Today’s OT/IoT/industrial-security developments include a municipal utility cyberattack, vendor announcements on OT vulnerability prioritization and device certifications, a DOE request for information on bulk‑power supply-chain risks, and multiple ICS vendor security advisories.
Cyberattack encrypts systems at Bavarian municipal utility
Stadtwerke Landsberg reported a criminal cyberattack on September 1 that encrypted its central IT systems and disrupted office operations, limiting staff availability by phone and email. The utility said electricity, water, wastewater treatment, district heating, fiber, charging infrastructure, pool and parking operations were unaffected while a forensic investigation assesses whether customer data was accessed or exfiltrated; the utility activated a crisis team, disconnected internet connections, engaged specialists and notified authorities.
Source: The Record (Recorded Future News)
Rilian and Bastazo Partner to Bring AI-Driven Vulnerability Prioritization to Critical Infrastructure Worldwide
Bastazo announced that its OT/ICS vulnerability prioritization and remediation technology will be integrated as an agent in Rilian’s Caspian multi‑agent security platform, with the companies stating the capability is available immediately and initially targeted at sovereign and national security operations centers. These operational and availability claims are vendor statements and should be treated as such pending independent validation.
Source: PR Newswire (source: Bastazo)
Securing the United States Bulk-Power System
The U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response published a request for information to inform implementation of Executive Order 14421 addressing foreign‑supplied bulk‑power‑system equipment, seeking input on transaction scope, supply‑chain risk, software and firmware, digital and maintenance services, remote access, and mitigation approaches. The RFI is not a rule or directive and requests comments by October 9, 2026.
ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Schneider Electric, Siemens and Aveva issued September 2026 ICS security advisories, with Schneider’s most severe newly reported issue CVE-2026-3869 described as an authentication‑algorithm flaw affecting certain Modicon M580 and M580 Safety controllers and rated Critical (CVSS v4.0 9.2). Schneider’s advisory and other vendor guidance call for firmware and application‑level updates under appropriate OT change control to address affected products.
Source: SecurityWeek
TUTK Helps Indian Security Customers Achieve STQC Cybersecurity Certification
ThroughTek (TUTK) said security devices made by its Indian customers that use its P2P and cloud technology passed STQC cybersecurity assessments, and the release cites controls such as device authentication and certificate binding, DTLS/SRTP encryption and encrypted relay services. This is a vendor release; STQC’s public IoT System Certification Scheme confirms CCTV cameras are within the covered categories but does not identify the specific customers, devices, or certificates referenced.
Source: PR Newswire APAC (source: ThroughTek; TUTK)
End of briefing; please contact Viakoo incident or sales teams for follow‑up on any item above.