<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: OT, ICS, and Critical Infrastructure</title><link>https://cybersecuritytracker.ai/?cats=ot-ics</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>The automotive software vulnerabilities hiding in your dashboard</title><link>https://helpnetsecurity.com/2026/07/24/car-research-automotive-software-vulnerabilities</link><guid isPermaLink="false">cst-3146</guid><description>Modern vehicles contain substantial embedded software running operating systems like Android, Linux, QNX, and VxWorks across dashboard displays and safety-critical systems. Carmakers have transitioned to software-dependent architectures over the past decade, introducing potential vulnerability exposures in these systems. The article examines security risks inherent in automotive software stacks.</description><pubDate>Fri, 24 Jul 2026 06:30:41 GMT</pubDate></item><item><title>US government says Iran-linked hackers are disrupting American water and energy providers</title><link>https://techcrunch.com/2026/07/23/us-government-says-iran-linked-hackers-are-disrupting-american-water-and-energy-providers</link><guid isPermaLink="false">cst-3129</guid><description>The US government issued an updated advisory warning that Iranian-linked hackers are exploiting systems used by water and energy infrastructure providers. The advisory indicates ongoing targeting of critical infrastructure sectors essential to public services.</description><pubDate>Thu, 23 Jul 2026 17:27:08 GMT</pubDate></item><item><title>Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure</title><link>https://databreaches.net/2026/07/23/iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical-infrastructure-2?pk_campaign=feed&amp;pk_kwd=iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical-infrastructure-2</link><guid isPermaLink="false">cst-3126</guid><description>Iranian-affiliated cyber actors are actively targeting internet-connected operational technology devices, particularly programmable logic controllers, across multiple U.S. critical infrastructure sectors, causing disruptions. U.S. government agencies issued an urgent advisory warning organizations of the ongoing threat. The campaign highlights persistent efforts by nation-state actors to compromise industrial control systems.</description><pubDate>Thu, 23 Jul 2026 12:45:42 GMT</pubDate></item><item><title>US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices</title><link>https://securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices</link><guid isPermaLink="false">cst-3060</guid><description>Federal agencies released an advisory detailing attack techniques used by Iranian hackers to compromise programmable logic controllers from Siemens, Schneider Electric, and Rockwell Automation. The advisory documents methods for targeting these critical industrial control system (ICS) devices.</description><pubDate>Thu, 23 Jul 2026 05:28:50 GMT</pubDate></item><item><title>Federal agencies broaden alert on Iran-linked OT attacks</title><link>https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks</link><guid isPermaLink="false">cst-3035</guid><description>Federal agencies issued an alert regarding attacks attributed to Iran targeting operational technology (OT) environments. The incidents involved malicious manipulation of industrial control systems, including human machine interface and supervisory control and data acquisition displays.</description><pubDate>Wed, 22 Jul 2026 19:18:00 GMT</pubDate></item><item><title>The air gap is a myth and other OT security truths</title><link>https://helpnetsecurity.com/2026/07/21/benjamin-bachmann-bilfinger-ot-security</link><guid isPermaLink="false">cst-2878</guid><description>Benjamin Bachmann, Bilfinger's Director of Group Information Security, discusses operational technology (OT) security misconceptions in an interview with Help Net Security. He addresses the limitations of air gap protection, the importance of visibility into legacy equipment through network monitoring, and how ransomware operators price demands based on operational downtime. The discussion covers incident containment negotiation and threat actor motivations in industrial environments.</description><pubDate>Tue, 21 Jul 2026 06:00:29 GMT</pubDate></item><item><title>India says allegedly leaked nuclear plant files pose no safety risk</title><link>https://therecord.media/india-nuclear-plant-kudankulam-world-leaks-documents</link><guid isPermaLink="false">cst-2859</guid><description>Indian officials stated that documents allegedly leaked by the World Leaks cybercrime group from the Kudankulam Nuclear Power Plant do not contain safety or security information. The incident highlights claims by the threat actor but officials have assessed the leaked materials as non-sensitive.</description><pubDate>Mon, 20 Jul 2026 18:20:00 GMT</pubDate></item><item><title>Scans for Hikvision Intelligent Security API</title><link>https://isc.sans.edu/diary/rss/33164</link><guid isPermaLink="false">cst-2803</guid><description>Internet-wide scans targeting Hikvision cameras have shifted to probing the OPEN Intelligent Security API (ISAPI), a REST-based interface that provides broad control over camera settings and features. The scans specifically target the /ISAPI/System/status endpoint to detect ISAPI-capable devices and potentially support credential brute-forcing. While ISAPI supports both Basic and Digest authentication with optional AES encryption, the encryption key derivation from passwords and exposed initialization vector undermine security if Basic authentication is used over unencrypted connections.</description><pubDate>Sun, 19 Jul 2026 15:00:38 GMT</pubDate></item><item><title>Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy</title><link>https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities</link><guid isPermaLink="false">cst-2749</guid><description>Three chained zero-day vulnerabilities were discovered in Siemens ROX II operational technology switches that enable privilege escalation and persistent root access when exploited together. The vulnerabilities form a complete attack chain affecting industrial control systems that rely on these network switches. Unit 42 published a technical analysis detailing the flaw sequence.</description><pubDate>Fri, 17 Jul 2026 10:00:24 GMT</pubDate></item><item><title>Legacy Systems, Real-World Impacts: The Reality of OT Security</title><link>https://securityweek.com/legacy-systems-real-world-impacts-the-reality-of-ot-security</link><guid isPermaLink="false">cst-2696</guid><description>An article examining the challenges of balancing vulnerability disclosure in operational technology environments where legacy systems, safety concerns, and critical infrastructure risks complicate security practices. The piece addresses the tensions inherent in securing aging systems that cannot always be quickly patched or updated.</description><pubDate>Thu, 16 Jul 2026 15:15:00 GMT</pubDate></item><item><title>What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out</title><link>https://wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon</link><guid isPermaLink="false">cst-2147</guid><description>Insurers conducted a classified tabletop exercise simulating a large-scale cyberattack on US water infrastructure by the Volt Typhoon threat group, modeling cascading failures such as ruptured pipes and hospital evacuations. The exercise revealed significant gaps in preparedness and response coordination for such a critical infrastructure breach.</description><pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Orbia CISO Miranda Ritchie on building security into sustainable infrastructure</title><link>https://helpnetsecurity.com/2026/07/08/miranda-ritchie-orbia-industrial-cybersecurity</link><guid isPermaLink="false">cst-2130</guid><description>Miranda Ritchie, CISO at Orbia, discusses integrating security into industrial systems that manage water, chemical, and manufacturing processes. She addresses the unique risks of operational technology (OT) environments, including geographically dispersed sites and legacy hardware, and advocates for embedding security teams early in project development and adopting zero-trust principles aligned with safety culture.</description><pubDate>Wed, 08 Jul 2026 06:00:52 GMT</pubDate></item><item><title>Building more resilient CNI: what industry pen testers told us</title><link>https://ncsc.gov.uk/blogs/building-more-resilient-cni-what-industry-pen-testers-told-us</link><guid isPermaLink="false">cst-284</guid><description>Penetration testers shared recommendations on hardening critical national infrastructure (CNI) defenses based on their field experience. The guidance focuses on practical steps organizations can implement to increase resistance to security testing and real-world attacks.</description><pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Frangoteam FUXA SCADA/HMI</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-181-02</link><guid isPermaLink="false">cst-268</guid><description>Frangoteam FUXA SCADA/HMI versions 1.3.1 and earlier contain an authentication bypass vulnerability (CVE-2026-13207) that allows unauthenticated attackers to enumerate user accounts and role assignments through dot-segment path normalization in the REST API. The vulnerability exploits improper path normalization before authentication middleware is applied, allowing attackers to access protected endpoints by using sequences like /api/./users or /api/project/../users. Frangoteam recommends upgrading to version 1.3.2 or later to remediate the issue.</description><pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate></item><item><title>LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience</title><link>https://sentinelone.com/labs/labscon25-replay-please-connect-to-the-foreign-entity-to-enhance-your-user-experience</link><guid isPermaLink="false">cst-607</guid><description>Joe FitzPatrick presents research on undocumented connectivity features in imported networked devices, particularly highlighting cellular radios discovered in U.S. highway solar inverters and the widespread reliance on foreign-manufactured hardware by small businesses and infrastructure operators. He argues that current safeguards like import bans and FCC regulations are ineffective at managing supply chain risks and recommends alternatives including right-to-repair policies with offline use guarantees, hardware bills of materials, and comprehensive privacy legislation. The talk examines how devices default to connecting to foreign entities and the practical challenges of using such hardware without establishing external connections.</description><pubDate>Wed, 06 May 2026 13:00:29 GMT</pubDate></item><item><title>Hacking Embodied AI</title><link>https://recordedfuture.com/research/hacking-embodied-ai</link><guid isPermaLink="false">cst-1965</guid><description>Humanoid and quadruped robots are increasingly deployed in manufacturing, critical infrastructure, and military operations, but security has lagged behind rapid adoption. Researchers demonstrated that commercially available robots can be compromised via Bluetooth, exfiltrate data to remote servers, and spread compromises across robot fleets wirelessly. Organizations deploying embodied AI must treat robots as cyber-physical endpoints with comprehensive security controls, network isolation, and fleet continuity plans.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>Securing Critical Infrastructure in the Cloud Era: A Policy and Technology Blueprint</title><link>https://wiz.io/blog/securing-critical-infrastructure-in-cloud-era</link><guid isPermaLink="false">cst-1399</guid><description>This article discusses strategies for securing critical infrastructure in cloud environments, addressing the intersection of policy frameworks and technological implementations needed in modern deployments. The piece presents a blueprint for organizations managing critical systems as they transition toward cloud-based architectures.