Recent developments in operational technology and industrial cybersecurity reveal both ongoing vulnerabilities and steps toward improved security certifications. Industry leaders and researchers continue to identify risks and recommend tools to aid sectors such as energy, manufacturing, and healthcare. Here is a summary of the latest verified reports.
OT Security Readiness Remains Uneven Across Critical Infrastructure, Survey Finds
A 2026 Honeywell survey involving 603 cybersecurity and operations leaders highlighted uneven OT security maturity across sectors in the Americas, EMEA, and APAC. For example, only 21% had complete OT asset inventories and 33% centralized OT in a security operations center. Fifty-four percent experienced operational downtime averaging 16.2 hours due to OT cyber incidents.
Source: The Economic Times Infrastructure
Nozomi Labs Finds 19 Flaws in Pepperl+Fuchs IO-Link Master
Nozomi Networks Labs disclosed 19 vulnerabilities in the Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 IO-Link Master device firmware 1.7.3, including authentication bypass and OS command injection. Several issues enable potential privilege escalation, with CVE-2026-27546 allowing an unauthenticated admin session. CERT@VDE recommends upgrading to firmware version 1.7.8 for mitigation.
Source: Nozomi Networks Labs
CISA and FBI Warn of Third-Party ICS Integrator Risk
A fact sheet from CISA and FBI warns critical infrastructure operators about cyber risks posed by third-party ICS integrators. A U.S. industrial automation company was compromised by foreign actors who accessed sensitive SCADA data and device details in early 2025. Recommended mitigations include least privilege access, contract supply-chain requirements, and offline backups.
Source: RTO Insider
TDengine Flaw Can Disrupt Industrial Telemetry and Monitoring
Industrial Cyber reported that CVE-2026-42542 is a CVSS 7.5 integer-underflow vulnerability in TDengine versions 3.4.0.0 through 3.4.1.5. An attacker can remotely crash the taosd server without credentials using a specially crafted RPC packet. Upgrading to TDengine 3.4.1.6 and restricting access to TCP port 6030 is advised.
Source: Industrial Cyber
Envision Energy Receives IEC 62443 Certification for Wind-Farm Control System
Envision Energy announced that TUV SUD certified its wind-farm control system to IEC 62443-3-3 Security Level 2. The certification scope includes SCADA, power-plant controllers, PLCs, and industrial network devices. This system-level certification complements other IEC 62443 component and lifecycle certifications.
Source: PR Newswire (source: Envision Energy)
These updates highlight ongoing challenges and efforts to enhance security for OT environments across multiple industry verticals. Continued vigilance and adoption of recommended solutions remain important for risk management.