Viakoo OT Security Roundup Flags Exploited Flaws and Credential Risks
The September 27, 2026 OT security roundup covers ongoing exploitation of unpatched network and application flaws. It also notes broad credential exposure that could give attackers paths into operational systems. Government agencies are using AI-assisted defenses, though some AI-related attack claims have not been verified.
The roundup centers on active exploitation of unpatched network and application flaws. watchTowr reported two remote-code-execution zero-days in Citrix NetScaler ADC and Gateway appliances, said to be under exploitation and distinct from CVE-2026-19490. Citrix had not confirmed them or issued fixes at publication, and no affected versions, victims, indicators, or workarounds were identified.
Separately, Singapore’s Cyber Security Agency moved toward proactive hunting after UNC3886 struck four major telcos. It deployed AI-supported penetration testing and code review across roughly 2,000 government systems, while CSA and GovTech scan critical-infrastructure operators’ internet-facing systems and weigh broader use. The roundup also cites ShinyHunters exploiting a WAF bypass in Oracle PeopleSoft attacks.
These developments could affect organizations running operational technology, especially utilities, telecoms, and government services, because unpatched flaws and exposed credentials may provide paths from IT systems into OT. If attackers exploit those paths, disruptions could affect service availability or safety. AI-assisted defenses may help agencies find weaknesses faster, but unverified attack claims and unresolved vendor fixes mean defenders may face uncertainty. The broader public could feel impacts indirectly through outages or degraded critical services.