Daily OT Security News: September 28, 2026

Daily OT Security News: September 28, 2026 — concise summaries of five OT/IoT security developments.

CISA Adds Actively Exploited Citrix NetScaler Zero-Days to KEV

CISA added CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, to the Known Exploited Vulnerabilities catalog after reports and partner intelligence confirmed active global exploitation. One flaw is an unauthenticated remote-code-execution issue affecting NetScaler ADC and Gateway in default configurations, and the other is a DTLS-enabled VPN virtual server memory-buffer-overflow that can enable RCE or denial of service; Citrix released fixed versions and CISA urged organizations to review advisories, assess for compromise, and prioritize mitigation, noting updates can require downtime and federal civilian agencies must address the flaws by September 30, 2026.

Source: Security Affairs

Industrial Sector Accounts for 31% of August Ransomware Attacks

NCC Group’s August 2026 cyber threat intelligence report recorded 1,073 global ransomware attacks, up 12% from July’s 960, with industrials accounting for 329 attacks (31% of the total) and becoming the most targeted sector. Qilin accounted for 15% of attacks with 164 confirmed incidents, and the report describes the emerging Aurora operation targeting manufacturing and other sectors using VPN exploitation and credential harvesting before data theft and encryption.

Source: Industrial Cyber

Satellite Connectivity Expands the IoT and Utilities Cyber Attack Surface

A report citing a World Economic Forum post says more than 18,000 active satellites and expanding direct-to-device services are increasing dependencies across satellite, ground-gateway, network-service, and endpoint layers. The article notes satellite-enabled IoT is spreading across logistics, agriculture, and utilities, and highlights risks including jamming, eavesdropping, unauthorized telemetry access, remote manipulation, and compromised software updates in increasingly software-defined satellite systems that could disrupt operations, safety, or infrastructure.

Source: Industrial Cyber

Honeywell Research Finds 87% of Maritime Respondents Report a Significant OT Incident

Honeywell’s 2026 Operational Technology Cybersecurity Benchmark Report found that 87% of maritime respondents experienced a significant OT cybersecurity incident in the preceding 12 months, based on a survey of more than 600 cybersecurity, risk, compliance, and operations leaders across critical-infrastructure industries and regions. Only 21% reported a complete OT asset inventory, 33% had fully integrated OT into a centralized SOC, and 20% continuously monitored connected IoT equipment; significant incidents averaged 16.2 hours of downtime with losses up to $500,000 per hour in the most costly cases.

Source: Splash247

Bipartisan Bill Proposes Voluntary Telecom Cybersecurity Framework and Certification

U.S. Senators Mark Warner and Ted Cruz introduced the Telecommunications Cybersecurity and Resilience Act following the Salt Typhoon telecommunications compromises to establish an NTIA-led public-private working group to create voluntary, risk-based sector practices and an independent third-party certification process. The proposal would require the practices to be reviewed at least every two years and after significant incidents or threat changes, and could address security updates, decommissioning devices without updates, hardware/software/firmware configuration management, and MFA or access controls.

Source: Industrial Cyber

End of briefing.

Share this