The Human Take
Critical Infrastructure. Operations Technology / Information Technology. PLC and HMI exploits.
This is… Well… This is Cyber… And A Whole Lot More!
- Water Plants
- Manufacturing
- Powergrid
- E911 and Emergency Response
- Pipelines
- Transportation
Nation States actively target critical infrastructure on an hourly basis. Critical infrastructure brings in another area of Cybersecurity protection, Operations Technology. Not as well-known as its close relation, Information Technology. But every bit as vital and carries the well-earned label “critical”.
Operations Technology is
“Programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems/devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems, building management systems, fire control systems, and physical access control mechanisms.” Risk Management Framework for Information Systems and Organizations A NIST System Life Cycle Approach for Security and Privacy, 2018.
Yesterday, record rainfall fell in the Omaha, Bellevue, and Lincoln Nebraska area. Emergency response, water and sanitation, pipelines, transportation (trains, interstate, and metro) and manufacturing were all stressed by the flooding. Protecting Critical Infrastructure and OT matters at all times, severe weather magnifies the importance.
Bellevue University Cybersecurity actively supports and are members of InfraGard – a thirty-year collaboration among the US FBI, affiliated law enforcement agencies, business, critical infrastructure practitioners and educators. Protecting critical infrastructure is a shared responsibility.
Our Weekly Summary for October 1, 2026, highlights State Sponsored Threats and Zero-Day Exploits. Dig in. If this is an area that you want to learn more about, engage in, reach out to us. Interested in InfraGard? Watch the video below and explore membership via the link.
Weekly Cyber News Summary October 1, 2026
This week in cyber:- Nation-states actively target critical infrastructure and civilian networks globally.
- Cisco’s SD-WAN and Citrix NetScaler suffer critical zero-day exploits.
State-Sponsored Attacks
Active Zero-Day Exploits in Cisco SD-WAN Manager
A critical zero-day vulnerability, tracked as CVE-2026-76504, has been found in the Catalyst SD-WAN Manager from Cisco. This flaw allows attackers to bypass authentication mechanisms and escalate their privileges to administrative levels within the network.
Security briefings confirm that this vulnerability is not theoretical; attackers are actively exploiting it in the wild. Cisco has released necessary security updates, urging organizations to patch their devices immediately to mitigate the risk of unauthorized access and network takeover.
Sources:InfosecNexus Live Brief: https://infosecnexus.com/live-cybersecurity-brief/
BleepingComputer: https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/
Zero-Day Exploits/CVEs
Cisco SD-WAN Zero-Day is Actively Exploited in Attacks
A critical zero-day vulnerability, CVE-2026-76504, has been identified in Cisco’s Catalyst SD-WAN Manager. This flaw is an authentication bypass that allows attackers to escalate their privileges to full administrative rights.
Security analysts confirm that this exploit is not just theoretical; it is being actively leveraged in the wild. Cisco has issued immediate security updates, making prompt patching essential for organizations running this infrastructure.
Sources:BleepingComputer: https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/
InfosecNexus Live Brief: https://infosecnexus.com/live-cybersecurity-brief/
Citrix NetScaler Zero-Days Enable Remote Code Execution
Two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affect Citrix NetScaler devices. These flaws allow for Remote Code Execution (RCE), meaning an attacker can run arbitrary code on the server.
Unit 42 and other sources confirm these flaws are being exploited in real-world attacks. Citrix has issued fixes, and these CVEs were added to the CISA KEV catalog, signaling their immediate threat level.
Sources:Cybersecurity News: https://cybersecuritynews.com/citrix-netscaler-0-day-rce-2/
Unit 42 Palo Alto Networks: https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/








