Halil, with one emergency window and thin staffing, I would not try to “patch everything.” I’d sequence it like this: isolate first, patch second, hunt before and after. Tonight’s isolation list is internet-exposed PLC/HMI assets first, then internet-facing PTC Windchill/FlexPLM, then any Windows systems exposed to the BlueHammer / Microsoft Defender CVE-2026-33825 risk. The OT call is not theoretical: the reporting says Iranian-affiliated actors are exploiting exposed PLCs and manipulating HMI displays, including Rockwell CompactLogix and Micro850 environments. Pull those systems off direct internet access, block inbound engineering access, force access through a controlled jump host/VPN, and preserve current controller logic/project files before anyone “fixes” anything.
For the patch window: CRITICAL tonight is BlueHammer-affected Microsoft Defender/Windows estate on domain controllers, EDR management servers, backup servers, file servers, and internet-facing Windows hosts — not the full 570-flaw Microsoft wave. Treat the July Microsoft release as a prioritization problem: patch the exploited Defender issue and high-value Windows choke points first, then schedule the rest. For PTC Windchill/FlexPLM, if a tested vendor patch is already staged, apply it after evidence capture; if not, isolate and apply vendor-recommended web-layer blocking until a smoke-tested patch is ready. Hunt PTC before patching for suspicious webshell artifacts already reported in prior PTC activity — GW.class, payload.bin, and dpr_<random>.jsp — plus odd servlet access, new JSP/class files, abnormal outbound connections, and new admin accounts. After patching, repeat the same hunt because patching does not remove a webshell or stolen session.
Evidence to preserve before changes: full disk or targeted forensic collection from PTC app/web servers, IIS/Apache access/error logs, Windchill/FlexPLM app logs, WAF/proxy logs, EDR timelines, Microsoft Defender event logs, domain authentication logs, firewall/VPN logs, and for OT, PLC logic snapshots, HMI project backups, engineering workstation logs, and packet captures from the OT boundary if available. Today: isolate PLC/HMI and PTC exposure, patch BlueHammer priority Windows systems, capture evidence. This week: finish the Microsoft 570-flaw wave by asset criticality, patch remaining PTC after staging, and validate no persistence remains. Schedule: OT architecture cleanup — no direct internet path to PLCs or HMIs.