Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

IT/OT Security Weekly — July 26, 2026

Posted on July 26, 2026 by admini
IT/OT Security Weekly · July 26, 2026 · Weekly Edition

IT/OT Security Weekly

A federal advisory on Iran-linked hackers hunting PLCs, ICS Patch Tuesday across the big three vendors, and fresh code-execution flaws in Rockwell’s Arena · for OT/ICS security teams and plant engineers

This week at a glance

The week was defined by a single, loud federal signal: US agencies warned that Iran-linked hackers are actively targeting the industrial control systems that run critical infrastructure, naming Siemens, Schneider Electric, and Rockwell Automation devices and urging operators to pull Rockwell PLCs off direct internet exposure immediately. Three outlets carried the story from different angles — SecurityWeek on the vendor-device targeting, GBHackers on CISA’s remove-from-the-internet guidance, and The Record on the broadened multi-agency alert — and together they point to the same defensive priority: internet-reachable controllers are being scanned and hit, and network exposure is the first thing to fix.

The vulnerability cycle stayed busy underneath the headline. ICS Patch Tuesday brought coordinated fixes from Siemens, Schneider, and Rockwell, and Rockwell followed up mid-week by patching code-execution flaws in its Arena Simulation software. On the longer arc, a thoughtful piece on legacy systems and the real-world reality of OT security frames why these environments are so hard to defend, while two recent foundational stories — controller flaws exposing highway signs and billboards and the first in-the-wild exploitation of a PTC Windchill vulnerability — are reminders that OT attack surface reaches well beyond the plant floor. New foundational research widens the lens further, into the vehicle: a scan of the Linux, Android, QNX, and VxWorks stacks inside modern cars tallies huge raw vulnerability counts but argues the exploitable reality is far smaller — the same flaw knocked a service offline on two platforms and failed on a third, depending entirely on which defenses were switched on. It was a lighter week by volume, but the through-line is consistent: reduce exposure, patch the controllers, and treat legacy OT — on the plant floor and in the dashboard — as an active target rather than background risk.

Topic map — actors, vendors, controllers, and how they intersect

Named entities extracted from this week’s ten IT/OT articles — the Iran-linked threat actor, the ICS vendors and their products, the regulators issuing guidance, the CVEs from the patch cycle, and the OT-security themes connecting them.

Topic map for IT/OT security — July 26, 2026

This week clusters around three centres of gravity: the federal advisory (an Iran-linked APT drawing CISA and its FBI/NSA partners into a broadened alert, with Siemens, Schneider, and Rockwell PLCs in the crosshairs and direct internet exposure as the headline risk); the vulnerability and patch cycle (ICS Patch Tuesday across the big three vendors, plus code-execution flaws in Rockwell’s Arena Simulation); and the OT-security fundamentals that tie it together (legacy systems, critical-infrastructure impact, and two adjacent exposures — highway-sign controllers and the first in-the-wild PTC Windchill exploitation).

View interactive topic map →

Article index

Weekly news

Iran-linked OT threat & the federal advisory

US agencies warn that Iran-linked hackers are targeting Siemens, Schneider, and Rockwell ICS devices; CISA urges operators to remove Rockwell PLCs from direct internet exposure; and federal partners broaden the alert on Iran-linked OT attacks. Three outlets, one story.

# Article Source Date
1 US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices SecurityWeek Jul 23
2 CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure GBHackers Jul 23
3 Federal agencies broaden alert on Iran-linked OT attacks The Record Jul 22

ICS vulnerabilities & the patch cycle

The monthly ICS Patch Tuesday lands with coordinated fixes from Siemens, Schneider, and Rockwell, and Rockwell separately patches code-execution flaws in its Arena Simulation software.

# Article Source Date
4 ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell SecurityWeek Jul 20
5 Rockwell Patches Code Execution Flaws in Arena Simulation Software SecurityWeek Jul 25

Industry & community

SecurityWeek launches an awards program to recognize excellence in industrial cybersecurity.

# Article Source Date
6 SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity SecurityWeek Jul 21

Foundational reading

OT security fundamentals & emerging exposures

A grounded look at why legacy systems make OT so hard to secure, plus two recent exposures that show how far the OT attack surface now reaches — highway-sign and billboard controllers, and the first in-the-wild exploitation of a PTC Windchill flaw.

