Focused update for defenders of IoT, OT, CPS, ICS, and other critical‑infrastructure environments.
CISA assessment programs for critical infrastructure are being rolled back
Reported: Security Magazine says CISA will roll back six free assessment offerings — Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments, and Cyber Infrastructure Surveys — a change attributed in the report to budget cuts and declining workforce capacity, with commentators noting the timing precedes expected finalization of CIRCIA reporting requirements. Practical relevance: organizations that have relied on those free CISA assessment services may lose access to them and should account for reduced federal assessment capacity when planning resilience and third‑party support resources.
N-able releases emergency hotfix for critical N-central remote-code-execution flaw
Reported: Cybersecurity Dive reports N‑able issued a hotfix for CVE-2026-86218, a pre‑authentication vulnerability in on‑premises N‑central that can enable remote code execution (reported CVSS score 10); the vendor characterized this as its fourth consecutive hotfix after recent disclosures, and the report recounts earlier observed exploitation chains against N‑central that included creation of an unauthorized user and installation of Cloudflared. Practical relevance: on‑premises N‑central deployments match the threat surface described and the high severity and prior chaining activity indicate organizations operating N‑central should validate patch status and investigate potential indicators of compromise where exposure may have occurred.
Microsoft’s record September patch release includes two exploited Windows zero-days
Reported: Krebs on Security reports Microsoft released fixes for at least 974 vulnerabilities (including 113 rated critical) and identifies CVE-2026-81963 and CVE-2026-85880 as actively exploited Windows privilege‑escalation zero‑days; the article also highlights CVE-2026-69730 (a Windows DNS issue described as likely exploitable) and CVE-2026-69829 (a Windows Shell remote‑code‑execution flaw with a CVSS score of 9.8). Practical relevance: the scale and presence of actively exploited zero‑days and other high‑severity flaws mean organizations should prioritize assessment and deployment of relevant Microsoft patches according to their exposure and risk posture.
New survey signals Cyber Resilience Act readiness pressure for connected-device makers
Reported: FINCHANNEL, reporting on the ONEKEY IoT & OT Cybersecurity Report 2026, summarizes that more than half of surveyed companies have formed dedicated teams for Cyber Resilience Act (CRA) preparation, over 60% rely on external assistance, 61% have budgeted or plan to budget for the transition, only 18% believe they do not need outside support, and more than 60% expect connected‑device, machine, and system development cycles to lengthen. Practical relevance: connected‑device manufacturers and their supply chains face documented resource and timeline pressures tied to CRA preparedness and may need to plan for longer development cycles and increased reliance on external expertise.