Today’s OT-security briefing collects reported developments that affect operational technology, network infrastructure, supply chains, and incident response posture across multiple industrial and critical‑infrastructure sectors. The summaries below focus on factual takeaways relevant to operators, security teams, and resilience planners without implying that every item represents an ongoing incident in every environment.
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
CISA added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Reporting indicates that the Artifactory flaws were chained with another vulnerability to obtain administrator control, deploy persistence mechanisms and install Rust‑based backdoors; ScreenConnect exploitation reportedly enabled unauthorized file transfer and execution via active sessions using a malicious VBScript payload; and CERT Polska documented a RouterOS chain that allowed unauthenticated device takeover. CISA listed federal remediation deadlines of September 13 for RouterOS, September 14 for ScreenConnect, and September 25 for Artifactory, highlighting prioritized timelines for federal agencies and their contractors.
Source: The Hacker News
Dutch NCSC: Critical Check Point VPN Flaws Exploitation Is Imminent
The Dutch National Cyber Security Centre warned of near‑term exploitation attempts against two critical Check Point VPN vulnerabilities, CVE‑2026‑85102 and CVE‑2026‑85103, which were assigned CVSS 9.8 scores in reporting. The flaws can enable unauthenticated remote code execution on Security Gateways, and a certificate‑decoding issue can affect Security Management Servers; Check Point released fixes on September 9 and the NCSC urged immediate patching while also recommending restricting Site‑to‑Site VPN rules to trusted IP addresses to reduce exposure. Although public proof‑of‑concept code had not been reported in the coverage, the agency’s advisory framed rapid mitigation and access controls as priority actions for affected deployments.
Source: BleepingComputer
Watching What Cannot Be Stopped: Maritime’s OT Blind Spot
Cybersecurity Insiders examines a persistent visibility gap in maritime OT where propulsion, steering, ballast, power, cargo and navigation systems are increasingly networked while many vessels run aging, vendor‑specific equipment and operate with intermittent connectivity. The article argues that intrusive monitoring can be unsafe for safety‑critical control systems and recommends passive, non‑intrusive monitoring combined with local data collection and shore‑based maritime SOC analysis to enable continuous anomaly detection without disrupting operations. It also highlights growing exposure from remote maintenance, satellite links, autonomous shipping, electrification and automated ports and notes IMO and IACS expectations for cyber resilience in the sector.
Source: Cybersecurity Insiders
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
U.S. reporting, citing the Department of Justice, states that Ukrainian national Oleksii Oleksiyovych Lytvynenko, 44, was sentenced in U.S. federal court to four years in prison after pleading guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation. Authorities say he acted as both intruder and developer, helped code a malware loader, personally harmed at least 12 companies and possessed data from eight U.S. and four overseas victims; Conti‑attributed activity affected more than 1,000 victims across 47 U.S. states, 31 countries, Washington, D.C., and Puerto Rico, with estimated payouts exceeding $150 million. The report underscores individual criminal accountability tied to a large transnational ransomware campaign and the broad operational and financial impacts documented in the case.
Source: Security Affairs
Daily OT Security News: September 12, 2026
Security Boulevard’s September 12 daily briefing summarizes five OT and critical‑infrastructure developments, including maritime OT monitoring limitations, expanded U.S. critical‑infrastructure support programs, EU Cyber Resilience Act vulnerability reporting expectations, a Department of Energy request for input on bulk‑power‑system supply‑chain and cybersecurity risks, and Boston Scientific’s post‑cyberattack recovery. The DOE item discussed in the briefing focused on supply‑chain and cybersecurity risk from foreign‑produced equipment, components, software, firmware, digital and maintenance services, and remote access, and the notice was described as informational and planning‑oriented rather than a proposed rule or directive. The roundup positioned these items as operational context for OT teams managing supply‑chain risk, firmware and remote‑access controls, and recovery planning in healthcare manufacturing and other sectors.
Source: Security Boulevard
Operational takeaway: prioritize rapid inventory and prioritized remediation for network‑ and firmware‑exposed infrastructure, adopt non‑intrusive monitoring approaches where safety constraints limit active interrogation, and align patching plus access‑rule hardening with documented federal and sector advisory timelines to reduce exposure windows.