# Article Source Date
7 Legacy Systems, Real-World Impacts: The Reality of OT Security · FOUNDATIONAL SecurityWeek Jul 21
8 New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking · FOUNDATIONAL SecurityWeek Jun 30
9 First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild · FOUNDATIONAL SecurityWeek Jun 26

Connected vehicles & embedded OS risk

Fresh research scans the operating systems inside modern cars — Automotive Grade Linux, Android, QNX, VxWorks — and argues that raw vulnerability counts badly overstate real-world exploitability. The same RTOS families run factory floors and aircraft, making this squarely an OT-adjacent embedded-systems story.

# Article Source Date
10 The Automotive Software Vulnerabilities Hiding in Your Dashboard · FOUNDATIONAL Help Net Security Jul 24

Detailed write-ups

1. Federal agencies warn of Iran-linked hackers hunting ICS devices — and tell operators to pull Rockwell PLCs off the internet now

SecurityWeek · Jul 23, 2026  |  GBHackers · Jul 23, 2026  |  The Record · Jul 22, 2026

The week’s dominant story is a coordinated federal warning that Iran-linked threat actors are actively targeting the industrial control systems behind US critical infrastructure. SecurityWeek reports the campaign is going after devices from the three vendors that anchor most plant floors — Siemens, Schneider Electric, and Rockwell Automation — while The Record notes that multiple federal agencies have broadened an earlier alert, with CISA joined by its FBI and NSA partners, reflecting both wider targeting and heightened concern in the current geopolitical climate. The most concrete, do-it-today instruction comes via GBHackers: CISA is urging organizations to remove Rockwell PLCs from direct internet exposure, because internet-reachable controllers are trivially discoverable and are exactly what opportunistic, ideologically motivated actors scan for and hit. The pattern echoes the CyberAv3ngers-style intrusions that defaced and disrupted exposed OT devices in prior campaigns — low sophistication, high impact, and enabled almost entirely by exposure rather than any exotic exploit. The action items are unambiguous: inventory every internet-facing controller and HMI, get PLCs behind a firewall or VPN with no direct exposure, enforce strong non-default credentials, segment OT from IT, and watch for scanning and unauthorized configuration changes against the named vendors’ devices.

Read the article

Sources: SecurityWeek — Iranian hackers targeting Siemens/Schneider/Rockwell ICS · GBHackers — CISA urges removing Rockwell PLCs from the internet · The Record — federal agencies broaden Iran-linked OT alert

4. ICS Patch Tuesday: Siemens, Schneider, and Rockwell ship coordinated fixes

SecurityWeek · Jul 20, 2026

The monthly industrial patch cycle landed with advisories from Siemens, Schneider Electric, and Rockwell Automation addressing vulnerabilities across their product lines. The timing matters this month: it arrives alongside the Iran-linked targeting warning covering the same three vendors, which makes the usual OT patch-lag calculus sharper than normal. OT environments notoriously trail on patching — change windows are scarce, uptime is sacrosanct, and many controllers can’t be taken offline without a scheduled outage — but this cycle is one where the exposure-reduction and patch conversations converge. Where a fix can’t be applied immediately, lean on compensating controls: network segmentation, removal of internet exposure, tightened access to engineering workstations, and monitoring for exploitation of the specific advisories. Review each vendor’s advisory set, rank by exploitability and exposure rather than CVSS alone, and prioritize anything reachable from IT or the internet.

Read the article

Sources: SecurityWeek — ICS Patch Tuesday

5. Rockwell patches code-execution flaws in Arena Simulation

SecurityWeek · Jul 25, 2026

Rockwell Automation followed the patch cycle with a separate fix for code-execution vulnerabilities in its Arena Simulation software, the discrete-event modeling tool engineers use to design and validate production and process flows. Arena is an engineering-workstation application rather than a controller, but that’s precisely why it matters: flaws that allow code execution — typically triggered when a user opens a maliciously crafted simulation file — put the engineering seat at risk, and the engineering workstation is one of the highest-value pivot points in an OT network because it holds project files, controller logic, and trusted access to the devices themselves. Compromise there can lead straight to the PLCs. Apply Rockwell’s update to all Arena installs, treat simulation and project files from untrusted sources with the same caution as any other untrusted document, and keep engineering workstations tightly controlled and segmented from both general IT and the wider internet.

