Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

IT/OT Security Weekly — September 27, 2026

Posted on September 27, 2026 by admini

September 27, 2026 · Weekly Edition

IT/OT Security

Nine ICS advisories on September 22, led by a 9.8 in the lwIP embedded stack that only device makers can fix. Three separate water stories: a Colorado intrusion, an infostealer exposure study and a House bill. NIST opens SP 800-82 Rev 4 for comment, CISA and the FBI turn to integrators, and Dragos completes its NetRise and runZero deals.

This week at a glance

The advisory cycle sets the week’s patch load, and its lead item is a supply-chain problem rather than a vendor one. CISA published nine ICS advisories on September 22. Two cover the lwIP TCP/IP stack, which is compiled into a wide range of embedded devices: CVE-2026-87121 in the MQTT client is a network-reachable out-of-bounds write at CVSS v3.1 9.8, and the fixes exist only as upstream code commits with no tagged release. Operators cannot patch that themselves; they have to wait for each device maker’s firmware. Six Siemens advisories and an end-of-life OpenPLC release fill out the batch. Two pieces of independent research sit alongside it: Nozomi Networks Labs’ chain from login bypass to root on a Pepperl+Fuchs IO-Link master, with no exploitation observed, and Ridge Security’s single-packet denial of service in the TDengine time-series database.

Water gets three stories, and they should stay separate. Two small Colorado utilities had equipment settings, alarms and pumping cycles altered in late August, with no water-quality impact and no confirmed attacker beyond “foreign actors.” SpyCloud found infostealer exposure at 1,787 of the 10,000 water organisations it sampled, including one smart-meter provider’s device holding logins for about 167 utility tenants. And a bipartisan House bill would authorise $100 million for an AI cyber defence pilot at CISA. On guidance, NIST opened comment on SP 800-82 Rev 4 until November 30, and CISA and the FBI told operators to tighten the terms and remote access they give integrators.

The market story is Dragos completing its NetRise and runZero acquisitions after Accenture’s majority investment closed, adding asset discovery and device firmware analysis to its platform. Three vendor datasets — Honeywell, Forescout and Rockwell — describe more confidence than inventory and less segmentation than the diagrams suggest. And OpenAI opened its Daybreak cyber models to Ukraine’s infrastructure defenders, one of several items this week on what AI changes for OT defence.

On our watch list

  • Whether lwIP tags a release, and which device makers ship firmware. The fixes for CVE-2026-87121 and CVE-2026-91018 exist only as upstream commits. Watching for a tagged lwIP release and for the first vendor firmware notices that name the commits, because until device makers rebuild, every embedded product on lwIP 2.0.1 through 2.2.1 stays exposed regardless of what operators do.
  • Any change to Pepperl+Fuchs’s “no exploitation” status. CISA’s SSVC decision recorded no evidence of exploitation and no public exploit was indexed as of September 16. Watching for a public proof of concept for CVE-2026-27546, the 9.8 authentication bypass, because a researcher chain from login to root is a short step once code is out.
  • Whether anyone confirms who was behind the Colorado incidents. The governor’s office says only “foreign actors” and cannot confirm more. Watching for a CISA or FBI statement that either ties the incidents to the national wave covered by CISA’s August 21 advisory or does not — that is what separates an isolated intrusion from a campaign.
  • November 30: the comment deadline for NIST SP 800-82 Rev 4. The draft extends coverage to building automation, water, food and agriculture, freight rail and maritime vessels and reorganises around CSF 2.0’s Govern function. Watching for how much of the new zero trust and system-management material survives comment, since the final text will shape audits in those newly named sectors.
  • Whether H.R. 10519 moves, and whether money follows. The AI Cyber Defense Act authorises $100 million for 2027 through 2031, subject to appropriations. Watching for committee action and for how it is reconciled with ONCD’s voluntary Watershed 250 pilot in Texas — an authorisation without an appropriation funds nothing for small and rural operators.
  • What the Dragos Platform looks like after the integration. Dragos has promised integration details “in the coming months” for runZero’s asset discovery and NetRise’s firmware analysis. Watching for whether device firmware analysis reaches customers as a product feature, because this week’s lwIP advisory is exactly the embedded-component question it is meant to answer.
  • New York utilities’ AI-use inventories, due within 60 days. The New York PSC, chaired by Rory Christian, requires utilities to file inventories of how they use AI, citing risk in a “growing dependency”; cybersecurity attacks are one of several risk categories. Watching for whether other state commissions copy the inventory requirement.
  • July 16, 2027: the MTSA cybersecurity plan deadline. Dragos’s VL Prosperity piece restates the MTSA cyber-rule dates: reporting from July 16, 2025, training by January 12, 2026, and the Cybersecurity Officer, assessment and plan by July 16, 2027. Watching for further detail on the tanker boardings, where claims about propulsion, navigation and cargo systems still come only from Iranian state media.
  • Whether OpenAI’s Daybreak access produces reported results in Ukraine. Ukraine has named incident response, threat triage, log analysis and vulnerability validation as its uses. Watching for any published outcome from verified infrastructure teams — the first public measure of whether AI access shortens defenders’ response time in practice.

