standards such as IACS UR E26, NERC CIP, NIS2 and ISA/IEC 62443.

Source: Ocean Science & Technology

Operational takeaway: Prioritize immediate patching and SSH access restrictions for exposed RouterOS devices; evaluate AI-assisted detection carefully and require measurable error visibility; use CSET alongside CPGs for self-assessment as CISA phases out adviser-supported reviews; water utilities should adopt continuous monitoring, segmentation and vulnerability prioritization; consider managed OT security services to augment in-house capabilities and support standards alignment.

Share this