Daily OT Security News: September 14, 2026

This is the Daily OT Security News briefing for September 14, 2026.

OT-ISAC, NCSA, TXOne conduct Predictive Resilience exercise, focus on evidence-driven OT cybersecurity decisions

OT-ISAC, Thailand’s National Cyber Security Agency (NCSA), and TXOne Networks conducted a Predictive Resilience Exercise in Bangkok on August 18, 2026 that had participants work through an evolving operational scenario by identifying and validating signals, challenging assumptions, involving relevant stakeholders, and making decisions that account for cybersecurity and safe operations rather than seeking a single attacker or malware identification. The exercise highlighted cross-functional IT/OT collaboration and practical resilience improvements such as better visibility of vendor access and OT changes, stronger monitoring, shared-account controls, configuration comparison, and clearer escalation paths.

Source: Industrial Cyber

Global ransomware attacks hit record 997 in August 2026 as utility, healthcare and business attacks surge

Industrial Cyber reports that Comparitech logged 997 known or suspected ransomware attacks worldwide in August 2026, 23% above July’s 809 and above the previous monthly record of 988 in February 2025, with business attacks rising to 861, healthcare to 69, and utility-company attacks doubling from five to 10. The report says Qilin and The Gentlemen together accounted for more than 26% of the total; Comparitech’s methodology distinguishes publicly confirmed incidents from unconfirmed ransomware-group claims, so the headline total should not be read as 997 independently verified attacks.

Source: Industrial Cyber

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

ConnectWise released urgent patches for CVE-2026-84869, a critical ScreenConnect client vulnerability that can permit unauthorized file transfer and execution through an active remote session in certain circumstances. SecurityWeek reports Huntress observed exploitation beginning August 20, including modified ScreenConnect instances used to deliver VBScript payloads to connected clients; ConnectWise fixed the issue in version 26.6.5 and recommended disabling the TransferFiles permission until patching.

Source: SecurityWeek

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national, was sentenced in U.S. federal court to four years in prison after pleading guilty to conspiracy to commit wire fraud connected to the Conti ransomware operation. The Justice Department said he admitted helping code a malware loader, possessing data stolen from eight U.S. and four overseas victims, and remaining involved in ransomware activity after Conti’s 2022 end; Conti attacks affected more than 1,000 victims worldwide and generated estimated payouts exceeding $150 million as of January 2022.

Source: Security Affairs

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

SecurityWeek reports that multiple threat actors exploited three JFrog Artifactory vulnerabilities—CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329—to obtain or escalate administrative access on self-hosted instances and deploy persistence, malicious plugins, shell commands, and follow-on payloads. Wiz observed the two-vulnerability chain between August 15 and September 8, while CVE-2026-82329 was exploited separately in early September for activities including configuration and cluster-key exfiltration, token minting, and persistent access.

Source: SecurityWeek

Operational teams should evaluate relevance to their environments and follow vendor and government advisories.

Share this