Topic map of this week's IT/OT Security themes

This week’s topic map — an advisory week with the water sector running through it. The ICS advisory cycle sits at the centre with CISA, drawing in the lwIP TCP/IP stack and CVE-2026-87121, Siemens and Industrial Edge Management, and OpenPLC Runtime v3, with the embedded supply chain as the link to energy and water. A research cluster joins Nozomi Networks Labs, Pepperl+Fuchs and the ICE2 IO-Link master to CERT@VDE’s VDE-2026-014, alongside Ridge Security’s TDengine finding. Water and wastewater connects Colorado, SpyCloud and infostealer exposure, the EPA and the AI Cyber Defense Act. NIST SP 800-82 Rev 4 and CSF 2.0 anchor the guidance band, with CISA and the FBI on third-party integrator risk. Dragos carries Accenture, NetRise, runZero and xOT visibility; Honeywell, Forescout, Rockwell and ENISA form the benchmark cluster; and OpenAI’s Daybreak links Ukraine to AI for OT defence. No threat actor is named this week, so none appears.

View interactive topic map →

Article index

The ICS advisory cycle and OT vulnerability research

A nine-advisory CISA release anchored by two flaws in the lwIP embedded TCP/IP stack, plus two pieces of independent research on field-level devices. None of the flaws in this group has been reported as exploited in the wild; the lwIP fixes are the supply-chain problem, because they exist only as upstream code commits.
Article Source Published
1. CISA Releases Nine Industrial Control Systems Advisories (lwIP, Siemens x6, OpenPLC) CISA Sep 22, 2026
2. Fooling the Master: Pepperl+Fuchs IO-Link Under Attack Nozomi Networks Sep 24, 2026
3. Ridge Security warns of high-severity TDengine vulnerability that can disrupt industrial telemetry and monitoring Industrial Cyber Sep 25, 2026
4. Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars SecurityWeek Sep 1, 2026

Water sector under pressure

Three separate stories, not one: an incident at two small Colorado utilities, a vendor study of infostealer exposure across water organisations, and a House bill that would fund an AI cyber defence pilot at CISA. Read them side by side, but do not read them as a single campaign.
Article Source Published
5. Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems SecurityWeek Sep 21, 2026
6. Another worry for water systems: infostealer exposure CyberScoop Sep 22, 2026
7. After water attacks, Capitol Hill offers its own proposal for AI cyber defense pilot at CISA CyberScoop Sep 22, 2026

Guidance, regulation and regulators speaking

NIST opened comment on a fourth revision of its OT security guide, CISA and the FBI addressed the integrators who hold keys to many plants, and three regulators — maritime, Texas energy and New York utilities — spoke to their own sectors.
Article Source Published
8. OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators SecurityWeek Sep 24, 2026
9. VL Prosperity: What MTSA Cybersecurity Already Requires Dragos Sep 24, 2026
10. RRC Commissioner Christian Urges Texas Energy Industry to Prepare for Evolving Cyber Threats Railroad Commission of Texas Sep 24, 2026
11. New York audits utility AI use, cites risk in ’growing dependency’ Utility Dive Sep 24, 2026

OT platform consolidation

Dragos completed two acquisitions that fold asset discovery and device firmware analysis into its platform. The second item is Dragos’s own product-marketing follow-up on the same deal.
Article Source Published
12. Dragos Acquires NetRise and runZero: What’s Next for xOT Security Dragos Sep 21, 2026
13. Visibility Was Never the Finish Line Dragos Sep 23, 2026

