Daily OT Security News: September 22, 2026

Viakoo Daily OT Security News — September 22, 2026. Below are concise summaries of verified developments affecting operational technology and critical-infrastructure cybersecurity from today’s reporting.

NIST SP 800-82r4 draft expands OT security guidance with zero trust, CSF 2.0, consequence-driven risk management

NIST issued the initial public draft of SP 800-82r4, a revised Guide to Operational Technology (OT) Security, addressing OT systems’ distinct performance, reliability, and safety requirements. The draft restructures guidance around Cybersecurity Framework 2.0 and expands advice on risk management, asset management, monitoring and detection, system-management security, and zero-trust principles across sectors including water, transportation, and IIoT. NIST is accepting public comments through November 30, 2026.

Source: Industrial Cyber

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-7273, a stack-based buffer overflow affecting Zyxel GS1900 Series Switches, to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation. The KEV record and Zyxel’s advisory state a LAN-based, unauthenticated attacker could potentially execute OS commands via a crafted HTTP request to the affected CGI program, and Zyxel has released patches for the affected models. The alert is dated September 21, 2026.

Source: Cybersecurity and Infrastructure Security Agency (CISA)

New York State Senate to Hold Hearing on Water Infrastructure Cybersecurity and Preparedness

The New York State Senate announced a public hearing for October 1, 2026, on water security and preparedness focused on cybersecurity threats to municipal water and wastewater infrastructure. The hearing is jointly convened by the Senate committees on Local Government, Cities 1, and Cities 2, chaired by Sens. Monica R. Martinez, Erik Bottcher, and Chris Ryan, and is scheduled for noon at 250 Broadway in New York City; oral testimony is by invitation only. The release says the inquiry follows digital attacks on water systems nationwide that disrupted operational technology at several municipal facilities.

Source: New York State Senate

Health Infrastructure Security Act reintroduced to strengthen healthcare cybersecurity standards, resilience and oversight

Sens. Mark R. Warner and Ron Wyden reintroduced the Health Infrastructure Security and Accountability Act, a proposal to create and enforce minimum cybersecurity standards across the U.S. health-care system with heightened requirements for systemically important or national-security-critical entities. The bill would require covered entities to perform security risk analyses, maintain incident-and-recovery plans, test recovery of essential functions, and undergo independent audits while proposing $1.3 billion in hospital cybersecurity funding and expanded HHS oversight and enforcement, including fines up to $5,000 per day for noncompliance.

Source: Industrial Cyber

CISA’s Cyber Storm X tests cybersecurity preparedness across transportation, water and wastewater sectors

CISA hosted Cyber Storm X, a four-day national cybersecurity exercise involving 2,000 participants and more than 200 organizations to test incident preparedness across critical infrastructure. The scenario involved a nation-state adversary targeting transportation systems—including rail and ports—and water and wastewater systems, allowing participants to exercise response planning, coordination, and information sharing; CISA said it will work with participants on lessons learned for a public after-action report.

Source: Industrial Cyber

Note: Each summary links to the publisher’s canonical page for the full report.

Share this