Read the article

Sources: SecurityWeek — Rockwell Arena code-execution flaws

7. Legacy systems, real-world impacts: the reality of OT security

SecurityWeek · Jul 21, 2026 · Foundational

This foundational piece is the connective tissue under the week’s news: it explains why OT environments are so difficult to secure and why the consequences are physical, not just informational. The core problem is legacy systems — controllers and software built for multi-decade service lives, deployed long before internet exposure or modern threat models were a consideration, and running processes that cannot simply be paused for a patch or a rebuild. When those systems fail or are manipulated, the impact shows up in the real world: stopped production lines, unsafe process states, and disruption to the critical services communities depend on. The article’s value is in reframing the risk conversation for plant and infrastructure engineers: you can’t always patch your way out, so the durable answers are architectural — segmentation and zoning, strict control of remote access, monitoring purpose-built for OT protocols, and lifecycle planning that treats security as a property of the whole system rather than a bolt-on. It’s the strategic backdrop that makes this week’s exposure-reduction guidance land: the reason “take the PLC off the internet” is such urgent advice is that the underlying device often can’t defend itself.

Read the article

Sources: SecurityWeek — Legacy Systems, Real-World Impacts

10. The automotive software vulnerabilities hiding in your dashboard

Help Net Security · Jul 24, 2026 · Foundational

A modern car is now a rolling collection of general-purpose computers — the dash running Android or Automotive Grade Linux, safety systems running QNX or VxWorks, the same real-time operating systems that run factory floors and fly aircraft — and it inherits every publicly documented bug those platforms have accumulated. Researchers at Télécom SudParis built a scanner (VERA) to tally the baggage, and the raw counts are eye-watering: Automotive Grade Linux logged 1,203 known flaws in the tested build, while a lean safety-focused stack came in with eight. The paper’s real contribution, though, is puncturing the scary number. A logged vulnerability is a maybe — it matters only if the vulnerable code is switched on, reachable, and the setup lines up. To prove the point the team ran one SOME/IP service-discovery attack against three platforms: it worked on Red Hat’s AutoSD and on Tesla’s software, and failed on Android Automotive purely because that platform shuffled its port numbers. Same CVE, same severity score, three different outcomes — determined by which defenses were actually enabled.

For OT and embedded-security teams the lesson generalizes well beyond cars: certification helps but doesn’t immunize (certified QNX Neutrino still carried 56 known flaws), commodity scanners drown OT-style images in false positives, and a defensible program prioritizes by real exploitability and exposure rather than CVE tallies. It’s the same message as this week’s plant-floor stories, told through the dashboard: the length of the rap sheet tells you how much there is to watch; the job is sorting out which of those old bugs your particular system will ever let anyone near.

Read the article

Sources: Help Net Security — Automotive software vulnerabilities

On our watch list

  1. Iran-linked OT targeting escalation. With federal agencies broadening the alert and naming Siemens, Schneider, and Rockwell devices, watch for follow-on advisories, indicators of compromise, and any confirmed disruptions at named sectors — and treat exposed-controller scanning as an active-threat signal, not background noise.
  2. Internet-exposed controller cleanup. CISA’s remove-from-the-internet guidance for Rockwell PLCs is likely a template for further vendors; expect exposure to be the recurring theme, and use this week as the prompt to close out any internet-reachable PLCs and HMIs across your estate.
  3. Engineering-workstation attack surface. The Arena Simulation code-execution flaws are a reminder that OT risk isn’t only in the controllers — watch for more file-parsing and workstation-side vulnerabilities in ICS engineering tools, and keep those seats patched and segmented.
  4. OT attack surface beyond the plant. Highway-sign controllers and the first in-the-wild PTC Windchill exploitation show the OT perimeter now includes roadside infrastructure and product-lifecycle systems; expect the “what counts as OT” boundary to keep widening.
  5. Connected-vehicle and embedded-OS risk. The automotive research is a reminder that the same RTOS families (QNX, VxWorks) and Linux/Android stacks span cars, plants, and aircraft — watch for exploitability-aware scanning (over raw CVE counts) to become the norm for triaging embedded and OT fleets.

IT/OT Security Weekly · a weekly intelligence bulletin from Security Radar LLC

Curated by Paul Davis (paul.davis@security-radar.com)

Weekly news items are from the previous seven days. Foundational reading is refreshed each week.

*|LIST:ADDRESS|*

View this email in your browser · Unsubscribe

© 2026 Security Radar LLC. All rights reserved.

Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.

Recent Posts

  • Security Operations Weekly — July 26, 2026
  • Security Operations Weekly — July 26, 2026 — Interactive Topic Map
  • IT/OT Security Weekly — July 26, 2026

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • Competitive
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • IT/OT Security
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme