Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

IT/OT Security Weekly — August 2, 2026

Posted on August 2, 2026 by admini

August 2, 2026 · Weekly Edition

IT/OT Security Weekly

A coordinated cyberattack hit more than thirty Minnesota water utilities, turning the week’s abstract warnings about exposed PLCs into a live incident; CISA and SecurityWeek pushed urgent water-sector guidance and a fresh batch of Siemens and ABB ICS advisories; Europe moved against Russia’s Turla over destructive attacks on Poland’s grid while US agencies re-warned about Russian and Iranian targeting of control systems; and researchers showed new ways to disrupt power grids and critical systems without a traditional exploit. A week where the OT threat stopped being theoretical.

At a glance

The week’s defining event was on the ground in Minnesota. State and federal agencies confirmed a coordinated cyberattack against operational technology at more than thirty community water systems, hitting the automated controls that run treatment and distribution — some utilities briefly reverted to manual operation, and at least one took its plant offline as a precaution, though officials stressed drinking water remained safe and made no formal attribution. The incident was covered from three angles: The Record’s reporting on CISA’s warning of a spike in water-system attacks, Dark Reading’s look at what the intrusions expose about the sector’s risk, and SecurityWeek’s detailed account of the more-than-thirty affected utilities. It landed as the concrete instance of exactly the exposure defenders have been warning about — internet-reachable PLCs and cellular-connected remote sites — and CISA followed with an urgent July 30 alert urging water and wastewater operators to disconnect exposed controllers and lock down remote access.

The advisory machinery ran hot alongside it. CISA published a batch of Industrial Control Systems advisories (the ICSA-26-211 series) plus multiple Siemens SIMATIC bulletins — S7-PLCSIM Advanced, the S7-1500 CPU line, and Desigo CC — and an ABB KNX advisory, the steady drumbeat of vendor vulnerabilities that OT asset owners have to triage against the reality that patching a live controller is rarely simple. On the nation-state front, the pressure was explicit: the EU and UK moved against Russia’s Turla group over espionage and “destructive attacks,” tied to the earlier assault on Poland’s energy sector, and US agencies issued a fresh joint advisory warning that Russian FSB-linked actors are targeting network devices in critical infrastructure — while the foundational reading carries the updated CISA advisory (AA26-097A) on Iranian-affiliated exploitation of internet-connected PLCs across US critical infrastructure.

Two threads pointed at where the risk is heading. Dark Reading reported thousands of data-center controllers left open to takeover — the building-management and infrastructure layer that underpins the compute everything else now depends on — and CISA, with Australia’s ACSC, published joint guidance on isolating vital OT systems so operators can contain an incident and keep essential services running. The research in this week’s foundational set sharpens the horizon further: a “Bit2Watt” technique that could let cloud tenants disrupt power grids without a conventional exploit, 6 GHz Wi-Fi flaws that could disrupt critical systems, Iran’s widening target set beyond critical infrastructure, and the BusySnake infostealer working its way into critical-infrastructure networks. Taken together, it was the week the OT threat model stopped being a briefing slide and became an operations problem.

Topic map of this week's IT/OT Security themes

This week’s topic map — the coordinated Minnesota water-utility OT attacks and CISA’s urgent water-sector guidance, the ICS advisory batch (Siemens SIMATIC S7-PLCSIM/S7-1500/Desigo CC, ABB KNX, the ICSA-26-211 series), nation-state pressure on critical infrastructure (Turla and the Poland grid attack, the Russian FSB/Cisco device-targeting advisory, the Iranian PLC campaign AA26-097A), OT exposure and the US–Australia isolation guidance, and the critical-infrastructure threat research (Bit2Watt, 6 GHz Wi-Fi flaws, Iran’s widening target set, BusySnake).

View interactive topic map →

Article index

Weekly News

Water-sector OT attacks

The week’s live incident: a coordinated attack on more than thirty Minnesota water utilities’ operational technology, and the urgent CISA guidance that followed.
Article Source Published
1. CISA warns of spike in attacks on water systems as Minnesota incidents probed The Record Jul 31, 2026
2. Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks Dark Reading Jul 30, 2026
3. Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks SecurityWeek Jul 29, 2026
4. CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs SecurityWeek Jul 30, 2026

CISA & ICS advisories

The week’s vendor-vulnerability drumbeat: a fresh CISA advisory batch plus multiple Siemens SIMATIC bulletins and an ABB KNX advisory for OT asset owners to triage.
Article Source Published
5. CISA Releases Industrial Control Systems Advisories (ICSA-26-211 series) CISA Jul 30, 2026
6. Siemens SIMATIC S7-PLCSIM Advanced (ICSA-26-209-03) CISA Jul 28, 2026
7. Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (ICSA-26-209-04) CISA Jul 28, 2026
8. Siemens Desigo CC (ICSA-26-209-01) CISA Jul 28, 2026
9. ABB KNX Update Tool (ICSA-26-209-07) CISA Jul 28, 2026

Nation-state activity against critical infrastructure

Explicit state pressure: Europe sanctioning Russia’s Turla over destructive grid attacks, and a fresh US warning that Russian actors are targeting critical-infrastructure network devices.
Article Source Published
10. Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ CyberScoop Aug 1, 2026
11. Officials warn defenders that Russian hackers are targeting network devices CyberScoop Aug 1, 2026

OT exposure & isolation guidance

Where the exposure is widening — data-center controllers left open to takeover — and the binational guidance on isolating vital OT to contain an incident.
Article Source Published
12. Thousands of Data Center Controllers Open to Takeover Dark Reading Jul 28, 2026
13. US, Australia Release OT Isolation Guidance for Critical Infrastructure SecurityWeek Jul 29, 2026

Foundational Reading

Critical-infrastructure threat research

The longer-horizon research shaping the OT threat model — new grid- and critical-system-disruption techniques, Iran’s widening target set, an infostealer reaching into critical-infrastructure networks, and the standing Iranian PLC advisory.
Article Source Published
14. New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit The Hacker News Jul 21, 2026
15. 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems Dark Reading Jul 14, 2026
16. Iran’s Cyber Crosshairs Focus Beyond Critical Infrastructure Dark Reading Jul 9, 2026
17. ‘BusySnake’ Infostealer Slithers Into Critical Infrastructure Networks Dark Reading Jul 6, 2026
18. Iranian-Affiliated Actors Exploit PLCs Across US Critical Infrastructure (AA26-097A) CISA Jul 22, 2026

Detailed write-ups

1. Minnesota: the OT attack stops being theoretical

The Record · Dark Reading · SecurityWeek · July 29–31, 2026

More than thirty Minnesota community water systems were hit in a coordinated cyberattack on their operational technology, and the incident is the concrete version of every warning the sector has absorbed for years. According to state and federal reporting, the attacks struck the automated control systems that run water treatment and distribution; several utilities activated contingency procedures and reverted to manual operation, and at least one city took its plant offline as a precaution, with officials emphasizing that drinking water remained safe and declining, for now, to formally attribute the activity. The recurring technical detail across accounts is the exposure of internet-reachable controllers and cellular-connected remote assets — water towers, lift stations and pump stations that phone home over links often overlooked in risk assessments — which is precisely the attack surface CISA has been urging the sector to eliminate.

CISA’s response was immediate and specific. Its July 30 alert reported a significant increase in threat actors targeting PLCs in the water and wastewater sector and urged operators to take three steps now: disconnect PLCs from the public internet and route any remote access through a monitored VPN or gateway, enable password protection and change default credentials, and allowlist remote access to known engineering assets — plus keep a clean PLC image on hand in case attackers lock operators out by changing a device password. For water utilities, most of them small and resource-constrained, the hard part is not knowing what to do but having the staff and budget to do it; the incident is the argument for prioritizing exposure reduction over every other line item, and for treating secondary cellular links as first-class attack surface rather than an afterthought.

