This week at a glance
Two stories this week are about who fixes OT and who pays for it. Anthropic launched a Critical Infrastructure Defense Program that gives Claude, on-site engineers and threat research to eleven OT providers, from Dragos and Nozomi Networks to Rockwell Automation and Hitachi, reaching operators through the firms they already trust rather than directly. DOE put $100 million into technical help for electric co-ops and municipal utilities, routed through not-for-profit partnerships of at least six utilities each. Both approaches accept that operators cannot do this alone. Neither yet shows how fixes will reach running systems faster.
Europe’s renewables were the exposure story. Modat and the Dutch NCSC counted 8,547 wind and solar systems reachable online that should not be, including a turbine interface with Start, Stop and Reset buttons. A Commission expert group separately recommended restricting high-risk PV suppliers and requiring independent assessment of inverters under the Cyber Resilience Act. In Washington, the OT Cybersecurity Coalition asked CISA for a binding directive on federal OT after GAO found only 7 of 22 agencies had inventoried their devices.
On threats, CISA’s October 6 batch is led by critical flaws in end-of-life Hitachi Energy RTU500 firmware found by Dragos. A federal official said the two tankers boarded in August were compromised through known, unpatched flaws. ESET’s MatchBoil research shows a Russia-aligned group working through Ukrainian transport, manufacturing and energy firms. Three vendor surveys from Claroty, Rockwell and Palo Alto Networks agree that most organisations still run IT and OT security separately and do not watch third-party access. The foundational reading is about water: four pieces on what the summer’s PLC attacks should change.
On our watch list
- October 13: Siemens and Schneider Electric monthly advisories. Both publish on ICS Patch Tuesday. Watch for anything in remote-access gateways or PLC web servers, given how many renewables controllers the Modat scan found reachable, and for Schneider’s first advisories since announcing the PTC deal.
- Which providers join Anthropic’s program next, and what operators actually get. Anthropic says it will add partners and sectors in the coming months. The signal to watch is a provider publishing remediation numbers for OT customers: how many fixes were applied to running systems, not how many flaws were found.
- Whether CISA picks up the federal OT directive. The coalition’s proposal arrives with GAO showing 7 of 22 agencies met an inventory requirement that was due in 2024. A draft directive, or OMB fiscal 2026 OT guidance, would confirm the idea is moving. Silence from both would suggest it is not.
- The Commission’s response to its experts on PV suppliers. The working group recommends restricting high-risk suppliers and classing inverters as Class II under the CRA, but says a full risk assessment is still needed. Watch for a Commission-led assessment or an inverter delegated act, and for other member states following Lithuania’s restriction on remote control of large installations.
- Who answers DOE’s $100 million call. Applicants need at least six utility partners each. The number and size of the partnerships that form will show how many co-ops and municipal utilities are actually reached.
- Attribution and root cause in the tanker cases. Officials now say known, unpatched flaws were used, and Bloomberg reports access to a propulsion-linked system. Watch for the vulnerable product to be named, an advisory for shipboard systems, and whether the Coast Guard says more about the nearly 20 vessels being tracked.
- Whether MatchBoil turns up outside Ukraine, or deeper inside the energy firm. ESET has seen it only in Ukraine and only on IT endpoints. Any sign of it at EU energy or transport companies, or of follow-on tools on engineering workstations, would raise the stakes.
- Attribution for the summer water attacks. This week’s commentary disagrees on scale: twelve states in one op-ed, seven in another. An official attribution or a consolidated federal count would settle it, and would show whether the Water Safety Shield Act gets traction.
- Sweden’s detailed NIS2 guidance around the new year. MCFFS 2026:11 took effect October 1. NCSC’s guidance will show how strictly MFA for administrative access to production OT will be checked in practice.
This week’s topic map has two hubs. Unpatched and end-of-life OT sits at the centre, linking Anthropic’s Critical Infrastructure Defense Program and Claude with Dragos, the Hitachi Energy RTU500 advisory and CVE-2026-8065, and the maritime OT cluster with the US Coast Guard and FBI. IT/OT convergence links the Claroty, Rockwell and Palo Alto surveys, third-party access, NIS2, and ESET’s MatchBoil research with UAC-0099 and Ukraine. On the left, CISA connects the coalition’s binding-directive proposal and water. At the bottom, wind and solar exposure ties Modat and NCSC-NL to the Cyber Resilience Act, and DOE CESER to small and rural utilities. UAC-0099 is the only threat actor shown; the tanker and water attacks have no confirmed attribution.
View interactive topic map →
Article index
Renewables and the grid: exposure, suppliers and small utilities
Europe counts its exposed wind and solar control systems while its experts argue for curbing high-risk inverter suppliers. In the US, DOE puts $100 million behind help for small electric utilities, and a utility customer-portal breach is a reminder that not every utility incident touches the grid.
