{"id":6011,"date":"2026-10-08T11:13:59","date_gmt":"2026-10-08T16:13:59","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=6011"},"modified":"2026-10-08T11:14:00","modified_gmt":"2026-10-08T16:14:00","slug":"it-ot-security-weekly-october-4-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=6011","title":{"rendered":"IT\/OT Security Weekly &mdash; October 4, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#334155;background:linear-gradient(135deg,#334155 0%,#b45309 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">October 4, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">IT\/OT Security<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">A China-nexus ransomware group reaches a water utility through unpatched SharePoint, while WaterISAC regroups after a summer of PLC intrusions and NIST publishes remote-access architectures for small utilities. A rail breach in Spain and a medical-device production halt both stop at the IT side, which is the point. Plus Google&#8217;s numbers on AI-found flaws, and what MTSA now requires you to know about every device.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>This week at a glance<\/h2>\n<p>Water is the thread again, and this week it comes from three directions. Symantec says the China-nexus group behind Warlock ransomware, tracked as Longlegs or Storm-2603, used the ToolShell flaws in on-premises SharePoint to reach a water utility, a telecom provider, a regional government body and a university. These are 2025 CVEs, so this is still unpatched servers being exploited. WaterISAC, still dealing with a summer in which PLCs were the main way in, signed a threat-intelligence partnership with Cyware. And NIST published SP 1800-45, three tested remote-access architectures for utilities, more than 80% of which serve 3,300 people or fewer.<\/p>\n<p>Two incidents this week show how much an OT operation depends on IT. In Spain, attackers came in through Adif&#8217;s public web infrastructure, moved into Renfe&#8217;s IT and took about 500 GB of data. Shieldworkz says signalling, interlocking and traction-power SCADA stayed isolated and no trains were disrupted. Dennis Hackney&#8217;s column on Boston Scientific makes the same point from manufacturing: CrowdStrike found no compromise in SCADA or maintenance systems, yet production, fulfilment and shipping had to be restored. Production stopped even though the attackers never got into the control systems. Black Kite&#8217;s count of a 40% rise in ransomware attacks on manufacturers gives the scale.<\/p>\n<p>The rest of the issue asks what is inside the devices and how fast flaws in them are being found. Google&#8217;s threat intelligence group finds monthly vulnerability disclosures roughly doubled between January and August, with AI-found flaws leading to remote code execution twice as often as the wider CVE set. Dragos argues that firmware and software supply chain analysis belongs in xOT programmes, and its MTSA explainer lists the four device controls maritime operators must now document. Policy rounds it out: DOE&#8217;s bulk-power supply chain RFI closes October 9, ENISA&#8217;s CRA reporting platform is live, and CISA says CI-Fortify recovery guidance is coming.<\/p>\n<p>            <!-- Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>October 9: DOE&#8217;s bulk-power supply chain RFI closes.<\/strong> DOE is asking about foreign-produced grid equipment, firmware, software, remote access and procurement under the August 26 executive order declaring a national emergency on bulk-power system security. Watch what the filings say about remote-access capabilities in existing equipment. That will show whether the follow-on rules are written for equipment already installed or only for new purchases.<\/li>\n<li><strong>Whether the Warlock water victim surfaces, and whether OT was touched.<\/strong> Symantec names a water utility among four victims but gives no country and no process impact. Watch for any disclosure that ransomware reached HMI, historian or SCADA hosts rather than stopping at business systems. That would change this from a SharePoint patching story into an OT incident.<\/li>\n<li><strong>Official attribution for the summer water attacks.<\/strong> CyberScoop reports the US government &#8220;reportedly&#8221; believes Iran was behind them; nothing has been published. A CISA or FBI statement would let utilities match this summer&#8217;s PLC activity against a named actor&#8217;s tradecraft rather than a general warning.<\/li>\n<li><strong>What the WaterISAC&#8211;Cyware partnership produces first.<\/strong> The stated goal is cross-sector sharing, and WaterISAC already reaches 20,000 small utilities through the National Rural Water Association. Watch whether small members start receiving machine-readable indicators they can act on, or whether the gain stays with larger utilities that have analysts.<\/li>\n<li><strong>Whether Spanish authorities confirm the &#8220;AI-assisted&#8221; account of the Renfe breach.<\/strong> The account of automated AI exploitation agents comes from Shieldworkz&#8217;s analysis, not from Renfe, Adif or CCN-CERT. An official finding either way will decide whether this becomes the first well-documented AI-agent intrusion at a rail operator.<\/li>\n<li><strong>CISA&#8217;s CI-Fortify recovery guidance.<\/strong> CISA and its Five Eyes partners say OT recovery guidance is next, following July&#8217;s advice on isolating vital systems. CISA&#8217;s Matt Rogers says the core message is to test response and recovery end to end under real conditions. Watch for whether it sets a testing cadence or stays as principles.<\/li>\n<li><strong>Whether GTIG&#8217;s exploitation numbers keep climbing.<\/strong> Exploited vulnerabilities per month rose from 10.5 in 2025 to 18 in January&#8211;August 2026, and High-Risk exploitation from 28 to 75. GTIG calls the AI-discovery link an early indicator. If the next data set holds the rise, patch windows for edge devices in front of OT will have to shorten.<\/li>\n<li><strong>NCCoE&#8217;s new OT asset management and visibility project.<\/strong> NIST is seeking collaborators for automated and manual asset discovery techniques. Watch who signs on, since the resulting build guide is likely to become the reference for what inventory evidence MTSA, NERC CIP and water regulators accept.<\/li>\n<li><strong>First reports through ENISA&#8217;s Single Reporting Platform.<\/strong> CRA reporting obligations for actively exploited vulnerabilities took effect September 11; the main requirements apply from December 11, 2027. Watch whether industrial vendors&#8217; first notifications show up in member-state CSIRT advisories, which would be the first sign the platform is working.<\/li>\n<li><strong>July 16, 2027: the MTSA cybersecurity plan deadline.<\/strong> Dragos&#8217;s explainer sets out the four device controls in 33 CFR 101.650(b), and the Coast Guard&#8217;s Cyber Protection Team has carried out an estimated 40 to 50 vessel inspections in the past year. Watch for enforcement guidance that says how much inventory and network-map evidence auditors will expect.<\/li>\n<\/ul><\/div>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/10\/topic-map-it-ot-security-2026-10-04.png\" alt=\"Topic map of this week's IT\/OT Security themes\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&#8217;s topic map is a water week that spreads into supply chain and maritime. The water and wastewater node sits at the centre. It links Storm-2603, Warlock, the ToolShell SharePoint flaws and Symantec on one side, and WaterISAC, CISA, NIST SP 1800-45 and secure remote access, with Forescout, on the other. An IT\/OT dependency cluster joins Renfe and Adif, Shieldworkz and CCN-CERT with Boston Scientific and Rhysida. AI vulnerability discovery links Google GTIG to edge devices and Nozomi&#8217;s SCALANCE LPE9403 research with Siemens. Dragos connects the software supply chain question to MTSA, the US Coast Guard and maritime. Storm-2603 and Rhysida are the only threat actors shown; the summer water attacks have no confirmed attribution, so no actor node is drawn for them.<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=6010\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#334155;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h3>Water under sustained pressure<\/h3>\n<div class=\"cluster-intro\">Four separate items: a ransomware campaign that included a water utility, the sector&#8217;s ISAC regrouping after a summer of PLC intrusions, NIST&#8217;s remote-access build guide, and a vendor&#8217;s case for brokered remote access. The common link is remote access to devices that should not be reachable.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/cyberscoop.com\/water-utility-cyberattacks-waterisac-cyware-threat-intelligence\/\">WaterISAC reckons with range of threats after summer of cyberattacks<\/a><\/td>\n<td class=\"src\">CyberScoop<\/td>\n<td class=\"dt\">Sep 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/industrialcyber.co\/ransomware\/symantec-reports-warlock-ransomware-group-targets-water-telecom-government-organizations-through-sharepoint-flaws\/\">Symantec reports Warlock ransomware group targets water, telecom, government organizations through SharePoint flaws<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Oct 2, 2026<\/td>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/www.nist.gov\/blogs\/cybersecurity-insights\/securing-water-and-wastewater-operational-technology-environments\">Securing Water and Wastewater Operational Technology Environments<\/a><\/td>\n<td class=\"src\">NIST Cybersecurity Insights<\/td>\n<td class=\"dt\">Oct 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/www.forescout.com\/blog\/secure-remote-access-the-door-you-built-yourself\/\">Secure Remote Access: the Door You Built Yourself<\/a><\/td>\n<td class=\"src\">Forescout<\/td>\n<td class=\"dt\">Sep 24, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>When IT incidents stop the plant (and the railway)<\/h3>\n<div class=\"cluster-intro\">In both main cases the control systems held and operations were still hit. Spain&#8217;s rail breach and Boston Scientific&#8217;s production halt both came in on the IT side. Manufacturing ransomware numbers and the tanker boardings fill out the picture.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/industrialcyber.co\/expert\/inside-the-it-ot-dependency-problem-boston-scientifics-production-halt-berlins-rhysida-leak-and-the-developer-workstation-as-an-entry-point\/\">Inside the IT-OT Dependency Problem &#8211; Boston Scientific&#x27;s Production Halt, Berlin&#x27;s Rhysida Leak, and the Developer Workstation as an Entry Point<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/industrialcyber.co\/transport\/shieldworkz-finds-adif-web-infrastructure-served-as-entry-point-for-renfe-compromise-in-ai-assisted-cyber-breach\/\">Shieldworkz finds Adif web infrastructure served as entry point for Renfe compromise in AI-assisted cyber breach<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/www.securityweek.com\/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows\/\">Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Sep 17, 2026<\/td>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/www.securityweek.com\/cyberattacks-on-two-oil-tankers-prompt-coast-guard-fbi-to-board-vessels\/\">Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Sep 17, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>What&#8217;s inside the device: supply chain, integrators and inventory<\/h3>\n<div class=\"cluster-intro\">Firmware and software provenance, third-party integrators, device inventories required by regulation, and cryptography on controllers expected to stay in service until around 2050. The CISA\/FBI joint guidance on third-party ICS integrators, first noted last week, draws further coverage.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/www.dragos.com\/blog\/xot-software-supply-chain-security\">Software and Supply Chain Security Can&#x27;t Be an Afterthought in xOT Anymore<\/a><\/td>\n<td class=\"src\">Dragos<\/td>\n<td class=\"dt\">Sep 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/securitytoday.com\/articles\/2026\/09\/28\/fbi-cisa-warn-of-third-party-ics-integrator-risks.aspx\">FBI, CISA Warn of Third-Party ICS Integrator Risks<\/a><\/td>\n<td class=\"src\">Security Today<\/td>\n<td class=\"dt\">Sep 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/www.dragos.com\/blog\/mtsa-device-security\">No Devices Adrift: MTSA&#x27;s Device Security Requirement<\/a><\/td>\n<td class=\"src\">Dragos<\/td>\n<td class=\"dt\">Oct 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/www.forescout.com\/blog\/pqc-in-manufacturing-11-must-ask-questions-before-you-upgrade\/\">PQC in Manufacturing: 11 Must-Ask Questions Before You Upgrade<\/a><\/td>\n<td class=\"src\">Forescout<\/td>\n<td class=\"dt\">Sep 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/industrialcyber.co\/news\/schneider-electric-seclab-expand-ot-cybersecurity-collaboration-for-industrial-infrastructure\/\">Schneider Electric, SECLAB expand OT cybersecurity collaboration for industrial infrastructure<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 29, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Vulnerability discovery and the patch cycle<\/h3>\n<div class=\"cluster-intro\">Google&#8217;s data on how fast flaws are now being found and exploited, alongside two reference items for the ICS patch queue: Nozomi&#8217;s SCALANCE LPE9403 research and September&#8217;s ICS Patch Tuesday.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/industrialcyber.co\/critical-infrastructure\/google-gtig-finds-ai-accelerating-vulnerability-discovery-across-enterprise-and-critical-infrastructure-attack-surfaces\/\">Google GTIG finds AI accelerating vulnerability discovery across enterprise and critical infrastructure attack surfaces<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Oct 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.nozominetworks.com\/blog\/exploiting-the-edge-vulnerabilities-in-the-siemens-scalance-lpe9403\">Exploiting the Edge: Vulnerabilities in the Siemens SCALANCE LPE9403<\/a><\/td>\n<td class=\"src\">Nozomi Networks<\/td>\n<td class=\"dt\">Sep 15, 2026<\/td>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/www.securityweek.com\/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws\/\">ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Sep 9, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Regulation, standards and recovery guidance<\/h3>\n<div class=\"cluster-intro\">Network monitoring documentation under NERC CIP-015, Australia&#8217;s move to enforcement under the SOCI Act, DOE&#8217;s bulk-power supply chain RFI, the EU CRA reporting platform, FERC&#8217;s approval of CIP-014-4, and CISA&#8217;s next CI-Fortify guidance.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/www.nozominetworks.com\/blog\/nerc-cip-015-in-practice-9-writing-your-insm-program\">NERC CIP-015 in Practice #9: Writing Your INSM Program<\/a><\/td>\n<td class=\"src\">Nozomi Networks<\/td>\n<td class=\"dt\">Sep 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/industrialcyber.co\/regulation-standards-and-compliance\/australias-cisc-strengthens-critical-infrastructure-compliance-under-soci-act-with-tiered-regulatory-measures\/\">Australia&#x27;s CISC strengthens critical infrastructure compliance under SOCI Act with tiered regulatory measures<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>19. <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/us-doe-seeks-industry-input-on-securing-bulk-power-systems-from-foreign-equipment-supply-chain-cybersecurity-risks\/\">US DOE seeks industry input on securing bulk-power systems from foreign equipment, supply chain, cybersecurity risks<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 11, 2026<\/td>\n<\/tr>\n<tr>\n<td>20. <a href=\"https:\/\/industrialcyber.co\/regulation-standards-and-compliance\/enisa-launches-single-reporting-platform-as-eu-cyber-resilience-act-vulnerability-reporting-obligations-take-effect\/\">ENISA launches Single Reporting Platform as EU Cyber Resilience Act vulnerability reporting obligations take effect<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 14, 2026<\/td>\n<\/tr>\n<tr>\n<td>21. <a href=\"https:\/\/industrialcyber.co\/regulation-standards-and-compliance\/ferc-approves-nerc-cip-014-4-to-strengthen-physical-security-and-risk-assessments-for-critical-transmission-facilities\/\">FERC approves NERC CIP-014-4 to strengthen physical security and risk assessments for critical transmission facilities<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 16, 2026<\/td>\n<\/tr>\n<tr>\n<td>22. <a href=\"https:\/\/www.bankinfosecurity.com\/cisa-promises-ot-recovery-guidance-through-ci-fortify-a-32928\">CISA Promises OT Recovery Guidance Through CI-Fortify<\/a><\/td>\n<td class=\"src\">BankInfoSecurity<\/td>\n<td class=\"dt\">Sep 24, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Structural risk and security debt<\/h3>\n<div class=\"cluster-intro\">Longer-horizon pieces on manufacturing security debt, the expanding satellite attack surface, and Chinese-owned infrastructure along NATO&#8217;s military mobility routes.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>23. <a href=\"https:\/\/industrialcyber.co\/features\/how-decades-of-disconnected-modernization-created-ot-security-debt-manufacturers-cant-escape\/\">How decades of disconnected modernization created OT security debt manufacturers can&#x27;t escape<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>24. <a href=\"https:\/\/industrialcyber.co\/industrial-cyber-attacks\/satellite-communications-growth-expands-cybersecurity-attack-surface-across-iot-utilities-critical-infrastructure\/\">Satellite communications growth expands cybersecurity attack surface across IoT, utilities, critical infrastructure<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>25. <a href=\"https:\/\/industrialcyber.co\/critical-infrastructure\/fdd-says-chinese-infrastructure-footprint-cybersecurity-gaps-threaten-nato-military-mobility-corridors-across-europe\/\">FDD says Chinese infrastructure footprint, cybersecurity gaps threaten NATO military mobility corridors across Europe<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 30, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. Warlock&#8217;s operators reach a water utility through unpatched SharePoint<\/h4>\n<p class=\"meta\">Industrial Cyber, on Symantec research &middot; October 2, 2026<\/p>\n<p>Symantec&#8217;s Threat Hunter Team describes recent intrusions by &#8220;the China-nexus group behind Warlock ransomware, tracked as Longlegs or Storm-2603.&#8221; The four victims named by sector are a water utility, a telecommunications provider, a regional government body and a university, in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. Warlock first appeared in June 2025; this activity spans roughly the past two months.<\/p>\n<p>The way in is not new. The group exploited the ToolShell flaws in on-premises Microsoft SharePoint Server (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771). Symantec&#8217;s point is that ToolShell &#8220;remains a viable initial access route&#8221; wherever SharePoint has not been patched or mitigated. Once inside, the operators relied on webshells, Visual Studio Code tunnelling through code-insiders.exe, DLL sideloading and living-off-the-land tools. In one case they pushed a tool that disables security software to at least 40 hosts in about two hours and deployed ransomware on more than 33.<\/p>\n<p>Read the water detail carefully. The utility is not named, its country is not given, and nothing in the reporting says process or control systems were affected. For OT teams the lesson is speed: from an internet-facing collaboration server, the operators had disabled defences across dozens of hosts in two hours. That is the time you have to separate business IT from anything that reaches the plant.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/ransomware\/symantec-reports-warlock-ransomware-group-targets-water-telecom-government-organizations-through-sharepoint-flaws\/\">Industrial Cyber<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. WaterISAC regroups after a summer in which PLCs were the way in<\/h4>\n<p class=\"meta\">CyberScoop &middot; September 30, 2026<\/p>\n<p>WaterISAC announced a partnership with Cyware to strengthen its threat-intelligence work and, in the words of Cyware&#8217;s Tom Stockmeyer, &#8220;start enabling cross-sector sharing.&#8221; It builds on WaterISAC&#8217;s existing partnership with the National Rural Water Association, which serves 20,000 of the sector&#8217;s smallest utilities.<\/p>\n<p>The context is a summer that included a coordinated attack disrupting water utilities in 30 Minnesota communities. CyberScoop reports that the US government &#8220;reportedly&#8221; believes Iran was behind this summer&#8217;s water attacks, and that Russia and China are also active against the sector; there is no published attribution. WaterISAC executive director Tom Dobbins says programmable logic controllers have been the &#8220;main point of entry.&#8221;<\/p>\n<p>His prescription is plain: &#8220;OT systems that are exposed to the internet are a major challenge, and many of these systems that are older generation need to be not accessible.&#8221; For a sector where most systems are small, that means taking controllers off the internet before investing in more advanced detection.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/cyberscoop.com\/water-utility-cyberattacks-waterisac-cyware-threat-intelligence\/\">CyberScoop<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. NIST SP 1800-45: three tested ways to give remote access to water OT<\/h4>\n<p class=\"meta\">NIST Cybersecurity Insights &middot; October 1, 2026<\/p>\n<p>NIST&#8217;s National Cybersecurity Center of Excellence published SP 1800-45, <em>Cybersecurity for the Water and Wastewater Sector: Build Architecture (Operational Technology Remote Access)<\/em>, the output of a project begun in 2022 with utilities, technology providers and associations. It demonstrates three approaches: a conventional firewall with a remote-access server; a cloud-based option for resource-constrained utilities; and automated system-to-system data exchange protected by hardware encryption.<\/p>\n<p>The audience is small utilities. The US has nearly 50,000 community water systems and more than 16,000 wastewater systems, and more than 80% serve 3,300 people or fewer. The blog cites July 2026 attacks that targeted PLCs to change settings, reduce monitoring and disrupt operations. The controls are technical (encryption, multifactor authentication, segmentation, jump servers) and administrative (access lists, least privilege, logging). For enterprise-wide risk, NIST points to CSF 2.0 and SP 800-82r3. NCCoE is also launching a project on OT asset management and visibility.<\/p>\n<p>Forescout&#8217;s piece the week before makes the same case from the threat side. CISA observed malicious activity against more than 100 water and wastewater entities in July, often through PLCs connected directly to cellular modems. Forescout&#8217;s Vedere Labs counts nearly 60,000 VNC servers without authentication, more than 670 of them tied to OT or ICS control panels. Its recommended pattern is one brokered gateway in the DMZ, just-in-time sessions and vaulted credentials: &#8220;Reducing internet exposure does not mean turning off necessary remote access; it means removing it where it isn&#8217;t needed and securing it where it is.&#8221;<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.nist.gov\/blogs\/cybersecurity-insights\/securing-water-and-wastewater-operational-technology-environments\">NIST Cybersecurity Insights<\/a>, <a href=\"https:\/\/www.forescout.com\/blog\/secure-remote-access-the-door-you-built-yourself\/\">Forescout<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. Spain&#8217;s rail breach: in through Adif&#8217;s website, out with Renfe&#8217;s data, trains unaffected<\/h4>\n<p class=\"meta\">Industrial Cyber, on Shieldworkz analysis &middot; September 30, 2026<\/p>\n<p>According to Shieldworkz&#8217;s analysis, attackers compromised external-facing web infrastructure at Adif, Spain&#8217;s state-owned rail infrastructure manager, and used it to pivot into interconnected Renfe IT systems. About 500 GB of enterprise data was taken, including passenger names and email addresses; per official statements, bank and payment details, national identity numbers and passwords were not.<\/p>\n<p>The timeline is short at the end and long at the start. Renfe reported weeks of attempted attacks, and Shieldworkz describes reconnaissance and brute-forcing from late August to mid-September. Abnormal behaviour was detected late on September 24, contained on the 25th and systems restored by the 26th. Shieldworkz says the final phase used automated AI-driven exploitation agents that resembled Claude API tool-use wrappers. That is the firm&#8217;s assessment, not a finding from Renfe, Adif or Spain&#8217;s CCN-CERT.<\/p>\n<p>The OT result is the useful part. Shieldworkz reports that &#8220;zero physical train disruptions, signalling failures, or station control outages occurred,&#8221; with interlocking, centralised traffic control and traction-power SCADA isolated and unaffected. The separation held, and the breach still came through a partner organisation&#8217;s web estate. Weak points are often shared web front ends and trust between affiliated operators, not the control network.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/transport\/shieldworkz-finds-adif-web-infrastructure-served-as-entry-point-for-renfe-compromise-in-ai-assisted-cyber-breach\/\">Industrial Cyber<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. The IT&#8211;OT dependency problem: production stops even when SCADA is clean<\/h4>\n<p class=\"meta\">Industrial Cyber (expert column) &middot; September 30, 2026<\/p>\n<p>Dennis Hackney&#8217;s column puts three recent cases side by side. At Boston Scientific, attackers entered through an external-facing network device on August 25. CrowdStrike found no evidence of compromise in SCADA or manufacturing maintenance systems, yet manufacturing, order fulfilment and shipping were not fully restored until September 9. In Berlin, Rhysida exfiltrated data between August 7 and 12, two Senate departments were cut off from state networks on August 14, and the group claimed 5.7 TB with a 30-bitcoin minimum bid before publishing packages on September 4 and 6, the second including access credentials.<\/p>\n<p>The third case is about developers: an actor tracked as Nimbus Manticore posed as recruiters and sent engineers trojanised coding challenges with three-hour deadlines. Hackney presents his conclusions as assessment rather than finding. His argument is that plants depend on ERP, scheduling and logistics systems, so an IT intrusion can stop production without touching a controller.<\/p>\n<p>Suzu Labs&#8217; Jacob Krell puts the economics in one line: &#8220;The attacker doesn&#8217;t need to destroy anything. They just need to make downtime more expensive than whatever they&#8217;re asking for.&#8221; Black Kite&#8217;s report gives the numbers: a 40% rise in attacks on manufacturers in early 2026 against the same period of 2025, and 1,183 new incidents in the first seven months of the year.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/expert\/inside-the-it-ot-dependency-problem-boston-scientifics-production-halt-berlins-rhysida-leak-and-the-developer-workstation-as-an-entry-point\/\">Industrial Cyber<\/a>, <a href=\"https:\/\/www.securityweek.com\/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows\/\">SecurityWeek<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>6. What&#8217;s in the firmware: supply chain security comes to xOT<\/h4>\n<p class=\"meta\">Dragos &middot; September 30, 2026<\/p>\n<p>Dragos&#8217;s Michael Rothschild argues that software and supply chain analysis can no longer be an afterthought in OT, IoT and related environments. His example is the 2024 backdoor attempt in widely used infrastructure software, caught only because an engineer noticed a login taking 500 milliseconds too long. &#8220;A network scan won&#8217;t find that. A threat detection rule won&#8217;t catch it either, because there&#8217;s nothing to detect until it&#8217;s already been used against you.&#8221;<\/p>\n<p>He cites Dragos&#8217;s 2026 Year in Review finding that only 3&#8211;6% of xOT vulnerabilities require immediate action. Without component-level knowledge, teams cannot tell which few matter. He also says NERC CIP, NIS2 and TSA pipeline directives now expect operators to answer for what runs inside their devices. The post promotes the Dragos Platform&#8217;s software and supply chain capability built from the NetRise and runZero acquisitions, so read it as a vendor&#8217;s case. Still, the question is the right one: do your suppliers give you SBOMs and firmware detail you can check?<\/p>\n<p>Forescout&#8217;s post-quantum piece raises the same procurement question over a longer period. NIST finalised FIPS 203, 204 and 205 in August 2024, and the UK NCSC suggests discovery by 2028, priority migrations by 2031 and completion by 2035. Forescout&#8217;s example: &#8220;A PLC installed today has an ECDSA public key in its bootloader and is designed to stay in the field until around 2050.&#8221; For controllers bought now, ask the supplier how their firmware signing will be upgraded.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.dragos.com\/blog\/xot-software-supply-chain-security\">Dragos<\/a>, <a href=\"https:\/\/www.forescout.com\/blog\/pqc-in-manufacturing-11-must-ask-questions-before-you-upgrade\/\">Forescout<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>7. Google: AI is speeding up vulnerability discovery, and exploitation is rising with it<\/h4>\n<p class=\"meta\">Industrial Cyber, on Google Threat Intelligence Group research &middot; October 1, 2026<\/p>\n<p>Google&#8217;s Threat Intelligence Group reports that monthly vulnerability disclosures roughly doubled this year, from 5,045 in January to 10,740 in August. Exploitation rose too: from 10.5 exploited vulnerabilities a month in 2025 to 18 a month in January&#8211;August 2026. High-Risk vulnerabilities exploited more than doubled, from 28 in all of 2025 to 75 in eight months.<\/p>\n<p>GTIG tracked 2,076 AI-related CVE disclosures from January 2025 through August 2026, and found that half of AI-discovered vulnerabilities led to remote code execution, against 26% across the wider CVE set. Edge and security appliances accounted for 14% of exploited vulnerabilities, and more than 65% of those exploited edge flaws were rated High or Critical. GTIG is careful: &#8220;Although still an early indicator rather than an established trend, confirmed exploitation shows the risk from AI-discovered flaws is not purely theoretical.&#8221;<\/p>\n<p>These are enterprise-wide figures, not ICS statistics, and only 0.23% of 2026 disclosures were seen exploited. The OT relevance is the edge devices in front of plants. Nozomi&#8217;s research on the Siemens SCALANCE LPE9403 shows the kind of flaw involved: 12 vulnerabilities, with a local unprivileged user able to escalate to root, fixed under Siemens SSA-327438.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/critical-infrastructure\/google-gtig-finds-ai-accelerating-vulnerability-discovery-across-enterprise-and-critical-infrastructure-attack-surfaces\/\">Industrial Cyber<\/a>, <a href=\"https:\/\/www.nozominetworks.com\/blog\/exploiting-the-edge-vulnerabilities-in-the-siemens-scalance-lpe9403\">Nozomi Networks<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>8. MTSA device security: four controls, and IT systems count too<\/h4>\n<p class=\"meta\">Dragos &middot; October 1, 2026<\/p>\n<p>Dragos&#8217;s Elan Alvey and Bobbie Crinella explain what 33 CFR 101.650(b) requires in Section 6 of a maritime facility&#8217;s or vessel&#8217;s Cybersecurity Plan. There are four controls: an approved list of hardware, firmware and software; executable code disabled by default on critical IT and OT systems; an accurate inventory of network-connected systems; and network maps with documented OT device configurations. They stress what operators often miss: the rule covers critical IT such as domain controllers, jump servers and historian databases, not just OT.<\/p>\n<p>Dragos&#8217;s field data shows how far behind many operators are. About 40% of regulated organisations have unlisted assets crossing the OT boundary into DMZ or corporate networks, and about 80% of organisations with no regulatory requirement do. Dragos and Marsh McLennan put global OT cyber risk at $31.1 billion for 2025. The authors point operators to the Coast Guard&#8217;s Small Entity Compliance Guide, and the post ends with an assessment offer. Their summary is the useful part: &#8220;Know what&#8217;s on your network, what&#8217;s supposed to be there, what it&#8217;s configured to do, and how it talks to everything else.&#8221;<\/p>\n<p>SecurityWeek&#8217;s September report on the tanker boardings shows why the Coast Guard is pressing this. Coast Guard and FBI teams boarded the VL Prosperity on August 21 for a four-day inspection and a second tanker on August 24. US authorities confirmed malicious cyber activity but attributed it to no one, and the claims of engine and communications disruption come from Iranian media. The Coast Guard&#8217;s Cyber Protection Team has carried out an estimated 40 to 50 such inspections in the past year.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.dragos.com\/blog\/mtsa-device-security\">Dragos<\/a>, <a href=\"https:\/\/www.securityweek.com\/cyberattacks-on-two-oil-tankers-prompt-coast-guard-fbi-to-board-vessels\/\">SecurityWeek<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Calls to action --><\/p>\n<div class=\"watchlist\">\n<h2>Calls to action<\/h2>\n<ul>\n<li><strong>Close ToolShell on every on-premises SharePoint server this week.<\/strong> Confirm CVE-2025-49704, -49706, -53770 and -53771 are patched or mitigated, rotate machine keys if a server was ever exposed unpatched, and hunt for code-insiders.exe tunnels, new webshells and security-tool tampering. Then check what that server can reach on the OT side.<\/li>\n<li><strong>Find internet-reachable PLCs and cellular modems, and take them off.<\/strong> PLCs were the main entry point in this summer&#8217;s water attacks, often through directly connected cellular modems. Search your external footprint for controllers, HMIs and VNC services, especially VNC without authentication, and remove every exposure that is not formally justified.<\/li>\n<li><strong>Put all vendor and integrator access behind one brokered gateway.<\/strong> Use NIST SP 1800-45&#8217;s three architectures as a template: sessions through a DMZ jump point, multifactor authentication, just-in-time approval, vaulted credentials and logging. No persistent connection straight to a controller.<\/li>\n<li><strong>Audit public web front ends that bridge to partners or affiliates.<\/strong> The Renfe breach came through Adif&#8217;s external web infrastructure. List every web application shared with, or trusted by, a sister organisation, and confirm in a test, not on paper, that your signalling, SCADA or control networks stay isolated if it falls.<\/li>\n<li><strong>Map which IT systems production cannot run without.<\/strong> Boston Scientific&#8217;s SCADA was clean and production still stopped. Document the ERP, scheduling, labelling and shipping dependencies for each line, and decide in advance how long you can run in manual or degraded mode.<\/li>\n<li><strong>Update Siemens SCALANCE LPE9403 under SSA-327438.<\/strong> Move devices below V4.0 HF0 to the fixed firmware and SINEMA Remote Connect Edge Client below V2.1 to the fixed release. Until then, restrict local accounts on the device, since the chain starts with unprivileged local access.<\/li>\n<li><strong>File, or at least start the inventory for, DOE&#8217;s bulk-power RFI by October 9.<\/strong> If you own bulk-power assets, list foreign-produced equipment, firmware and remote-access paths now. That inventory will be needed whatever rules follow.<\/li>\n<li><strong>MTSA-regulated operators: test your plan against the four 101.650(b) controls.<\/strong> Approved hardware, firmware and software list, executable code disabled by default, a network-connected inventory and OT network maps. Include domain controllers, jump servers and historians, not just OT devices.<\/li>\n<li><strong>Ask suppliers for SBOMs, firmware details and a cryptography roadmap.<\/strong> Write component transparency and a plan for upgrading firmware signing into new controller purchases. Equipment bought this year may still be running in 2050.<\/li>\n<\/ul><\/div>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">IT\/OT Security<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>October 4, 2026 &middot; Weekly Edition IT\/OT Security A China-nexus ransomware group reaches a water utility through unpatched SharePoint, while WaterISAC regroups after a summer of PLC intrusions and NIST publishes remote-access architectures for small utilities. A rail breach in Spain and a medical-device production halt both stop at the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[],"class_list":["post-6011","post","type-post","status-publish","format-standard","hentry","category-it-ot-security"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6011"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6011\/revisions"}],"predecessor-version":[{"id":6022,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6011\/revisions\/6022"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6011"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}