#OTSecurity
New research reveals how attackers can exploit synchronized measurements in grid control systems to destabilize power networks faster than previously thought—and why current detection may not be enough.

https://arxiv.org/abs/2609.36583

#OTsecurity #ICS
October 2, 2026 at 6:30 AM
ICS[AP] Dashboards are updated with the 6 CISA Advisories released on 10/1/2026:

Johnson Controls: 2 New
ABB: 1 New
Armatura LLC: 1 New - ⚠ KEV MATCH FOUND: CVE-2023-46604 - Apache ActiveMQ
Meari: 1 New
Monta: 1 New
(www.icsadvisoryproject.com)
#icssecurity
#otsecurity
#vulnerabilitymanagement
ICS Advisory Project
ICS Advisory Project The ICS Advisory Project is an open-source project that provides the Critical Infrastructure Security Agency (CISA) ICS Advisories, visualized as a Dashboard and in Comma-Separat...
www.icsadvisoryproject.com
October 1, 2026 at 9:53 PM
Didn't get a ticket? Join the waiting list to increase your chances on a last-minute package! opensecurityconference.org/conference/r...

#osco #osco26 #Security #CyberSecurity #InfoSec #AppSec #OTSecurity [lisi] 2/2
Registration
Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 5-8 November 2026 in Rückersbach, Germany.
opensecurityconference.org
October 1, 2026 at 1:27 PM
Not every OT threat has to break in. Some already have access.

Juan Negrete explores why insider risk goes beyond malicious intent and how mistakes, misconfigurations, and unmanaged access can impact OT.

enaxy.com/2026/09/myth...

#OTSecurity #ICS #Cybersecurity #Enaxy
September 30, 2026 at 5:07 PM
AI is dramatically lowering the technical bar for cyberattacks in relation to energy infrastructure, making real-time network telemetry crucial for detecting machine-speed threats.
bit.ly/3TDm6xd
#AI #Cybersecurity #CriticalInfrastructure #NetworkSecurity #OTSecurity #ThreatDetection #EnergySector
AI Cyberattacks Outpacing Energy Sector Defenses — ExtraHop
Discover how AI lowers the barrier for attacks on energy infrastructure, see key factors driving vulnerability, and explore strategies for better defense.
www.extrahop.com
September 30, 2026 at 3:07 PM
A critical Apache PLC4X vulnerability, CVE-2026-102508, lets attackers impersonate OPC UA servers and steal credentials. Upgrade to PLC4X 1.0.0 now.

#Apache="/hashtag/ApachePLC4X" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#ApachePLC4X #PLCref="/hashtag/PLC4X" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#PLC4X #OPCUA #CVE2026102508 #ICSSecurity #OTSecurity #PLC #Apache
Critical Apache PLC4X Flaw Lets Attackers Hijack OPC UA Connections to PLCs
TL;DR The Apache Software Foundation disclosed CVE-2026-102508, a critical Apache PLC4X vulnerability in its OPC UA driver, on September 30, 2026. It scores 9.2 under CVSS 4.0. An attacker in a network position between client and server can impersonate the server and steal user credentials. Why This Apache PLC4X Vulnerability Matters Apache PLC4X is a set of libraries for talking to industrial programmable logic controllers (PLCs).
securityonline.info
September 30, 2026 at 8:44 AM
ICS[AP] Dashboards are updated with the 7 CISA Advisories released on 9/29/2026:

New:
Anjvision
Baicells Technologies
Lantronix
MikroTik
Toptech Systems
VIVOTEK
Viidure

[www.icsadvisoryproject.com](www.icsadvisoryproject.com)
#icssecurity
#otsecurity
#vulnerabilitymanagement
ICS Advisory Project
ICS Advisory Project The ICS Advisory Project is an open-source project that provides the Critical Infrastructure Security Agency (CISA) ICS Advisories, visualized as a Dashboard and in Comma-Separat...
www.icsadvisoryproject.com
September 30, 2026 at 3:51 AM
⚡ Air gapping is a myth in the remote access era. Over 60% of OT breaches use stolen credentials. Protect Level 1 controllers by enforcing identity verification before command execution.
shorturl.at/UF20q

#swIDch #OTAC #AirGapping #RemoteAccess #OTSecurity #ZeroTrust
September 29, 2026 at 2:07 PM
🚨 19 vulnerabilities, including a critical auth bypass (CVE-2026-27546), found in Pepperl+Fuchs IO-Link industrial gateways. Flaws allow root access, posing a severe risk to OT networks. Patches are available. #ICS #OTSecurity #Vulnerability