Sources: The Record · Dark Reading · SecurityWeek (Minnesota) · SecurityWeek (CISA alert)

2. The ICS advisory drumbeat: Siemens, ABB, and the patch-triage reality

CISA · July 28–30, 2026

CISA’s advisory output kept its steady weekly cadence, publishing the ICSA-26-211 batch of Industrial Control Systems advisories alongside a cluster of Siemens SIMATIC bulletins — covering S7-PLCSIM Advanced, the S7-1500 CPU line, and the Desigo CC building-management platform — and an advisory for ABB’s KNX update tool. The specifics vary (denial-of-service conditions, authentication weaknesses, resource-handling flaws), but the operational significance is cumulative: these are the controllers, engineering tools and building systems that run plants and facilities, and each advisory adds to a patch backlog that OT teams cannot clear at IT speed.

The uncomfortable truth OT defenders live with is that “apply the patch” is rarely available on demand. A live PLC or building controller often cannot be taken down outside a scheduled maintenance window, vendor-validated fixes lag disclosure, and some affected devices will never receive a patch at all. That is why CISA’s advisories pair vulnerability details with compensating controls — network segmentation, minimizing internet exposure, restricting access to known engineering systems — and why the practical posture for asset owners is to treat these bulletins as a prioritization input against exposure and criticality rather than a patch-now list. The advisories that matter most this week are the ones affecting devices that are both internet-reachable and safety-relevant; those are where the compensating controls need to go in immediately, patch window or not.

Sources: CISA (ICSA-26-211 series) · Siemens S7-PLCSIM · Siemens S7-1500 · Siemens Desigo CC · ABB KNX

3. Nation-state pressure gets explicit: Turla, Russian device targeting, and Iranian PLC exploitation

CyberScoop · CISA · July 22–August 1, 2026

The geopolitical layer of the OT threat moved from background to foreground. CyberScoop reported that the EU and UK took action against Russia’s Turla group over espionage and “destructive attacks,” tied to the earlier assault on Poland’s energy sector — the incident in which adversaries reached OT through vulnerable internet-facing edge devices and deployed destructive tooling that damaged remote terminal units and wiped human-machine-interface data across dozens of renewable and heat-generation sites. In parallel, US agencies issued a fresh joint advisory warning defenders that Russian FSB-linked actors are actively targeting network devices in critical infrastructure — the routers, firewalls and edge appliances that sit between IT and OT and, once compromised, become the pivot into control-system networks.

The Iranian thread runs alongside it in this week’s foundational reading: CISA’s updated advisory AA26-097A documents Iranian-affiliated actors exploiting internet-connected PLCs — Rockwell, Schneider and Siemens devices — across US water, energy and government facilities, manipulating project files and HMI/SCADA displays and, in some cases, causing operational disruption. Read together, the three sources describe a consistent adversary playbook: reach OT through exposed edge and network devices, then interact directly with controllers. The defensive implication is unambiguous and reinforces the water-sector guidance — the edge and the network layer are the battleground, so removing internet-facing OT, hardening and monitoring network devices, and verifying controller logic against trusted baselines are the controls that actually blunt this class of attacker.

Sources: CyberScoop (Turla) · CyberScoop (Russian device targeting) · CISA (AA26-097A)

4. Widening exposure — and a playbook for containment

Dark Reading · SecurityWeek · July 28–29, 2026

Two stories framed both the problem and the response. Dark Reading reported that thousands of data-center controllers — the building-management and infrastructure systems that keep facilities powered and cooled — are exposed and open to takeover. It is an easy category to overlook because it sits between traditional IT and traditional OT, but it is load-bearing in the most literal sense: as data centers become the backbone of the AI build-out, their environmental and power controllers are critical infrastructure in their own right, and an attacker who can manipulate cooling or power sequencing can cause physical disruption without ever touching a server.

The counterpart was a concrete defensive playbook. CISA, with Australia’s ACSC, published joint guidance on isolating vital OT and enabling systems — the capability to cut critical operational technology off from other networks to contain an active incident and keep essential services running. That directly matches what Minnesota’s utilities needed in practice: the ability to fall back to a known-safe, isolated mode of operation when the automated layer is compromised. For OT operators the guidance is a useful checklist for a control they may not have exercised — segmentation and isolation as an incident-response capability, tested before it is needed, not improvised during a live event. The pairing captures the week’s throughline: the exposure is widening faster than most programs are maturing, and the near-term priority is the ability to contain and keep operating rather than to prevent every intrusion.

Sources: Dark Reading · SecurityWeek

5. Foundational research: new disruption paths and a widening target set

The Hacker News · Dark Reading · July 6–21, 2026

This week’s foundational reading extends the threat model past the current incidents. The Hacker News detailed “Bit2Watt,” a technique that could let cloud tenants disrupt power grids without a conventional exploit — manipulating aggregate power draw in shared data-center environments to induce grid-level effects, a novel bridge between the cloud and the physical grid that does not fit existing detection models. Dark Reading covered 6 GHz Wi-Fi flaws with the potential to disrupt critical systems, a reminder that the wireless expansion into industrial environments brings its own disruption surface, and separately reported on Iran widening its cyber crosshairs beyond critical infrastructure — a signal that target selection is broadening even as the critical-infrastructure focus persists.

Dark Reading’s account of the BusySnake infostealer working into critical-infrastructure networks grounds the research back in present operations: information-stealing malware inside OT-adjacent IT environments is how many of these intrusions begin, harvesting the credentials and network knowledge that make the eventual control-system access possible. For OT security teams the collective value of the foundational set is horizon-scanning — the disruption techniques that do not yet have signatures (Bit2Watt), the expanding wireless and IT/OT-boundary surface (6 GHz Wi-Fi, BusySnake), and the shifting intent of the most active state actors (Iran’s widening set). None require action this week, but all belong in the risk register that shapes next year’s OT security investment.

Sources: The Hacker News (Bit2Watt) · Dark Reading (6 GHz Wi-Fi) · Dark Reading (Iran) · Dark Reading (BusySnake)

On our watch list

  • Minnesota attribution and scope. Watching whether investigators attribute the water-utility attacks, whether the count of affected systems grows, and whether the same actor moves to other states’ utilities.
  • Water-sector exposure reduction. Watching whether CISA’s urgent guidance actually moves small utilities to disconnect exposed PLCs and secure cellular links — and how the funding gap for under-resourced operators gets addressed.
  • Edge and network-device targeting. After the Russian FSB advisory, watching for active exploitation of the IT/OT-boundary devices (routers, firewalls, VPNs) adversaries use to pivot into control systems.
  • Iranian PLC campaign progression. Watching whether AA26-097A activity expands to more vendors and sectors, and whether any incident moves from targeting to confirmed operational impact.
  • Data-center controller exposure. Watching whether the exposed building-management systems get remediated as data centers scale for AI — and whether an attacker weaponizes cooling/power control.
  • OT isolation in practice. Watching whether the US–Australia isolation guidance translates into operators actually testing fallback-to-isolated modes before an incident forces it.
  • Novel grid-disruption research. Watching whether Bit2Watt-style, exploit-free disruption techniques move from research to real-world attempts as data-center power demand keeps climbing.

IT/OT Security Weekly

A weekly intelligence bulletin from Security Radar LLC.
Curated by Paul Davis · paul.davis@security-radar.com

© 2026 Security Radar LLC. All rights reserved.

Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.

*|LIST:ADDRESS|*

View this email in your browser · Unsubscribe

Recent Posts

  • Security Operations Weekly — August 2, 2026
  • Security Operations Weekly — August 2, 2026 — Interactive Topic Map
  • IT/OT Security Weekly — August 2, 2026

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • Competitive
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • IT/OT Security
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme