Threat Feed
CISA   CVE-2026-32117 added to Known Exploited Vulnerabilities catalogue, Atlassian Confluence auth bypassNCSC UK   Joint advisory with allied agencies on reconnaissance against energy operatorsENISA   Q2 threat landscape update: ransomware activity down 12% across the EUCSA Singapore   Critical advisory for ICS-affecting GE Cimplicity, patch & segmentASD   Increased reconnaissance against ANZ critical infrastructure operatorsMarkets   CrowdStrike +2.4%, SentinelOne −1.2% after Q1 print; Zscaler guidance heldKBI   New, 'Platformisation is a myth.' According to a long-standing cyber analystCISA   CVE-2026-32117 added to Known Exploited Vulnerabilities catalogue, Atlassian Confluence auth bypassNCSC UK   Joint advisory with allied agencies on reconnaissance against energy operatorsENISA   Q2 threat landscape update: ransomware activity down 12% across the EUCSA Singapore   Critical advisory for ICS-affecting GE Cimplicity, patch & segmentASD   Increased reconnaissance against ANZ critical infrastructure operatorsMarkets   CrowdStrike +2.4%, SentinelOne −1.2% after Q1 print; Zscaler guidance heldKBI   New, 'Platformisation is a myth.' According to a long-standing cyber analyst
The Voice of Cyber® · Independent Cyber Journalism
Topic

OT Security

19 stories

OT Security, or Operational Technology Security, refers to the practices and measures implemented to safeguard the operational technology systems. This encompasses hardware and software used to monitor and control physical processes, particularly in context with critical infrastructure and similar deployments across manufacturing, transportation, defence, and energy production.

  1. Critical-infrastructure regulation
    Contributor

    Australia's Critical Infrastructure Rules Just Grew Teeth

    The SOCI amendments push OT security from best-effort to board-level obligation. Operators are still catching up.

    27 May 2026 · 6 min read
  2. SBOM regulation
    Contributor

    The SBOM Mandate Reaches the Plant Floor

    Software bills of materials were an IT idea. Now regulators want them for the controllers running the grid.

    26 May 2026 · 5 min read
  3. Water utility tabletop
    Interview · Series 041

    Inside a Water Utility's First Tabletop Exercise

    What a regional water authority learned when it finally war-gamed an attack on its treatment systems.

    25 May 2026 · 26 min watch
  4. Control-systems engineer interview
    Interview · Series 042

    The Engineer's Case Against the Air Gap

    A veteran control-systems engineer on why "just air-gap it" is a comforting myth, and what actually keeps a plant safe.

    24 May 2026 · 19 min watch
  5. Claroty xDome
    Press Release · Claroty

    Claroty Extends xDome to Building Management Systems

    The OT-security vendor brings asset discovery and risk scoring to HVAC, lifts, and access control.

    23 May 2026 · 3 min read
  6. KBKast episode artwork
    Podcast · KBKast Ep. 369

    When the Factory Floor Becomes the Attack Surface

    IT/OT convergence has erased the old perimeter. We unpack what defenders still get wrong about the plant.

    22 May 2026 · 41 min watch
  7. Purdue model
    Contributor

    The Purdue Model Is Dead. Long Live the Purdue Model.

    Cloud-connected plants broke the tidy layers of the reference architecture. It still beats the alternatives.

    21 May 2026 · 6 min read
  8. KBKast substation
    Podcast · KBKast Ep. 365

    The Substation That Phoned Home

    A maintenance laptop, a forgotten modem, and the quiet anatomy of a near-miss on the grid.

    20 May 2026 · 38 min watch
  9. Legacy PLCs
    Contributor

    Legacy PLCs and the Twenty-Year Patch Gap

    Half the controllers in heavy industry predate the threats now hunting them. Ripping them out is not an option.

    18 May 2026 · 5 min read
  10. Industrial CISO
    Interview · Series 040

    A CISO's View From the Floor of Heavy Industry

    Budgets, blame, and the long argument for treating safety and security as the same job.

    16 May 2026 · 21 min watch
  11. OT incident response
    Contributor

    Why Your IT Security Playbook Fails on the Plant Floor

    Patch Tuesday doesn't exist when downtime costs millions an hour. OT security needs its own rulebook.

    15 May 2026 · 5 min read
  12. Safety instrumented systems
    Contributor

    Why Safety Instrumented Systems Are the Real Crown Jewels

    When the last line of defence between a process and a disaster is networked, the threat model changes.

    13 May 2026 · 6 min read
  13. Dragos ransomware report
    Press Release · Dragos

    Dragos Reports Surge in Ransomware Against Manufacturing

    The ICS-security firm logs a record quarter of incidents targeting production environments.

    12 May 2026 · 4 min read
  14. Ransomware and OT
    Contributor

    Ransomware's Quiet Pivot to Operational Technology

    Crews worked out that a halted production line pays faster than encrypted email. The telemetry backs them up.

    10 May 2026 · 7 min read
  15. Remote access risk
    Contributor

    Remote Access Was Always the Soft Underbelly

    Every vendor VPN and jump box is a door. The pandemic propped most of them open and nobody closed them.

    08 May 2026 · 5 min read
  16. KBKast IT/OT
    Podcast · KBKast Ep. 363

    When the IT and OT Teams Finally Talk

    Two tribes, one plant. A conversation about the cultural gap that breaks more security programmes than any exploit.

    06 May 2026 · 44 min watch
  17. OT threat intelligence
    Contributor

    The Case for OT-Specific Threat Intelligence

    Generic IOCs miss the adversaries who actually study turbines and PLCs. Defenders need feeds that speak the language.

    02 May 2026 · 5 min read
  18. Nozomi Networks Labs report
    Press Release · Nozomi Networks

    Nozomi Networks Labs Finds Healthcare the Most-Targeted Industry in Australia

    New telemetry from the vendor's threat-research arm points to a sharp rise in attacks on connected medical and building systems.

    30 Apr 2026 · 4 min read