Daily OT Security News: September 27, 2026

This roundup highlights active exploitation of unpatched network and application vulnerabilities, widespread credential exposure that could enable access to operational systems, and governments deploying AI-assisted defensive tools while some attack-related AI claims remain unconfirmed. Together the reports underline persistent IT threats to critical-infrastructure sectors and the continuing risk of IT-to-OT pivots where segmentation or credentials are weak.

WatchTowr reports two unpatched Citrix NetScaler RCE zero-days under exploitation

Security firm watchTowr said it found two unpatched remote-code-execution zero-days affecting Citrix NetScaler ADC and Gateway appliances that were actively exploited, based on forensic investigations. Citrix had not confirmed the flaws or released fixes as of the report; the issues are said to be distinct from CVE-2026-19490 and no affected versions, victims, indicators, or vendor workarounds were identified in the article.

Source: The Hacker News

Singapore shifts cyber strategy after UNC3886 attacks, deploying AI security tools

The Straits Times reports Singapore’s Cyber Security Agency is shifting toward active threat hunting after the UNC3886 attack on four major telcos and has deployed AI-assisted penetration testing and source-code scanning across about 2,000 government systems. CSA and GovTech are also scanning critical-information-infrastructure operators’ internet-facing systems and are evaluating whether to expand the AI tools to other CII sectors; the article notes the tools are currently deployed on government systems and expansion remains under evaluation.

Source: The Straits Times

ShinyHunters uses a WAF bypass in Oracle PeopleSoft attacks

BleepingComputer reports Google Mandiant and GTIG observed ShinyHunters percent-encoding the P in /PSEMHUB/ to bypass WAF rules protecting unpatched Oracle PeopleSoft CVE-2026-35273, an unauthenticated RCE flaw. Google says the renewed activity deployed web shells on dozens of systems and enabled data theft and potential lateral movement; Mandiant recommended applying Oracle’s update rather than relying on a WAF rule, and the observed exploitation is attributed to Google Mandiant and GTIG while separate attacker claims were not independently verified.

Source: BleepingComputer

SpyCloud finds credential exposure at U.S. water and wastewater organizations

The Cool Down reports SpyCloud’s review of roughly 10,000 U.S. water and wastewater organizations found infostealer-collected credentials from 1,787 organizations, nearly 20% of the sample. SpyCloud said credentials from at least 250 organizations appeared capable of reaching operational networks and remote-access tools used to run pumps and control water movement, and a separate vendor review tied one infected device to passwords for 167 utility companies; the article stresses this is research on exposed credentials, not proof of compromise or OT manipulation.

Source: The Cool Down

Renfe and Adif report a cyber incident tied to external Adif systems

Xataka reported attackers compromised Adif systems and reached interconnected Renfe systems; Renfe confirmed an incident and said names and email addresses may have been accessed. Renfe said it isolated affected environments, found no evidence of access to payment, banking or ID data, and that rail services continued operating; claims about 500 GB being taken and use of AI are attributed to investigation sources and have not been confirmed as of the report.

Source: Xataka

These developments reinforce the need for patching, credential hygiene, network segmentation, and careful validation of attribution and technical claims while investigations continue.

Share this