Daily OT Security News: concise summaries of notable operational-technology security reporting from the previous 24-hour window.
CISA publishes eight new ICS advisories and two updates
JPCERT/CC reports that CISA issued eight new ICS advisories and updated two others on September 3; the new advisories cover OPC Foundation OPC UA LDS, IXON VPN Client, three Rockwell Automation products, Inductive Automation Ignition, and Pyramid Solutions NetStaX EtherNet/IP Stack, while the updates address Schneider Electric products and other affected devices.
JPCERT/CC summary of CISA ICS advisory releases
Tycon TPDIN‑Monitor‑WEB2 update details two CVEs and urgent remediation guidance
Security Arsenal reports on CISA Update A for Tycon TPDIN‑Monitor‑WEB2, describing CVE‑2026‑61884 (missing authentication for critical functions) and CVE‑2026‑55985 (cleartext storage of sensitive information); the article attributes a combined CVSS v3 score of 9.8 and reports recommended remediation steps including upgrading to firmware 2.4.5 or later and reducing internet exposure.
Security Arsenal coverage of Tycon TPDIN‑Monitor‑WEB2 and CISA Update A
Vendor-specific advisories cite buffer overflow, default-permission and injection issues
Chemical Facility Security News corroborates the new advisories and notes product-specific findings including a stack‑based buffer overflow in Pyramid NetStaX EtherNet/IP Stack, incorrect default permissions in Inductive Automation Ignition, a missing‑authentication condition in a Rockwell product (ControlFLASH referenced), a CRLF injection issue in IXON VPN, and unnecessary privileges in OPC UA LDS.
Chemical Facility Security News review of the eight advisories and two updates
Practitioner view: OT vulnerability management requires operational safety and governance
An interview in Silicon Republic with an OT practice lead emphasizes that effective OT vulnerability management goes beyond patching, calling out asset visibility, segmentation, legacy systems, third‑party and remote access, governance, and incident‑response and recovery planning—while balancing cybersecurity actions with safety and continuity requirements.
Silicon Republic interview on OT vulnerability management
Smart‑city program outlines inventory, procurement and maritime CPS risks
Security Info Watch describes New York City Cyber Command’s IoT and smart‑building program, noting challenges such as unknown device inventories, unvetted procurement and inconsistent contracts, monitoring and upgrade requirements, and limited budgets; the coverage also highlights risks to connected maritime endpoints including AIS/GPS spoofing, sensor‑data tampering, telemetry interception, and compromise of over‑the‑air updates.