Rules for federal, national and maritime OT
A coalition asks CISA to make OT security mandatory for federal civilian agencies, Sweden’s NIS2 rules take effect with MFA required for administrative access to production OT, and port and vessel operators face Coast Guard plan deadlines next July.
Threats and vulnerabilities
Six ICS advisories led by end-of-life Hitachi Energy RTU firmware, new detail on how two tankers were compromised, an upgraded downloader aimed at Ukrainian transport and energy firms, an insider who locked his own employer out, and a practitioner’s view of what the PLC attacks show.
What operators report
Three vendor surveys this week put the share of organisations hit at roughly half or more, and all three point at the same gaps: IT and OT teams that are not integrated, third-party access that is not watched, and OT assets nobody can see. Forescout adds segmentation and healthcare cryptography data.
AI and the vendor landscape
Anthropic routes Claude to OT security through eleven providers, Schneider Electric makes its largest acquisition, Rockwell moves further into managed security, and a vendor reads Forrester’s OT Wave as a shift toward risk reduction.
Water: the policy argument
Four longer pieces on what the summer’s water attacks should change: a federal plan, a public-safety framing, engineering practice and a vendor’s checklist. They agree on the first step, which is getting PLCs off the internet.
Detailed write-ups
1. Anthropic sends Claude to the providers that patch OT
BankInfoSecurity · October 9, 2026
Anthropic has launched a Critical Infrastructure Defense Program that gives frontier Claude models, on-site engineers and its threat research to eleven founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. The list covers the consultancies that run security programmes, the security firms that watch business and industrial networks, and the manufacturers that build and patch the equipment. The first targets are the OT behind power grids, water, factories and transport, plus government systems.
The program reaches operators through those providers rather than directly. Anthropic’s reasoning is that OT often cannot be taken offline to patch, so known flaws can stay open for years, and operators of every size already depend on a small set of trusted providers to tell them what is exposed and which fixes are safe on a running system. Several partners are already using Claude to fix vulnerabilities, and Anthropic says it will add partners and sectors in the coming months. It has not said who pays for the compute.
“Our first step is to work with a small cohort of providers to learn which strategies are most effective and practical,” the company said. BankInfoSecurity’s caveat is the one that matters on the plant floor: the impact depends on whether operators can apply prioritised fixes as quickly as AI finds the flaws, without disrupting operations. Finding vulnerabilities was never the slow part. If your OT provider is on the list, ask what you will actually receive and how fixes will be tested before they reach production.
Sources: BankInfoSecurity
2. Europe’s renewables: 8,547 exposed systems and a push to curb high-risk suppliers
Help Net Security · October 9, 2026; pv magazine · October 8, 2026
Modat and the Dutch NCSC found 8,547 internet-facing systems at wind farms and solar parks in 35 countries in and around the EU that should not be reachable online. They describe the number as a floor, because a system was counted only when it could be tied to a specific site. Solar accounts for 7,942 systems in 34 countries, with Spain alone holding 2,766. Wind accounts for 605, about two-thirds of them in Germany and Italy. One exposed turbine interface showed live power, wind speed and rotor data, with Start, Stop and Reset buttons, served from a Siemens ET 200SP PLC.
The day before, pv magazine reported a cybersecurity working group of the Commission’s Smart Energy Expert Group recommending restrictions on PV components and software from suppliers under the jurisdiction of high-risk third countries, across every market segment including plug-in systems. It also wants inverters classed as Class II important products under the Cyber Resilience Act, which would require independent assessment, and for commercial and utility-scale sites to replace automatic manufacturer firmware updates with controlled manual ones. The group ranks three risks highest: attacks on manufacturer cloud platforms, nation-state backdoors, and attacks on utility-scale plants through local networks. EU solar capacity has grown from 86 GW in 2015 to 406 GW in 2025, which the experts compare with the 3,000 MW of frequency containment reserve on the continental grid.
Two caveats. The report reflects the experts’ consensus, not the Commission’s position, and they say restrictions should follow a risk assessment they did not carry out. And CRA product rules apply only to products placed on the market from December 11, 2027, so they do nothing for the installed base the Modat scan found. As Tributech’s Thomas Plank put it, “Once an attacker is inside, the network can’t tell a legitimate stop command from a malicious one.”
Sources: Help Net Security, pv magazine
3. OT coalition asks CISA for a binding directive on federal OT
Infosecurity Magazine · October 7, 2026
The Operational Technology Cybersecurity Coalition wants CISA to issue a binding operational directive setting minimum OT security practice across federal civilian agencies. Agencies run OT in more than 8,000 GSA-managed facilities, including labs, hospitals and ports of entry, for HVAC, power, access control, water and building automation. The coalition argues that no current directive covers it and that CISA cannot see the risk.
