At a glance
The water sector is this week’s throughline, and it is escalating rather than resolving. SecurityWeek and The Record independently confirmed the campaign first reported in Minnesota has now touched at least twelve states, with The Record naming South Dakota and Georgia as newly affected and reporting an Iran-linked actor behind at least part of the activity — the first time this run of intrusions has carried an explicit attribution. Layered on top of that, a Forescout internet-exposure scan found thousands of Rockwell/Allen-Bradley controllers still reachable from the open internet, the same class of exposed PLC that CISA has been warning water utilities to disconnect for months. Federal warnings and a widening attack count are colliding with an exposure problem that has not meaningfully shrunk. The one piece of good news: New York put money behind the fix, awarding $9M in SECURE program grants to strengthen cybersecurity at 153 water systems — a direct, if partial, answer to the funding gap that keeps small utilities from acting on the guidance they already have.
The OT risk lens widened past water this week, too. SecurityWeek reported that a safety recall for Bendix’s EC80 truck brake controller doubled as a hidden security fix, with research tied to the National Motor Freight Traffic Association’s (NMFTA) heavy-vehicle cybersecurity program surfacing at Black Hat — a reminder that safety-critical embedded controllers on the road carry the same exposure risk as controllers on the plant floor, often disclosed through channels that do not say “security” out loud. Separately, SecurityWeek covered a decades-old vulnerability in Baseboard Management Controllers using the IPMI protocol, leaving thousands of data centers exposed to remote compromise of the physical hardware layer underneath the compute everyone now depends on.
The foundational reading closes the loop on both threads. A Nozomi Networks CEO op-ed in CyberScoop argues the water sector’s “wake-up call” has now sounded more than once without producing durable change, and SecurityWeek’s account of the cyberattack that disrupted operations at Japanese frozen-food giant Nichirei is the manufacturing-sector reminder that OT disruption is not confined to critical infrastructure with a regulator standing behind it — it is a risk to any operator running automated production. Together, this week’s items argue the same point from four different sectors: exposure reduction is the unglamorous, unfinished work, and every week without it widens the gap between the warnings and the incidents.
This week’s topic map — the water-sector campaign’s expansion to 12 states with an Iran-linked actor named, the Forescout scan of exposed Rockwell/Allen-Bradley controllers, New York’s SECURE grants for 153 water systems, the Bendix EC80 truck-brake security fix tied to NMFTA and Black Hat, the decades-old BMC/IPMI vulnerability exposing data centers, and the foundational Nozomi Networks op-ed and Nichirei manufacturing incident.
View interactive topic map →
Article index
Weekly News
Water-sector campaign expands to 12 states
The week’s dominant thread: the water-sector attack count grows to twelve states with an Iran-linked actor named, a Forescout scan shows exposure has not closed, and New York funds part of the fix.
OT risk beyond the water sector
Two reminders that the exposure problem isn’t confined to water: a safety-critical truck controller and a decades-old server-management flaw.
Foundational Reading
Sector wake-up calls
Two reminders, from water and from manufacturing, that the “wake-up call” keeps sounding without durable change following it.
Detailed write-ups
1. Water-sector attacks expand to 12 states, with an Iran-linked actor now named
SecurityWeek · The Record · August 5, 2026
The water-sector campaign that first surfaced in Minnesota has widened in both scope and attribution. SecurityWeek reported the attack count has reportedly reached at least twelve states, and The Record’s independent reporting named two of the newly affected states — South Dakota and Georgia — while attributing at least part of the activity to an Iran-linked actor. That is a meaningful shift from the earlier coverage, which stopped short of formal attribution; it moves the story from “coordinated attacks of unclear origin” to a nation-state-linked campaign against operational technology in a sector with some of the weakest and most unevenly resourced defenses in critical infrastructure.
The twelve-state figure also reframes the scale question. What began as a Minnesota-specific incident now reads as a broader, geographically distributed campaign against water utilities’ PLCs and remote-access infrastructure — consistent with the exposure pattern CISA has been warning about since the initial Minnesota reporting. For defenders, the attribution detail matters less than the trend line: the count of affected states is growing week over week, and the attack surface (internet-reachable PLCs, cellular-connected remote sites) that enabled the original intrusions has not visibly closed in the time since.
Sources: SecurityWeek · The Record
2. Forescout: the exposure hasn’t closed — thousands of Rockwell/Allen-Bradley controllers still online
CyberScoop · August 6, 2026
An internet-exposure scan from Forescout, reported by CyberScoop, found that despite months of federal warnings tied to the water-sector attacks, thousands of Rockwell/Allen-Bradley controllers remain reachable directly from the public internet. This is the exposure the entire week’s water-sector coverage keeps returning to: it is the same class of internet-facing PLC that CISA has repeatedly urged utilities to disconnect, and the scan is hard evidence that the guidance has not translated into remediation at scale.