Surveys, benchmarks and threat landscapes

A heavy week for vendor and agency datasets. Each figure below belongs to the organisation that collected it, and the samples, definitions and periods differ, so compare them with care.
Article Source Published
14. Honeywell 2026 OT Security Benchmark highlights gaps in OT visibility, incident recovery, cybersecurity readiness Industrial Cyber Sep 23, 2026
15. Only 13% of OT Network Segments Are Fully Isolated: Analysis SecurityWeek Sep 22, 2026
16. Rockwell study flags cybersecurity as industrial growth risk SecurityBrief Sep 23, 2026
17. ENISA Threat Landscape 2026 highlights ransomware, vulnerability exploitation, AI-enabled attacks across EU organizations Industrial Cyber Sep 23, 2026
18. Centrii’s GRIDLOCK report warns UK battery storage faces 92% probability of major cyberattack by 2031 Industrial Cyber Sep 3, 2026

AI on both sides of OT defence

An AI lab offering its cyber models to a country under attack, and three longer reads on what AI actually changes for defenders and attackers in industrial environments.
Article Source Published
19. OpenAI, Ukraine partner on ’Daybreak’ program to protect power grids and water systems CyberScoop Sep 23, 2026
20. What the AI Warning Letter Completely Missed Dark Reading Sep 3, 2026
21. What AI Actually Changes for OT Security: Observations from the Field Dragos Sep 10, 2026
22. AI adoption in OT security accelerates as legacy infrastructure and poor data expose readiness gaps Industrial Cyber Sep 22, 2026

Recovery and engineering out consequences

Foundational reading on the operational half of an OT incident: getting production back, the safety consequences in food and agriculture, and designing consequences out before an attacker arrives.
Article Source Published
23. From IT restoration to production restart: Why manufacturers continue to struggle with operational side of cyber recovery Industrial Cyber Sep 1, 2026
24. Cyberattacks on food and agriculture can turn disruptions into safety crises, threatening public health and supply chains Industrial Cyber Sep 8, 2026
25. Cyber-informed engineering shifts critical infrastructure security from protecting networks to engineering out consequences Industrial Cyber Sep 15, 2026

Detailed write-ups

1. Nine ICS advisories, and a network-reachable 9.8 in an embedded stack with no tagged release

CISA · September 22, 2026

CISA released nine industrial control system advisories on September 22, ICSA-26-265-01 through -09: two for the lwIP TCP/IP stack, six for Siemens products (Siveillance Control, SIPLUS and SIMATIC products, the Desigo CC family, Industrial Edge Management, SIMOVE Fleetmanager and SIPLANT, and the WTV676 and WTV776) and one for OpenPLC Runtime v3. The bulletin’s own instruction is the standard one — “CISA encourages users and administrators to review these ICS Advisories for technical details and mitigations” — so the prioritisation falls to you.

The lwIP pair is the story. ICSA-26-265-01 covers the lwIP MQTT client application, where CVE-2026-87121 is an out-of-bounds write (CWE-787) scored CVSS v3.1 9.8 and v4.0 9.3, reachable over the network with no credentials and no user action; CISA says it may allow full code execution on the device. ICSA-26-265-02 covers the core lwIP stack: CVE-2026-91018, a double free (CWE-415) at v3.1 8.8 and v4.0 8.7, adjacent-network only, which CISA states is not remotely exploitable. Both affect lwIP 2.0.1 through 2.2.1. The CSAF record for -02 lists eight critical-infrastructure sectors, from chemical and energy to water and wastewater. No public exploitation of the lwIP flaws is known.

What makes this hard is where the fix lives. The lwIP corrections exist only as upstream commits (f89407e for -01; f873b6295933e4149a2132adf3e9a2d2a676a5ec for -02), with no tagged lwIP release. lwIP is compiled into embedded firmware, so an operator cannot patch it directly: each device maker has to pick up the commit, rebuild and ship new firmware. Until that happens, affected devices stay exposed, and the practical task this week is asking suppliers whether their products embed lwIP and when firmware will follow.

Two other advisories carry clear actions. Siemens Industrial Edge Management (-06) has CVE-2026-18963, a flaw in the Keycloak reset-credentials flow that lets an unauthenticated attacker set a new password for any account; fixed versions are V1.15.20, V2.2.2 and V2.9.1, and Siemens’s workarounds restrict who can reach the login page. OpenPLC Runtime v3 (-09) carries CVE-2026-88020, a cross-site scripting flaw at CVSS v3.1 6.1 that needs a user to follow a link; v3 is end-of-life, there is no fix, and the vendor’s remedy is to move to v4. The remaining Siemens advisories should be read at source before triage — the public detail on several of them is still thin.