The evidence is a GAO report from September 30: only 7 of 22 civilian agencies reviewed had fully met OMB’s requirement to inventory networked OT and IoT devices, which was due in September 2024, and OMB had not issued updated guidance for fiscal 2026. The proposed directive would require a named senior official for OT security, bring OT into enterprise risk management, and set baselines for inventory, segmentation, remote access, configuration management, incident preparedness and verified recovery. The priority controls are basic ones: change default passwords, use MFA, segment and back up. Patching and firmware updates are not on the list.
A directive would bind only federal civilian agencies, but it would complement CISA’s CI Fortify work and give private operators and vendors a reference baseline. ColorTokens’ Louis Eichenbaum summed up the emphasis: “Patching remains essential, but we cannot patch our way out of cyber risk.”
Sources: Infosecurity Magazine
4. CISA’s October 6 advisories: end-of-life RTU firmware with a 9.1 firmware-upload flaw
CISA · October 6, 2026
CISA’s October 6 batch contains six ICS advisories, four of them for Hitachi Energy. The most serious is ICSA-26-279-06, based on Dragos findings in end-of-life RTU500 series CMU firmware, version 11.x and earlier. CVE-2026-8065 allows an unauthenticated attacker to upload arbitrary firmware through a crafted request, and CVE-2026-8066 allows unauthenticated file writes through path traversal; both are rated CVSS 9.1. Older issues carried in the same firmware include the VxWorks WDB debug agent on UDP port 17185 (CVE-2010-2965). Supported firmware is not affected, and the fix is to move to 12.7.8, 13.9.1 or later.
The rest of the batch: a CVSS 9.8 buffer overflow in the lwIP SMTP client 2.2.1 (CVE-2026-15340), which matters to anyone shipping embedded devices built on lwIP; hard-coded credentials in end-of-life Johnson Controls EasyIO FG building controllers, which will not be fixed and should be replaced with EasyIO Neo; an authenticated ActiveMQ code-injection flaw in Hitachi Energy SOI 2.0.0 to 2.2.0 (CVSS 8.8); and libexpat denial-of-service flaws in the IEC 61850 parsing of REB500 busbar protection, fixed in 8.3.4.0. No exploitation is reported for any of them.
Two of the six concern products that are out of support, which fits this week’s surveys: Palo Alto’s respondents name legacy, unpatchable OT as their biggest single risk. Siemens and Schneider Electric publish their monthly advisories on October 13.
Sources: CISA
5. DOE puts $100 million behind small and rural electric utilities
Industrial Cyber · October 6, 2026
DOE’s Office of Cybersecurity, Energy Security, and Emergency Response has opened a $100 million funding opportunity, the Rural and Municipal Utility Cybersecurity (RMUC) Advanced Cybersecurity Technical Assistance program. It is aimed at electric cooperatives, municipal utilities and small investor-owned utilities, the operators least able to staff a security team.
The money does not go to utilities directly. It goes to not-for-profit organisations, which must show formal partnerships with at least six qualifying electric utilities. Funded work can include assessments and planning, workforce training and certification, exercises, tool deployment, verification and validation, and threat-information sharing. ConnectWerx manages the program with DOE under an agreement set up by DOE’s Office of Technology Commercialization. CESER director Andrew McClure said the office “is committed to closing the capability gap for small and rural operators.”
For a small utility the practical question is which intermediary it partners with, since the award goes to the partnership. Co-ops and municipal utilities should talk to their statewide associations now rather than wait for a call after awards are made. The article gives no application deadline.
Sources: Industrial Cyber
6. The tanker hacks used known, unpatched flaws
BankInfoSecurity · October 6, 2026
New detail on the two US-bound tankers boarded in August: a federal official told ISMG that both incidents exploited known vulnerabilities in on-board systems that had not been patched. “This was preventable,” the official said. That had not been reported before.
The FBI and Coast Guard have said the boardings took place on August 21 and August 24 to check the integrity of the vessels’ OT and IT systems after indications that both networks had been compromised. Coast Guard Cyber Protection Teams found “malicious cyber activity”, and the agencies say there have been no reports of operational disruption, instability, danger to crews or environmental impact. Separately, Bloomberg reported this week, citing unnamed officials, that investigators found evidence of temporary access to a propulsion-linked system on the VL Prosperity, and that US agencies are tracking threats against nearly 20 vessels. No one has been publicly blamed.
Unpatched known flaws are the least surprising explanation and the most useful one for operators. Shipboard systems are patched in port, by vendors, on their schedule. The Coast Guard’s cybersecurity rule, with plans due in July 2027, is the lever most likely to change that.
