|
IT/OT Security Weekly · July 26, 2026 · Weekly Edition
IT/OT Security Weekly
A federal advisory on Iran-linked hackers hunting PLCs, ICS Patch Tuesday across the big three vendors, and fresh code-execution flaws in Rockwell’s Arena · for OT/ICS security teams and plant engineers
|
This week at a glance
The week was defined by a single, loud federal signal: US agencies warned that Iran-linked hackers are actively targeting the industrial control systems that run critical infrastructure, naming Siemens, Schneider Electric, and Rockwell Automation devices and urging operators to pull Rockwell PLCs off direct internet exposure immediately. Three outlets carried the story from different angles — SecurityWeek on the vendor-device targeting, GBHackers on CISA’s remove-from-the-internet guidance, and The Record on the broadened multi-agency alert — and together they point to the same defensive priority: internet-reachable controllers are being scanned and hit, and network exposure is the first thing to fix.
The vulnerability cycle stayed busy underneath the headline. ICS Patch Tuesday brought coordinated fixes from Siemens, Schneider, and Rockwell, and Rockwell followed up mid-week by patching code-execution flaws in its Arena Simulation software. On the longer arc, a thoughtful piece on legacy systems and the real-world reality of OT security frames why these environments are so hard to defend, while two recent foundational stories — controller flaws exposing highway signs and billboards and the first in-the-wild exploitation of a PTC Windchill vulnerability — are reminders that OT attack surface reaches well beyond the plant floor. New foundational research widens the lens further, into the vehicle: a scan of the Linux, Android, QNX, and VxWorks stacks inside modern cars tallies huge raw vulnerability counts but argues the exploitable reality is far smaller — the same flaw knocked a service offline on two platforms and failed on a third, depending entirely on which defenses were switched on. It was a lighter week by volume, but the through-line is consistent: reduce exposure, patch the controllers, and treat legacy OT — on the plant floor and in the dashboard — as an active target rather than background risk.
|
Topic map — actors, vendors, controllers, and how they intersect
Named entities extracted from this week’s ten IT/OT articles — the Iran-linked threat actor, the ICS vendors and their products, the regulators issuing guidance, the CVEs from the patch cycle, and the OT-security themes connecting them.
This week clusters around three centres of gravity: the federal advisory (an Iran-linked APT drawing CISA and its FBI/NSA partners into a broadened alert, with Siemens, Schneider, and Rockwell PLCs in the crosshairs and direct internet exposure as the headline risk); the vulnerability and patch cycle (ICS Patch Tuesday across the big three vendors, plus code-execution flaws in Rockwell’s Arena Simulation); and the OT-security fundamentals that tie it together (legacy systems, critical-infrastructure impact, and two adjacent exposures — highway-sign controllers and the first in-the-wild PTC Windchill exploitation).
View interactive topic map →
|
Article index
Weekly news
Iran-linked OT threat & the federal advisory
US agencies warn that Iran-linked hackers are targeting Siemens, Schneider, and Rockwell ICS devices; CISA urges operators to remove Rockwell PLCs from direct internet exposure; and federal partners broaden the alert on Iran-linked OT attacks. Three outlets, one story.
ICS vulnerabilities & the patch cycle
The monthly ICS Patch Tuesday lands with coordinated fixes from Siemens, Schneider, and Rockwell, and Rockwell separately patches code-execution flaws in its Arena Simulation software.
Industry & community
SecurityWeek launches an awards program to recognize excellence in industrial cybersecurity.
Foundational reading
OT security fundamentals & emerging exposures
A grounded look at why legacy systems make OT so hard to secure, plus two recent exposures that show how far the OT attack surface now reaches — highway-sign and billboard controllers, and the first in-the-wild exploitation of a PTC Windchill flaw.
