Critical Cybersecurity Updates for Transportation Stakeholders
9/9/2026

FTA is urging public transit agencies and operational technology operators to review certain updates from the Cybersecurity and Infrastructure Security Agency (CISA), including a new Gold Eagle AI Clearinghouse initiative.
CISA and Treasury Launch the Gold Eagle AI Clearinghouse
In support of Executive Order 14409, CISA and the Department of the Treasury launched Gold Eagle AI Clearinghouse, a software capability that augments the Vulnerability Information and Coordinated Environment (VINCE) platform.
Gold Eagle lets organizations report, validate, and track AI-related vulnerabilities at scale. It ensures CISA can quickly review and process reports and avoid duplicate efforts while helping researchers and vendors identify and fix vulnerabilities safely.
Industry partners interested in collaborating, innovating, and making a real impact are encouraged to reach out via clearinghouse@cisa.dhs.gov to get started.
CISA and Partners Issue Joint Cybersecurity Advisory on Siemens S7 Series PLCS
CISA, the National Security Agency (NSA), and partners released a joint advisory, Defending Against an Active Threat to Siemens S7 Series PLCs, which warns of threat activity targeting Siemens S7 series programmable logic controllers (PLCs). Threat actors are conducting reconnaissance and capability development against U.S. based Siemens PLCs using AI-generated scripts disguised as legitimate monitoring tools.
Organizations should also assess exposures across all PLCs and operational technology devices, as broader risk extends beyond Siemens products to other manufacturer devices.
New Industrial Control Systems (ICS) Advisories
CISA released three new ICS advisories regarding current security issues, vulnerabilities, and exploits:
- ICSA-26-230-01: CISA Malcolm
- ICSA-26-230-02: Siemens Simcenter Nastran
- ICSA-26-232-01: Johnson Controls Simplex Incident Manager
Stakeholder questions should be directed to Dot-Sector-Cyber@dot.gov.