🌐 cyber[.]netsecops[.]io
19 Flaws in Industrial Gateway Grant Root Access to OT Networks
Researchers found 19 flaws in a Pepperl+Fuchs industrial gateway, including a critical authentication bypass that could give attackers root access to OT...
cyber.netsecops.io
September 29, 2026 at 2:00 PM
Check out our core values and how they shape the conference and also our organizer team: opensecurityconference.org/about/values/

#osco #osco26 #Security #CyberSecurity #InfoSec #AppSec #OTSecurity [lisi] 2/2
Values
Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 5-8 November 2026 in Rückersbach, Germany.
opensecurityconference.org
September 29, 2026 at 12:21 PM
The DOE opened a request for information on securing the power grid from foreign-made equipment. Finite State's Doc McConnell says the signal is clear: regulators want evidence about what's inside the box, not just attestations. 🔌 #OTSecurity

https://bit.ly/4herTCx
September 28, 2026 at 2:45 PM
CISA & FBI issue joint guidance on securing critical infrastructure from third-party ICS integrator risks. The advisory stresses least privilege, robust contracts, and secure remote access monitoring. #ICS #OTsecurity #CISA #SupplyChain

🌐 cyber[.]netsecops[.]io
CISA & FBI Warn of Third-Party Risks to Industrial Control Systems
CISA and the FBI released a joint fact sheet urging critical infrastructure operators to mitigate cyber risks from third-party ICS integrators.
cyber.netsecops.io
September 25, 2026 at 8:31 PM
ICS[AP] Dashboards are updated with the 2 new and 2 updated CISA Advisories released on 9/24/2026:

Botslab: 1 New
Eufy: 1 New
Siemens: 1 Update
Wärtsilä: 1 Update

[www.icsadvisoryproject.com](www.icsadvisoryproject.com)
#icssecurity
#otsecurity
#vulnerabilitymanagement
ICS Advisory Project
ICS Advisory Project The ICS Advisory Project is an open-source project that provides the Critical Infrastructure Security Agency (CISA) ICS Advisories, visualized as a Dashboard and in Comma-Separat...
www.icsadvisoryproject.com
September 25, 2026 at 7:31 AM
OT-Sicherheit 2026: Lücke zwischen Anspruch und Praxis
Selbsteinschätzung und Realität klaffen auseinander + Überwachung bleibt lückenhaft + Ausfallzeiten mit spürbaren Folgen
www.all-about-security.de/ot-sicherhei...

#otsicherheit #otsecurity
OT-Sicherheit 2026: Lücke zwischen Anspruch und Praxis
OT-Sicherheit 2026 unter der Lupe: 88 Prozent der Firmen glauben an ihre Sicherheit, doch wo sind die Mängel?
www.all-about-security.de
September 25, 2026 at 6:29 AM
POTATO THREATS CAN DISRUPT THE PHYSICAL WORLD

Critical infrastructure attacks can lead to:

🔹 Operational disruption
🔹 Financial losses
🔹 Safety and compliance risks
🔹 Third-party access vulnerabilities

#PotatoSecurity #CriticalInfrastructure #OTSecurity #InfosecK2K
September 25, 2026 at 5:42 AM
CYBER THREATS CAN DISRUPT THE PHYSICAL WORLD

Critical infrastructure attacks can lead to:

🔹 Operational disruption
🔹 Financial losses
🔹 Safety and compliance risks
🔹 Third-party access vulnerabilities

#CyberSecurity #CriticalInfrastructure #OTSecurity #InfosecK2K
September 25, 2026 at 5:42 AM
CISA & FBI issue joint guidance on securing critical infrastructure from third-party ICS integrator risks. The advisory stresses least privilege, robust contracts, and secure remote access monitoring. #ICS #OTsecurity #CISA #SupplyChain

🌐 cyber[.]netsecops[.]io
CISA & FBI Warn of Third-Party Risks to Industrial Control Systems
CISA and the FBI released a joint fact sheet urging critical infrastructure operators to mitigate cyber risks from third-party ICS integrators.
cyber.netsecops.io
September 24, 2026 at 10:21 PM
The US has 150,000+ water utilities; only a few hundred are in Water-ISAC, the sector's threat-sharing group. Finite State's Joshua Marpet on OpenAI's $1B defender fund. Welcome help, but it only matters if lean utilities can actually use it. #OTSecurity

https://bit.ly/4rnjyzH
September 23, 2026 at 6:35 PM
How do you improve network segmentation when you can’t start from scratch?

Brandon Workentin explores practical ways to strengthen segmentation in brownfield OT environments without putting operations at risk.

enaxy.com/2026/09/impl...

#OTSecurity #ICS #Cybersecurity #Enaxy
September 23, 2026 at 6:03 PM