For a sector made up largely of small, resource-constrained utilities, the finding underscores why exposure reduction keeps stalling — it is not a knowledge gap, it is a staffing-and-budget gap. Every additional state added to the attack count and every controller the Forescout scan finds still exposed argues for treating this as the single highest-leverage fix available to the sector, ahead of any more sophisticated control.
Sources: CyberScoop
3. New York funds part of the fix: $9M for 153 water systems
SecurityWeek · August 4, 2026
New York announced $9M in grants under its SECURE program to strengthen cybersecurity at 153 water systems across the state, SecurityWeek reported. It is a direct, state-level answer to the funding gap that the Forescout exposure data and the CISA guidance both point back to — small water utilities generally know what they should do (disconnect exposed PLCs, lock down remote access, segment networks) but often lack the budget and staff to do it.
The grant program is worth watching less for its size than for whether it becomes a template. If New York’s approach — targeted state funding tied to specific security improvements at named utilities — produces measurable exposure reduction, it is a model other states can point to when the federal picture on infrastructure funding remains uncertain. If it does not move the needle, that itself is useful evidence about how much funding this problem actually requires.
Sources: SecurityWeek
4. OT risk beyond the tap: Bendix truck brakes and a decades-old BMC flaw
SecurityWeek · August 4–7, 2026
Two stories this week showed the OT exposure problem is not confined to water utilities. SecurityWeek reported that a safety recall for Bendix’s EC80 truck brake controller doubled as a hidden security fix, with research tied to the National Motor Freight Traffic Association’s (NMFTA) heavy-vehicle cybersecurity program surfacing around Black Hat. Safety-critical embedded controllers in commercial trucking sit in the same exposure category as controllers on a plant floor — and when a security fix rides in on a safety recall rather than a disclosed advisory, it is easy for fleet operators to miss that a security issue was addressed at all.
Separately, SecurityWeek covered a decades-old vulnerability in Baseboard Management Controllers running the IPMI protocol, leaving thousands of data centers exposed to remote compromise of the physical hardware layer beneath the compute stack. As data centers scale to meet AI-driven demand, the management interfaces that control power, cooling and remote hardware access are becoming critical infrastructure in their own right — and this is now the second consecutive week this bulletin has covered exposed data-center controllers as a distinct OT risk category.
Sources: SecurityWeek (Bendix EC80) · SecurityWeek (BMC/IPMI)
5. Foundational: the water sector’s wake-up call, and a reminder from Nichirei
CyberScoop · SecurityWeek · July 17 & August 6, 2026
This week’s foundational reading closes the loop on the water-sector story and broadens it to manufacturing. In a CyberScoop op-ed, Nozomi Networks’ CEO argues that the water sector’s “wake-up call” has now sounded more than once — the sector keeps absorbing warnings and incidents without the durable investment and staffing needed to act on them, a point this week’s twelve-state expansion and still-exposed Rockwell controllers make concrete rather than rhetorical.
SecurityWeek’s account of the cyberattack that disrupted operations at Japanese frozen-food giant Nichirei extends the same lesson outside critical infrastructure entirely. Manufacturing operators running automated production lines face the same OT disruption risk as a water utility or an energy grid, without a regulator or a CISA advisory series standing behind them. Read alongside this week’s twelve-state water campaign and the Bendix and BMC items, the foundational set argues that OT exposure is now a cross-sector operating risk, not a critical-infrastructure-specific one.
Sources: CyberScoop (Nozomi op-ed) · SecurityWeek (Nichirei)
On our watch list
- Water-sector attack count. Watching whether the twelve-state figure keeps growing, whether more states are named, and whether the Iran-linked attribution firms up or expands to additional actors.
- Rockwell/Allen-Bradley exposure reduction. Watching whether the Forescout findings move utilities and asset owners to actually take exposed controllers offline — the single highest-leverage fix available to the sector.
- SECURE grant outcomes. Watching whether New York’s $9M in water-system grants produces measurable security improvements, and whether other states adopt a similar targeted-funding model.
- Heavy-vehicle controller security. Watching whether more safety recalls in trucking and other embedded-controller domains turn out to carry undisclosed security fixes, and whether NMFTA’s program gains broader adoption.
- Data-center BMC/IPMI exposure. Watching whether the decades-old vulnerability gets patched at scale as data-center capacity keeps expanding for AI workloads.
- Cross-sector OT risk. Watching whether more manufacturing and non-critical-infrastructure operators report OT disruption incidents like Nichirei’s, signaling the risk model needs to widen beyond regulated sectors.
|