Dark Reading highlights a critical Telnet server vulnerability affecting operational environments, enabling attackers to exploit neglected legacy systems in ICS/OT networks.
Date: Jan 27, 2026 • Source: Dark Reading [darkreading.com]
2. New: Sandworm blamed for destructive wiper attack on Polish power grid
Summary: Sandworm/Electrum hacking group targeted ICS communication and control systems at 30 sites, wiping systems and demonstrating escalating OT‑focused nation‑state capabilities.
Date: Jan 26, 2026 • Source: Dark Reading [darkreading.com]
3. New: RondoDox botnet weaponizes React2Shell to compromise IoT devices
Summary: A nine‑month campaign targets IoT devices via React2Shell (CVSS 10.0) to enroll tens of thousands of exposed IoT assets into the RondoDox botnet. U.S. has most vulnerable instances.
Date: Jan 5, 2026 • Source: The Hacker News [thehackernews.com]
4. New: ICS default credentials exploited in destructive attack on Polish energy facilities
Summary: Attackers exploited factory‑default ICS credentials, destroying devices and reinforcing the need for rigorous credential hygiene and OT hardening practices.
Date: Feb 2, 2026 • Source: SecurityWeek [securityweek.com]