Sources: CISA

2. Pepperl+Fuchs IO-Link: a researcher’s chain from login bypass to root, not an attack in the wild

Nozomi Networks · September 24, 2026

Nozomi Networks Labs published its research into the Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 IO-Link master, tested on EtherNet/IP firmware 1.7.3. The headline’s “Under Attack” describes the researchers’ attack scenarios: CISA’s SSVC decision on September 16 recorded no evidence of exploitation, and no public exploit was indexed as of that date.

The count depends on who is counting. Nozomi’s blog reports 19 vulnerabilities; the coordinated advisory, CERT@VDE VDE-2026-014, published September 16 — eight days before the blog — lists 20, across ICE2-* and ICE3-* models (nine products). The worst is CVE-2026-27546, an authentication bypass (CWE-288) in the _account_log function at CVSS v3.1 9.8, which lets an unauthenticated remote attacker log in as admin even when accounts are correctly configured. From admin, OS command injection flaws scored 7.2 to 8.8 lead to root code execution; a path traversal flaw scores 7.5.

The operational point is about trust in process data. In Nozomi’s words, “A compromised IO-Link master can alter sensor data before it reaches the PLC” — which would let process manipulation on the factory floor hide behind normal-looking readings. Affected firmware is below 1.7.4, and CERT@VDE instructs installing firmware update 1.7.8.

Sources: Nozomi Networks

3. Colorado: two small water utilities, settings changed, no water-quality impact, no confirmed attacker

SecurityWeek · September 21, 2026

Two privately owned Colorado water utilities, each serving fewer than 200 people, were targeted in late August. The disclosure first ran in The Denver Post, Reuters, Axios and ABC on September 18; SecurityWeek’s September 21 piece follows up on that reporting. Neither utility has been named.

What happened is specific. “These two incidents consisted of individuals changing equipment settings, disabling remote access and alarms, and altering pumping cycles,” said Ally Sullivan, spokeswoman for Gov. Jared Polis. The providers addressed the incidents themselves and then alerted the state, and “to our knowledge, treatment processes and water quality were not impacted at either provider.” State health officials offered technical assistance and alerted other providers; Denver Water, which serves about 1.5 million customers, said its systems were not affected.

What is not known matters as much. The governor’s office attributes the incidents only to “foreign actors” and says it cannot confirm who was involved. It noted CISA-reported Iranian-backed activity against water systems nationally as context, not as attribution. The incidents came weeks after a wave of attacks on roughly a dozen states and about 100 water entities, the subject of a CISA advisory dated August 21, per Reuters. Treat any claim that names a group behind the Colorado incidents as unconfirmed.

Sources: SecurityWeek

4. SpyCloud: stolen logins, not guesswork, as the way into water systems

CyberScoop · September 22, 2026

SpyCloud, an identity-risk firm, analysed 10,000 EPA-registered water and wastewater organisations drawn from a database of 66,845 systems, and found 1,787 of those 10,000 showing active infostealer exposure. That is a finding about SpyCloud’s sample, not a count of all US water systems. The study does not name malware families or state its collection period.

The most striking figure is a concentration risk. A single infected device at a smart-meter technology provider held saved logins for roughly 167 different US utility metering tenants. Infostealer logs typically carry session cookies, credentials and autofill data, which is the point SpyCloud’s chief investigations officer Jason Lancaster makes: “Infostealer exposure means the attacker isn’t guessing anymore, they’ve got legitimate points of entry.”

The article’s incident context is this summer’s Minnesota water attacks, not Colorado. The lesson for operators is about suppliers as much as staff: a vendor’s compromised laptop can hold the keys to many utilities at once.

Sources: CyberScoop

5. The AI Cyber Defense Act: Congress’s answer to the water attacks

CyberScoop · September 22, 2026

Rep. Josh Gottheimer (D-NJ) introduced the AI Cyber Defense Act, H.R. 10519, with Reps. Don Bacon (R-NE), Zach Nunn (R-IA), Hillary Scholten (D-MI) and Greg Landsman (D-OH). It would set up an AI cyber defence pilot at CISA, with $100 million authorised for 2027 through 2031, subject to appropriations, and priority for nonprofit, public, rural and small operators.

