Ransomware attacks on manufacturers increased 40% in early 2026 as attackers exploit supply chain vulnerabilities and gaps in incident response. SMBs in manufacturing must act immediately to implement offline backups, segment networks, and establish recovery procedures before an attack hits operations.
Cisco ISE Under Active Attack, DNS Servers Need Urgent Patches, September 17th, 2026
Cisco has confirmed active exploitation of a critical vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) with a CVSS score of 10.0. The authentication bypass flaw allows attackers to gain unauthorized access without credentials. Cisco urges immediate patching and log review.
Two major DNS security updates require immediate attention: BIND 9 has patched 14 vulnerabilities that enable cache poisoning, remote crashes, and resource exhaustion. Unbound DNS resolver versions before 1.26.1 contain a critical heap overflow (CVE-2026-81642) in the DNSSEC validator that allows remote code execution when an attacker controls a malicious DNS zone.
Ransomware attacks on manufacturers increased 40% in early 2026 as attackers exploit supply chain disruptions. Manufacturers should implement offline backups, network segmentation, and recovery procedures.
North Korean IT workers are using AI and remote desktop tools to impersonate candidates during technical interviews, gaining employment to access systems and funnel payments to fund the regime. Organizations should strengthen identity verification and require in-person onboarding for sensitive roles.
RatHat, a new Chinese-made Android malware, uses AI to steal financial data including banking credentials and 2FA codes. The spyware has backdoor capabilities and is distributed through fake applications.
CISA released guidance "Using Cyber Decoys to Strengthen Detection and Response" recommending organizations deploy fake credentials, systems, and files (honeypots) to detect attackers who breach networks using legitimate credentials rather than malware.
Why ransomware attacks manufacturers are accelerating and what you must do first
Manufacturers face a compounding threat: attackers know supply chain disruptions create operational pressure and force faster ransom decisions. CISA's September 2026 guidance on using honeypots (fake credentials and systems) shows attackers often enter through legitimate credentials, not just malware. For a manufacturing SMB, this means your recovery plan must start now. Step one: create offline backups stored physically separate from your network. Step two: segment your OT (operational technology) systems from IT systems so a breach in one does not cascade. Step three: document your incident response chain of command before you need it. Cisco's ISE vulnerability (CVE-2026-76460) and DNS flaws in BIND and Unbound DNS demonstrate that attackers chain vulnerabilities to move laterally. Patch DNS servers and authentication systems this week. Test your recovery plan quarterly.
Key takeaways
- Offline backups must be physically disconnected; store copies off-site to survive ransomware encryption.
- Network segmentation isolates OT systems from IT so production lines keep running even if office systems are locked.
- Document and test your incident response plan now, including who calls law enforcement, who pays bills during downtime, and how you communicate with customers.
- Patch Cisco ISE, BIND, and Unbound DNS resolvers immediately; these are entry points attackers exploit to move inside your network.
Frequently asked questions
What should we do if ransomware locks our systems?
Stop. Do not pay the ransom immediately. Contact law enforcement (FBI IC3), preserve evidence (logs, malware samples), and activate your recovery plan using offline backups. Downtime costs money, but paying attackers without law enforcement involvement can expose you to sanctions if the attacker is on a government watchlist.
How often should we test our backups?
Test recovery from offline backups at least quarterly. Restore a sample of files to a test system, verify they open correctly, and time how long a full recovery takes. This reveals gaps in your procedure before you face actual downtime.
Are we at risk if we use DNS servers like BIND or Unbound?
Yes, if you have not patched. BIND 9 has 14 new flaws that allow attackers to crash DNS or poison cached results. Unbound before 1.26.1 has a heap overflow that allows remote code execution. Patch this week and verify with your IT vendor or provider that the update was applied.
What is network segmentation and why does it matter?
Segmentation means your production systems, office computers, and customer data live on separate networks with controlled access between them. If an attacker breaches email, they cannot immediately reach your machinery or inventory database. This buys time to isolate the breach and restore operations.
Sources
- https://www.infosecurity-magazine.com/news/cisco-active-exploitation-critical/
- https://cybersecuritynews.com/cisco-warns-of-critical-ise-0-day-vulnerability-exploited/
- https://cybersecuritynews.com/bind-dns-servers-hit-by-14-security-flaws/
- https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/
- https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html
- https://www.securityweek.com/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows/
- https://cybersecuritynews.com/north-korean-it-workers-2/
- https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/
- https://cybersecuritynews.com/cisa-fake-credentials-catch-hackers/
- https://www.infosecurity-magazine.com/news/cisa-critical-infrastructure-cyber/