Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

IT/OT Security Weekly — August 9, 2026

Posted on August 9, 2026 by admini

August 9, 2026 · Weekly Edition

IT/OT Security Weekly

The water-sector campaign that surfaced two weeks ago kept widening: SecurityWeek and The Record both put the count of affected states at twelve, with South Dakota and Georgia newly named and an Iran-linked actor now in the frame, while a Forescout scan found thousands of Rockwell/Allen-Bradley controllers still sitting exposed online despite months of federal warnings. New York put real money behind the problem with $9M in SECURE grants for 153 water systems. And the OT risk lens widened further still — a Bendix truck-brake controller’s safety recall doubled as a hidden security fix, and a decades-old BMC vulnerability left thousands of data centers exposed. A thin week in volume, a heavy one in signal.

At a glance

The water sector is this week’s throughline, and it is escalating rather than resolving. SecurityWeek and The Record independently confirmed the campaign first reported in Minnesota has now touched at least twelve states, with The Record naming South Dakota and Georgia as newly affected and reporting an Iran-linked actor behind at least part of the activity — the first time this run of intrusions has carried an explicit attribution. Layered on top of that, a Forescout internet-exposure scan found thousands of Rockwell/Allen-Bradley controllers still reachable from the open internet, the same class of exposed PLC that CISA has been warning water utilities to disconnect for months. Federal warnings and a widening attack count are colliding with an exposure problem that has not meaningfully shrunk. The one piece of good news: New York put money behind the fix, awarding $9M in SECURE program grants to strengthen cybersecurity at 153 water systems — a direct, if partial, answer to the funding gap that keeps small utilities from acting on the guidance they already have.

The OT risk lens widened past water this week, too. SecurityWeek reported that a safety recall for Bendix’s EC80 truck brake controller doubled as a hidden security fix, with research tied to the National Motor Freight Traffic Association’s (NMFTA) heavy-vehicle cybersecurity program surfacing at Black Hat — a reminder that safety-critical embedded controllers on the road carry the same exposure risk as controllers on the plant floor, often disclosed through channels that do not say “security” out loud. Separately, SecurityWeek covered a decades-old vulnerability in Baseboard Management Controllers using the IPMI protocol, leaving thousands of data centers exposed to remote compromise of the physical hardware layer underneath the compute everyone now depends on.

The foundational reading closes the loop on both threads. A Nozomi Networks CEO op-ed in CyberScoop argues the water sector’s “wake-up call” has now sounded more than once without producing durable change, and SecurityWeek’s account of the cyberattack that disrupted operations at Japanese frozen-food giant Nichirei is the manufacturing-sector reminder that OT disruption is not confined to critical infrastructure with a regulator standing behind it — it is a risk to any operator running automated production. Together, this week’s items argue the same point from four different sectors: exposure reduction is the unglamorous, unfinished work, and every week without it widens the gap between the warnings and the incidents.

Topic map of this week's IT/OT Security themes

This week’s topic map — the water-sector campaign’s expansion to 12 states with an Iran-linked actor named, the Forescout scan of exposed Rockwell/Allen-Bradley controllers, New York’s SECURE grants for 153 water systems, the Bendix EC80 truck-brake security fix tied to NMFTA and Black Hat, the decades-old BMC/IPMI vulnerability exposing data centers, and the foundational Nozomi Networks op-ed and Nichirei manufacturing incident.

View interactive topic map →

Article index

Weekly News

Water-sector campaign expands to 12 states

The week’s dominant thread: the water-sector attack count grows to twelve states with an Iran-linked actor named, a Forescout scan shows exposure has not closed, and New York funds part of the fix.
Article Source Published
1. Water Sector Cyberattacks Reportedly Hit at Least 12 States SecurityWeek Aug 5, 2026
2. Cyberattacks on Water Systems Expand to 12 States; South Dakota, Georgia Named The Record Aug 5, 2026
3. Despite Federal Warnings, Thousands of Rockwell/Allen-Bradley Controllers Exposed Online CyberScoop Aug 6, 2026
4. New York Awards $9M to Strengthen Cybersecurity at 153 Water Systems SecurityWeek Aug 4, 2026