The bill is pitched as an alternative to ONCD’s voluntary “Watershed 250” pilot in Texas. The “water attacks” in CyberScoop’s headline refer to the recent wave generally, not to Colorado specifically. As with any authorisation, the figure is a ceiling that only an appropriation turns into money.

Sources: CyberScoop

6. NIST SP 800-82 Rev 4 opens for comment, and CISA and the FBI turn to integrators

SecurityWeek · September 24, 2026

NIST released a draft of SP 800-82 Revision 4, “Guide to Operational Technology (OT) Security,” with public comments due November 30. The revision extends sector coverage to building automation, water and wastewater, food and agriculture, freight rail and maritime vessels. It aligns with NIST Cybersecurity Framework 2.0 and reorganises risk management around CSF 2.0’s Govern function, and it adds material on asset management, network monitoring and detection, protection of system-management functions and zero trust architecture.

Separately, CISA and the FBI jointly issued a fact sheet for critical-infrastructure operators that rely on third-party ICS integrators. Its recommendations are concrete: least privilege, granting access “only the minimum access necessary to perform their assigned tasks, and no more”; cybersecurity and supply-chain terms in contracts covering data storage, remote access and patch management; disconnecting devices from the public internet where possible; and logged, on-demand remote access rather than persistent connections.

The fact sheet grounds this in an FBI analysis of a March–April 2025 intrusion at an industrial automation company, in which foreign actors staged nine archives containing 800 network schematics and customer details. That intrusion is unattributed. The point for operators is that an integrator’s file share can hold a map of your plant.

Sources: SecurityWeek

7. Dragos closes NetRise and runZero and builds an xOT platform

Dragos · September 21, 2026

Dragos announced on September 21 that its acquisitions of NetRise and runZero are complete, following the close of Accenture’s majority investment in Dragos. Per Accenture, NetRise closed on July 31, the Dragos majority investment on September 16 and runZero on September 17. Accenture’s June agreement put the combined deal at approximately $4.175 billion in enterprise value; individual prices for NetRise and runZero were not disclosed.

The two companies fill different gaps. runZero, led by CEO HD Moore, the creator of Metasploit, brings asset discovery and exposure management across IT, OT, IoT and cloud. NetRise, led by CEO Thomas Pace with CTO and Chief Scientist Michael Scott, brings firmware and software supply-chain analysis of devices — directly relevant to a week in which the main advisory was an embedded-stack flaw. All three executives join with their teams to lead integration into the Dragos Platform, alongside the previously acquired Phosphorus, with details promised “in the coming months.” Robert M. Lee becomes chairman as well as CEO. “Defenders have one place to see everything in their xOT environment, understand what’s running on it, and stop what’s targeting it,” he said.

Dragos says it remains independent under governing documents that bind it to its OT mission, and that it will keep working with partners that compete with Accenture. This is the acquiring company’s own announcement; the companion post “Visibility Was Never the Finish Line” is Dragos product marketing for the same deal.

Sources: Dragos (acquisition) · Dragos (visibility)

8. Three vendor datasets on the gap between OT confidence and OT reality

Industrial Cyber, SecurityWeek, SecurityBrief · September 22–23, 2026

Honeywell’s 2026 OT Security Benchmark Report, a self-reported survey of more than 600 industrial cybersecurity leaders, measures a perception gap. 88% of respondents call their OT programmes mature, but only 21% keep a complete OT asset inventory and only 33% have fully integrated OT into the enterprise SOC. 92% claim top-tier recovery readiness, yet only 31% are fully prepared for incidents, and average downtime is 16.2 hours; 21% put downtime cost above $100,000 an hour and 4% above $500,000. On AI, 72% use AI-enabled threat detection and 23% report autonomous or agentic detection operations. “Organizations can no longer afford to have this visibility gap,” said Jim Masso, President and CEO of Honeywell Process Automation. The report’s “significant incident” figures — 91% of energy and utilities respondents, 87% in maritime — rest on an undefined term, so do not compare them with other reports’ incident rates.