Sources: BankInfoSecurity
7. MatchBoil: a Russia-aligned downloader aimed at Ukrainian transport and energy
The Record · October 8, 2026
ESET has published research on MatchBoil, a downloader used by UAC-0099, a group ESET says likely works in Russia’s interests. Every infection it observed was in Ukraine: transportation companies in July and August 2025, a manufacturer in December 2025 and an energy-sector company in June 2026. Phishing links deliver archives that run the malware, which collects system information, fetches further payloads and sets up persistence.
The tool has been in development since at least July 2024, with a newer version seen in April 2026, and the group keeps modifying it to evade security software. A late-2025 variant added a decoy daily planner. “Each new iteration of the downloader was more sophisticated than the last,” ESET’s researchers wrote. UAC-0099 has been active since at least 2022, mostly against Ukrainian government, finance and media targets. In August 2025 it sent fake court summonses to government, military and defence organisations to install the MatchWok backdoor and the Dragstare infostealer.
This is espionage against office endpoints at industrial companies, and no OT impact is reported. Its relevance here is the sequence: transport, then manufacturing, then energy. For an industrial firm, the phishing inbox is often the first step toward the plant.
Sources: The Record
8. Three surveys, one finding: IT and OT security are still run separately
Industrial Cyber · October 8 and 10, 2026
Claroty surveyed 2,000 leaders across 16 industries in more than 40 countries. 58% said a cyberattack had affected their operational environment in the past year, most often causing downtime (43%) or safety incidents (40%). The average loss was $1.04 million, rising to $2.25 million at organisations with 10,000 or more employees, and the average outage lasted three days. 75% had at least one operations-affecting incident tied to third-party access, yet 49% monitor third-party connections only partly or not at all. Only 16% say their IT and operational security teams are fully integrated.
Rockwell Automation’s report, which gives no sample size, finds 46% of industrial organisations had a cyber incident in the past year while 90% say they are confident they could contain one. It ranks IT/OT integration points among the most vulnerable areas. Palo Alto Networks surveyed more than 1,600 critical infrastructure security leaders in 11 countries. About six in ten had a significant breach in the past year, 68% lack complete real-time visibility of their OT assets, 42% call legacy, unpatchable OT their biggest single risk, and 74% have not fully integrated IT and OT security operations. It also reports that 29% of 2026 CVEs were exploited within 24 hours, against an average of 55 days to deploy a patch.
All three are vendor surveys, so read the headline percentages with care. The agreement between them is more useful than any single figure: separate IT and OT teams, third-party connections nobody watches, and assets nobody can see. “Businesses have quickly realized that prioritizing operational resilience is key to ensuring robust protection,” said Claroty’s Sean Tufts.
Sources: Industrial Cyber (Claroty), Industrial Cyber (Rockwell), Industrial Cyber (Palo Alto Networks)
Calls to action
- Upgrade or replace end-of-life Hitachi Energy RTU500 firmware. If any RTU500 CMU runs 11.x or earlier, plan the move to 12.7.8, 13.9.1 or later. Until then, make sure the device web and firmware-update interfaces are reachable only from engineering hosts, and block UDP 17185.
- Replace Johnson Controls EasyIO FG controllers. No fix is coming for the hard-coded credentials. Keep them off the internet on a segmented building-automation network until EasyIO Neo replacements are installed.
- Check embedded products for the lwIP SMTP client. If you build or buy devices on lwIP 2.2.1 with SMTP enabled, ask the supplier for its status on CVE-2026-15340 (CVSS 9.8).
- Search your external footprint for renewables and plant interfaces. Run the same check Modat did on your own address space: inverter portals, turbine and park controllers, PLC web servers. Anything with Start/Stop controls reachable from the internet should come off today.
- Take manufacturer auto-updates off utility-scale inverters. Follow the experts’ recommendation now: put firmware updates through a controlled, manual change process and restrict inverter cloud connections to what operations need.
- Inventory third-party connections and start monitoring them. Three-quarters of Claroty’s respondents had an operations-affecting incident tied to third-party access. List every vendor and integrator path into OT, close the unused ones and log the rest.
- Ship operators: get on-board system patch status from vendors. Both tanker compromises used known flaws. Ask each system supplier for current patch levels and a schedule, and build them into the Coast Guard cybersecurity plan due in July 2027.
- Small electric utilities: line up a DOE program partner. Talk to your statewide association or another not-for-profit about joining a six-utility partnership for the RMUC funding.
- Brief staff at industrial firms on court-summons and document lures. UAC-0099 reaches transport, manufacturing and energy companies through phishing archives. Block archive downloads from untrusted links on hosts that can reach engineering networks.
|