</description><pubDate>Thu, 30 Oct 2025 12:00:00 GMT</pubDate></item><item><title>When and Where SIEM Fits in Healthcare IT Settings | Huntress</title><link>https://huntress.com/blog/first-do-no-harm-when-and-where-siem-fits-in-healthcare-it-settings</link><guid isPermaLink="false">cst-906</guid><description>This article discusses the role of Security Information and Event Management (SIEM) systems within healthcare IT environments, examining when SIEM tools are valuable, where they have limitations, and how they fit into a broader security infrastructure. The piece provides guidance on integrating SIEM into healthcare security architectures to optimize detection and response capabilities.</description><pubDate>Wed, 18 Dec 2024 00:00:00 GMT</pubDate></item><item><title>New Report Reveals Hidden Risks: How Internet-Exposed Systems Threaten Critical Infrastructure</title><link>https://greynoise.io/blog/new-report-reveals-hidden-risks-how-internet-exposed-systems-threaten-critical-infrastructure</link><guid isPermaLink="false">cst-1927</guid><description>A Censys report identified approximately 145,000 internet-exposed industrial control systems (ICS) and thousands of insecure human-machine interfaces (HMI), creating readily exploitable entry points for attackers. Real-world incidents demonstrate active threats, including state-backed actors from Iran and Russia targeting HMI systems to compromise water infrastructure in Pennsylvania and Texas. GreyNoise research confirms attackers are actively scanning for HMI vulnerabilities and prioritizing remote access services as lower-friction attack vectors compared to direct ICS protocol exploitation.</description><pubDate>Thu, 21 Nov 2024 00:00:00 GMT</pubDate></item><item><title>NERC CIP-014 Standard Explained | Huntress</title><link>https://huntress.com/blog/nerc-cip-014-standard-explained</link><guid isPermaLink="false">cst-933</guid><description>Huntress provides an explanation of NERC CIP-014, a North American Electric Reliability Corporation (NERC) standard designed to enhance physical security at electric utility facilities. The standard was established to address vulnerabilities in the power grid infrastructure and outlines specific security requirements for utility operators.</description><pubDate>Mon, 07 Oct 2024 18:41:00 GMT</pubDate></item><item><title>Challenging Assumptions: Enhancing the Understanding of Securing Internet-Exposed Industrial Control Systems</title><link>https://greynoise.io/blog/challenging-assumptions-enhancing-the-understanding-of-securing-internet-exposed-industrial-control-systems</link><guid isPermaLink="false">cst-1934</guid><description>Censys and GreyNoise released research at LABSCon 2024 examining real-world threats to internet-exposed Industrial Control Systems (ICS). The findings show that attackers prioritize common Remote Access Service (RAS) protocols over ICS-specific communications when targeting internet-connected human-machine interfaces (HMIs), challenging previous assumptions about how critical infrastructure is compromised.</description><pubDate>Fri, 20 Sep 2024 00:00:00 GMT</pubDate></item><item><title>The Undeniable Benefits of Healthcare Security Awareness | Huntress</title><link>https://huntress.com/blog/the-undeniable-benefits-of-healthcare-security-awareness-training</link><guid isPermaLink="false">cst-983</guid><description>Huntress discusses the benefits of implementing security awareness training programs within healthcare organizations. The article emphasizes how security awareness can help build a culture of security and protect against threats in the healthcare sector.</description><pubDate>Tue, 30 Apr 2024 06:00:00 GMT</pubDate></item><item><title>Interconnected Devices Inject Risk into Patient Safety | Huntress</title><link>https://huntress.com/blog/interconnected-devices-inject-risk-into-patient-safety</link><guid isPermaLink="false">cst-987</guid><description>Healthcare providers face security risks from interconnected medical devices that could compromise patient safety and data protection. The article discusses how managed Endpoint Detection and Response (EDR) solutions and expert partnerships can help healthcare organizations address these device security challenges and maintain continuity of care.</description><pubDate>Mon, 08 Apr 2024 00:00:00 GMT</pubDate></item><item><title>The Health Sector is Under Attack. But You Can Fight Back. | Huntress</title><link>https://huntress.com/blog/the-health-sector-is-under-attack-but-you-can-fight-back-</link><guid isPermaLink="false">cst-1003</guid><description>Healthcare organizations face escalating cyber threats, and the U.S. Department of Health and Human Services is introducing new cybersecurity measures while small and mid-sized healthcare providers are encouraged to strengthen their defenses. The article emphasizes proactive security postures as a critical response to the current threat landscape.</description><pubDate>Thu, 15 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Securing Healthcare: Handling Cyber Threats with Care | Huntress</title><link>https://huntress.com/blog/securing-healthcare-handling-cyber-threats-with-care</link><guid isPermaLink="false">cst-1007</guid><description>This article discusses the cybersecurity threat landscape in healthcare and outlines defensive strategies to protect patient data and systems. The piece emphasizes the importance of addressing cyber threats within the healthcare sector's operational context.</description><pubDate>Fri, 12 Jan 2024 00:00:00 GMT</pubDate></item></channel></rss>