Forescout’s Vedere Labs looked at the network rather than the respondents: 47,700 segments holding more than 2.5 million devices across 209 organisations. Of the segments containing at least one OT device, only 13% were OT-only — the rest mix OT with other devices. Rockwell Automation’s study of 1,560 decision-makers in 17 countries, as reported by SecurityBrief, flags cybersecurity as a risk to industrial growth. Taken together, the three datasets point the same way: more confidence than inventory, and less separation than the architecture diagrams suggest.

Sources: Industrial Cyber (Honeywell) · SecurityWeek (Forescout) · SecurityBrief (Rockwell)

9. OpenAI opens Daybreak to Ukraine’s infrastructure defenders

CyberScoop · September 23, 2026

OpenAI and Ukraine’s Ministry of Digital Transformation announced a partnership on September 23 at OpenAI’s New York office, alongside the UN General Assembly. Verified Ukrainian critical-infrastructure teams get access to Daybreak, OpenAI’s umbrella for its cyber models and tools, plus training and technical support to find vulnerabilities and develop and test fixes faster. Ukraine names incident response, threat triage, log analysis, system inventory, code analysis and vulnerability validation as planned uses. CERT-UA recorded nearly 6,000 attacks on Ukraine in 2025, per the BBC.

Two framing notes. The $1 billion in subsidised tokens mentioned in coverage is OpenAI’s global commitment behind Daybreak for Frontline Defenders, announced September 3 — it is not a Ukraine-specific sum. And while CyberScoop’s headline names power grids and water systems, OpenAI itself describes the scope as civilian infrastructure. Ukraine’s framing of the goal was precise: “This is why the object is not to replace the cyber defender with AI, but to make sure the cyber defender acts faster,” said Dmytro Kushneruk, Consul General of Ukraine in San Francisco.

Sources: CyberScoop

Calls to action

  • Ask every OT supplier whether their products embed lwIP. Name CVE-2026-87121 (CVSS v3.1 9.8, network, no credentials) and CVE-2026-91018, versions 2.0.1 through 2.2.1, and ask for a firmware date. Until you have one, keep affected devices off routable networks and restrict which hosts can reach any MQTT client functionality.
  • Update Siemens Industrial Edge Management to V1.15.20, V2.2.2 or V2.9.1. CVE-2026-18963 lets an unauthenticated attacker set a new password for any account through the Keycloak reset-credentials flow. If you cannot update this week, apply Siemens’s workaround and restrict who can reach the login page.
  • Plan the move off OpenPLC Runtime v3. v3 is end-of-life and CVE-2026-88020 will not be fixed there; the vendor’s remedy is v4. Treat any remaining v3 deployment as unsupported software on a control path.
  • Update Pepperl+Fuchs IO-Link masters to firmware 1.7.8. Firmware below 1.7.4 is affected by the VDE-2026-014 set, including the CVSS 9.8 authentication bypass. While you schedule it, keep the devices’ management interfaces off anything but an engineering network.
  • Patch TDengine to 3.4.1.6 and fence off TCP 6030. CVE-2026-42542 (CVSS 7.5) is a pre-authentication flaw in the taosd RPC protocol that lets a single packet take down the time-series database in versions 3.4.0.0 through 3.4.1.5. If it holds your plant telemetry, losing it blinds your monitoring.
  • Check your vendors’ credential exposure, not just your staff’s. One infected device at a smart-meter provider held logins for roughly 167 utility metering tenants in SpyCloud’s data. Ask the suppliers with remote access into your environment how they detect infostealer infections, and rotate the credentials and session tokens they hold for you.
  • Rewrite integrator contracts against the CISA/FBI fact sheet. Add terms on data storage, remote access and patch management; replace persistent integrator connections with logged, on-demand access; and find out where your integrator keeps your network schematics — the 2025 case the FBI cites involved 800 of them.
  • Assign a reviewer for NIST SP 800-82 Rev 4 before November 30. If you run building automation, water, food and agriculture, freight rail or maritime systems, this is the first revision that names your sector. Comment now rather than audit against it later.

IT/OT Security

A weekly intelligence bulletin from Security Radar LLC.
Curated by Paul Davis · paul.davis@security-radar.com

© 2026 Security Radar LLC. All rights reserved.

Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.

*|LIST:ADDRESS|*

View this email in your browser · Unsubscribe

Recent Posts

  • Security Operations Weekly — September 27, 2026
  • Security Operations Weekly — September 27, 2026 — Interactive Topic Map
  • IT/OT Security Weekly — September 27, 2026

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • Competitive
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • IT/OT Security
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme