LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day
patchcritical

Even with OT network visibility, critical infrastructure operators struggle with legacy equipment

A recent survey of over 1,600 security and operations leaders in critical infrastructure organizations reveals that despite widespread adoption of security tools, many operators still lack full visibility into their operational technology (OT) networks and struggle with the risks posed by legacy equipment. The study, conducted by Palo Alto Networks, highlights a significant challenge in…

ZeroDay News ·

Source: Help Net Security

A recent survey of over 1,600 security and operations leaders in critical infrastructure organizations reveals that despite widespread adoption of security tools, many operators still lack full visibility into their operational technology (OT) networks and struggle with the risks posed by legacy equipment. The study, conducted by Palo Alto Networks, highlights a significant challenge in securing critical infrastructure, where decades-old OT systems are increasingly connected to modern networks without adequate security model updates.

The survey found that, on average, large critical infrastructure operators utilize seven distinct security tools. However, this proliferation of tools often complicates operations, with 59% of respondents reporting increased complexity and 56% noting higher operating costs. More than half of the organizations still rely on standard severity scores or manual processes to triage security alerts.

A primary concern identified by 52% of respondents is the presence of legacy OT equipment, which hinders network visibility. Furthermore, 42% consider unpatchable legacy equipment to be their greatest cybersecurity risk. Even among the 49% of respondents who believe they have complete network visibility, legacy OT remains a significant challenge, indicating that simply knowing an asset exists does not address its software vulnerabilities.

The past year saw a high incidence of security breaches, with 59% of organizations experiencing at least one significant incident, and one in five reporting multiple breaches. These incidents frequently have safety implications, cited by half of the respondents, and result in substantial financial losses due to unplanned downtime, averaging $288,563 per hour. While containment times are improving, only 15% of organizations currently resolve incidents within minutes through automation, an increase from 10% a year prior. Fifty-one percent aim to achieve this level of rapid containment within the next 12 months.

Looking ahead, there is considerable apprehension regarding advanced AI-powered attacks, with 95% of respondents expressing concern about "Frontier AI." Concurrently, 91% anticipate that AI-driven security tools will be crucial for defense. However, AI adoption in security is still nascent; only 19% of organizations use AI across four or more operational areas, and this figure includes applications beyond security, such as process optimization and predictive maintenance.

Another persistent issue is the lack of integration between IT and OT security operations, with 74% of organizations reporting separate functions. Among these, 44% attribute the divide to incompatible technology, and an equal percentage point to differing priorities between IT and OT teams. Automated alert correlation is seen as the most impactful solution for bridging this gap, with 52% of respondents identifying it as the key to accelerating IT and OT convergence over the next two years.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Android’s October 2026 Updates Patch 25 Vulnerabilities

Android’s October 2026 security updates have addressed a total of 25 vulnerabilities across the platform. Among these, a critical flaw within Android’s System component has been highlighted, which could potentially allow for privilege escalation on affected devices. The updates are designed to enhance the overall security posture of Android devices by resolving these identified weaknesses.

vulnerabilitycritical

Atlassian Patches Critical Vulnerability Affecting 8 Products

Atlassian has released patches for a critical vulnerability impacting eight of its products. The flaw, if exploited, could allow unauthenticated attackers to gain access to specific files located within the web application's root directory. This type of access could potentially expose sensitive configuration or application data, depending on the contents of the accessible files.

vulnerability

OpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing

The OpenSSH project released version 10.6 on October 6, introducing a new hybrid post-quantum signature algorithm and addressing several security vulnerabilities. The maintainers indicated that future releases may occur more frequently to expedite bug fixes, noting a rise in security reports, many identified with the assistance of AI models.

CVE-2026-93524

Check your X.Org server version because a dozen vulnerabilities have been patched

X.Org has released patches for a dozen security vulnerabilities affecting its X server and Xwayland components, with updates available in versions xorg-server 21.1.25 and xwayland-24.1.14. Nine of these flaws are critical, potentially allowing for arbitrary code execution, while the remaining three could lead to server crashes or information disclosure.

ai

AI Agent Gateway: Open-source tool keeps credentials out of agent configs

Tuskira has released AI Agent Gateway, an open-source tool designed to enhance the security of AI agent deployments by centralizing credential management and access control. The gateway operates as an intermediary between AI agents and the services they interact with, including both tool servers (referred to as MCP tools) for platforms like GitHub and Jira, and various large language model…

nation-state

AI endpoint management: Visibility, compliance, and remediation

Organizations today face a growing challenge in managing their endpoint estates, which are expanding rapidly due to factors like hybrid work models, increased cloud adoption, and the use of contractor devices. This expansion, coupled with a constant stream of new Common Vulnerabilities and Exposures (CVEs) and escalating compliance demands, often overwhelms security teams. Manual tracking and…