Connected vehicles & embedded OS risk
Fresh research scans the operating systems inside modern cars — Automotive Grade Linux, Android, QNX, VxWorks — and argues that raw vulnerability counts badly overstate real-world exploitability. The same RTOS families run factory floors and aircraft, making this squarely an OT-adjacent embedded-systems story.
|
Detailed write-ups
1. Federal agencies warn of Iran-linked hackers hunting ICS devices — and tell operators to pull Rockwell PLCs off the internet now
SecurityWeek · Jul 23, 2026 | GBHackers · Jul 23, 2026 | The Record · Jul 22, 2026
The week’s dominant story is a coordinated federal warning that Iran-linked threat actors are actively targeting the industrial control systems behind US critical infrastructure. SecurityWeek reports the campaign is going after devices from the three vendors that anchor most plant floors — Siemens, Schneider Electric, and Rockwell Automation — while The Record notes that multiple federal agencies have broadened an earlier alert, with CISA joined by its FBI and NSA partners, reflecting both wider targeting and heightened concern in the current geopolitical climate. The most concrete, do-it-today instruction comes via GBHackers: CISA is urging organizations to remove Rockwell PLCs from direct internet exposure, because internet-reachable controllers are trivially discoverable and are exactly what opportunistic, ideologically motivated actors scan for and hit. The pattern echoes the CyberAv3ngers-style intrusions that defaced and disrupted exposed OT devices in prior campaigns — low sophistication, high impact, and enabled almost entirely by exposure rather than any exotic exploit. The action items are unambiguous: inventory every internet-facing controller and HMI, get PLCs behind a firewall or VPN with no direct exposure, enforce strong non-default credentials, segment OT from IT, and watch for scanning and unauthorized configuration changes against the named vendors’ devices.
Read the article
Sources: SecurityWeek — Iranian hackers targeting Siemens/Schneider/Rockwell ICS · GBHackers — CISA urges removing Rockwell PLCs from the internet · The Record — federal agencies broaden Iran-linked OT alert
4. ICS Patch Tuesday: Siemens, Schneider, and Rockwell ship coordinated fixes
SecurityWeek · Jul 20, 2026
The monthly industrial patch cycle landed with advisories from Siemens, Schneider Electric, and Rockwell Automation addressing vulnerabilities across their product lines. The timing matters this month: it arrives alongside the Iran-linked targeting warning covering the same three vendors, which makes the usual OT patch-lag calculus sharper than normal. OT environments notoriously trail on patching — change windows are scarce, uptime is sacrosanct, and many controllers can’t be taken offline without a scheduled outage — but this cycle is one where the exposure-reduction and patch conversations converge. Where a fix can’t be applied immediately, lean on compensating controls: network segmentation, removal of internet exposure, tightened access to engineering workstations, and monitoring for exploitation of the specific advisories. Review each vendor’s advisory set, rank by exploitability and exposure rather than CVSS alone, and prioritize anything reachable from IT or the internet.
Read the article
Sources: SecurityWeek — ICS Patch Tuesday
5. Rockwell patches code-execution flaws in Arena Simulation
SecurityWeek · Jul 25, 2026
Rockwell Automation followed the patch cycle with a separate fix for code-execution vulnerabilities in its Arena Simulation software, the discrete-event modeling tool engineers use to design and validate production and process flows. Arena is an engineering-workstation application rather than a controller, but that’s precisely why it matters: flaws that allow code execution — typically triggered when a user opens a maliciously crafted simulation file — put the engineering seat at risk, and the engineering workstation is one of the highest-value pivot points in an OT network because it holds project files, controller logic, and trusted access to the devices themselves. Compromise there can lead straight to the PLCs. Apply Rockwell’s update to all Arena installs, treat simulation and project files from untrusted sources with the same caution as any other untrusted document, and keep engineering workstations tightly controlled and segmented from both general IT and the wider internet.
Read the article
Sources: SecurityWeek — Rockwell Arena code-execution flaws
7. Legacy systems, real-world impacts: the reality of OT security
SecurityWeek · Jul 21, 2026 · Foundational
This foundational piece is the connective tissue under the week’s news: it explains why OT environments are so difficult to secure and why the consequences are physical, not just informational. The core problem is legacy systems — controllers and software built for multi-decade service lives, deployed long before internet exposure or modern threat models were a consideration, and running processes that cannot simply be paused for a patch or a rebuild. When those systems fail or are manipulated, the impact shows up in the real world: stopped production lines, unsafe process states, and disruption to the critical services communities depend on. The article’s value is in reframing the risk conversation for plant and infrastructure engineers: you can’t always patch your way out, so the durable answers are architectural — segmentation and zoning, strict control of remote access, monitoring purpose-built for OT protocols, and lifecycle planning that treats security as a property of the whole system rather than a bolt-on. It’s the strategic backdrop that makes this week’s exposure-reduction guidance land: the reason “take the PLC off the internet” is such urgent advice is that the underlying device often can’t defend itself.
Read the article
Sources: SecurityWeek — Legacy Systems, Real-World Impacts
10. The automotive software vulnerabilities hiding in your dashboard
Help Net Security · Jul 24, 2026 · Foundational
A modern car is now a rolling collection of general-purpose computers — the dash running Android or Automotive Grade Linux, safety systems running QNX or VxWorks, the same real-time operating systems that run factory floors and fly aircraft — and it inherits every publicly documented bug those platforms have accumulated. Researchers at Télécom SudParis built a scanner (VERA) to tally the baggage, and the raw counts are eye-watering: Automotive Grade Linux logged 1,203 known flaws in the tested build, while a lean safety-focused stack came in with eight. The paper’s real contribution, though, is puncturing the scary number. A logged vulnerability is a maybe — it matters only if the vulnerable code is switched on, reachable, and the setup lines up. To prove the point the team ran one SOME/IP service-discovery attack against three platforms: it worked on Red Hat’s AutoSD and on Tesla’s software, and failed on Android Automotive purely because that platform shuffled its port numbers. Same CVE, same severity score, three different outcomes — determined by which defenses were actually enabled.
For OT and embedded-security teams the lesson generalizes well beyond cars: certification helps but doesn’t immunize (certified QNX Neutrino still carried 56 known flaws), commodity scanners drown OT-style images in false positives, and a defensible program prioritizes by real exploitability and exposure rather than CVE tallies. It’s the same message as this week’s plant-floor stories, told through the dashboard: the length of the rap sheet tells you how much there is to watch; the job is sorting out which of those old bugs your particular system will ever let anyone near.
Read the article
Sources: Help Net Security — Automotive software vulnerabilities
|
On our watch list
- Iran-linked OT targeting escalation. With federal agencies broadening the alert and naming Siemens, Schneider, and Rockwell devices, watch for follow-on advisories, indicators of compromise, and any confirmed disruptions at named sectors — and treat exposed-controller scanning as an active-threat signal, not background noise.
- Internet-exposed controller cleanup. CISA’s remove-from-the-internet guidance for Rockwell PLCs is likely a template for further vendors; expect exposure to be the recurring theme, and use this week as the prompt to close out any internet-reachable PLCs and HMIs across your estate.
- Engineering-workstation attack surface. The Arena Simulation code-execution flaws are a reminder that OT risk isn’t only in the controllers — watch for more file-parsing and workstation-side vulnerabilities in ICS engineering tools, and keep those seats patched and segmented.
- OT attack surface beyond the plant. Highway-sign controllers and the first in-the-wild PTC Windchill exploitation show the OT perimeter now includes roadside infrastructure and product-lifecycle systems; expect the “what counts as OT” boundary to keep widening.
- Connected-vehicle and embedded-OS risk. The automotive research is a reminder that the same RTOS families (QNX, VxWorks) and Linux/Android stacks span cars, plants, and aircraft — watch for exploitability-aware scanning (over raw CVE counts) to become the norm for triaging embedded and OT fleets.
|
|
IT/OT Security Weekly · a weekly intelligence bulletin from Security Radar LLC
Curated by Paul Davis (paul.davis@security-radar.com)
Weekly news items are from the previous seven days. Foundational reading is refreshed each week.
*|LIST:ADDRESS|*
View this email in your browser · Unsubscribe
© 2026 Security Radar LLC. All rights reserved.
Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.
|
|