Daily OT Security News: September 4, 2026

Daily OT Security News: concise summaries of notable operational-technology security reporting from the previous 24-hour window.

CISA publishes eight new ICS advisories and two updates

JPCERT/CC reports that CISA issued eight new ICS advisories and updated two others on September 3; the new advisories cover OPC Foundation OPC UA LDS, IXON VPN Client, three Rockwell Automation products, Inductive Automation Ignition, and Pyramid Solutions NetStaX EtherNet/IP Stack, while the updates address Schneider Electric products and other affected devices.

JPCERT/CC summary of CISA ICS advisory releases

Tycon TPDIN‑Monitor‑WEB2 update details two CVEs and urgent remediation guidance

Security Arsenal reports on CISA Update A for Tycon TPDIN‑Monitor‑WEB2, describing CVE‑2026‑61884 (missing authentication for critical functions) and CVE‑2026‑55985 (cleartext storage of sensitive information); the article attributes a combined CVSS v3 score of 9.8 and reports recommended remediation steps including upgrading to firmware 2.4.5 or later and reducing internet exposure.

Security Arsenal coverage of Tycon TPDIN‑Monitor‑WEB2 and CISA Update A

Vendor-specific advisories cite buffer overflow, default-permission and injection issues

Chemical Facility Security News corroborates the new advisories and notes product-specific findings including a stack‑based buffer overflow in Pyramid NetStaX EtherNet/IP Stack, incorrect default permissions in Inductive Automation Ignition, a missing‑authentication condition in a Rockwell product (ControlFLASH referenced), a CRLF injection issue in IXON VPN, and unnecessary privileges in OPC UA LDS.

Chemical Facility Security News review of the eight advisories and two updates

Practitioner view: OT vulnerability management requires operational safety and governance

An interview in Silicon Republic with an OT practice lead emphasizes that effective OT vulnerability management goes beyond patching, calling out asset visibility, segmentation, legacy systems, third‑party and remote access, governance, and incident‑response and recovery planning—while balancing cybersecurity actions with safety and continuity requirements.

Silicon Republic interview on OT vulnerability management

Smart‑city program outlines inventory, procurement and maritime CPS risks

Security Info Watch describes New York City Cyber Command’s IoT and smart‑building program, noting challenges such as unknown device inventories, unvetted procurement and inconsistent contracts, monitoring and upgrade requirements, and limited budgets; the coverage also highlights risks to connected maritime endpoints including AIS/GPS spoofing, sensor‑data tampering, telemetry interception, and compromise of over‑the‑air updates.

Security Info Watch on New York’s IoT cyber‑defense program

Share this