OT risk beyond the water sector

Two reminders that the exposure problem isn’t confined to water: a safety-critical truck controller and a decades-old server-management flaw.
Article Source Published
5. Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix SecurityWeek Aug 7, 2026
6. Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks SecurityWeek Aug 4, 2026

Foundational Reading

Sector wake-up calls

Two reminders, from water and from manufacturing, that the “wake-up call” keeps sounding without durable change following it.
Article Source Published
7. The Water Sector Just Got Its Wake-Up Call. Again. CyberScoop Aug 6, 2026
8. Cyberattack Disrupts Operations of Japanese Frozen-Food Giant Nichirei SecurityWeek Jul 17, 2026

Detailed write-ups

1. Water-sector attacks expand to 12 states, with an Iran-linked actor now named

SecurityWeek · The Record · August 5, 2026

The water-sector campaign that first surfaced in Minnesota has widened in both scope and attribution. SecurityWeek reported the attack count has reportedly reached at least twelve states, and The Record’s independent reporting named two of the newly affected states — South Dakota and Georgia — while attributing at least part of the activity to an Iran-linked actor. That is a meaningful shift from the earlier coverage, which stopped short of formal attribution; it moves the story from “coordinated attacks of unclear origin” to a nation-state-linked campaign against operational technology in a sector with some of the weakest and most unevenly resourced defenses in critical infrastructure.

The twelve-state figure also reframes the scale question. What began as a Minnesota-specific incident now reads as a broader, geographically distributed campaign against water utilities’ PLCs and remote-access infrastructure — consistent with the exposure pattern CISA has been warning about since the initial Minnesota reporting. For defenders, the attribution detail matters less than the trend line: the count of affected states is growing week over week, and the attack surface (internet-reachable PLCs, cellular-connected remote sites) that enabled the original intrusions has not visibly closed in the time since.

Sources: SecurityWeek · The Record

2. Forescout: the exposure hasn’t closed — thousands of Rockwell/Allen-Bradley controllers still online

CyberScoop · August 6, 2026

An internet-exposure scan from Forescout, reported by CyberScoop, found that despite months of federal warnings tied to the water-sector attacks, thousands of Rockwell/Allen-Bradley controllers remain reachable directly from the public internet. This is the exposure the entire week’s water-sector coverage keeps returning to: it is the same class of internet-facing PLC that CISA has repeatedly urged utilities to disconnect, and the scan is hard evidence that the guidance has not translated into remediation at scale.

For a sector made up largely of small, resource-constrained utilities, the finding underscores why exposure reduction keeps stalling — it is not a knowledge gap, it is a staffing-and-budget gap. Every additional state added to the attack count and every controller the Forescout scan finds still exposed argues for treating this as the single highest-leverage fix available to the sector, ahead of any more sophisticated control.

Sources: CyberScoop

3. New York funds part of the fix: $9M for 153 water systems

SecurityWeek · August 4, 2026

New York announced $9M in grants under its SECURE program to strengthen cybersecurity at 153 water systems across the state, SecurityWeek reported. It is a direct, state-level answer to the funding gap that the Forescout exposure data and the CISA guidance both point back to — small water utilities generally know what they should do (disconnect exposed PLCs, lock down remote access, segment networks) but often lack the budget and staff to do it.

The grant program is worth watching less for its size than for whether it becomes a template. If New York’s approach — targeted state funding tied to specific security improvements at named utilities — produces measurable exposure reduction, it is a model other states can point to when the federal picture on infrastructure funding remains uncertain. If it does not move the needle, that itself is useful evidence about how much funding this problem actually requires.

Sources: SecurityWeek

4. OT risk beyond the tap: Bendix truck brakes and a decades-old BMC flaw

SecurityWeek · August 4–7, 2026

Two stories this week showed the OT exposure problem is not confined to water utilities. SecurityWeek reported that a safety recall for Bendix’s EC80 truck brake controller doubled as a hidden security fix, with research tied to the National Motor Freight Traffic Association’s (NMFTA) heavy-vehicle cybersecurity program surfacing around Black Hat. Safety-critical embedded controllers in commercial trucking sit in the same exposure category as controllers on a plant floor — and when a security fix rides in on a safety recall rather than a disclosed advisory, it is easy for fleet operators to miss that a security issue was addressed at all.

Separately, SecurityWeek covered a decades-old vulnerability in Baseboard Management Controllers running the IPMI protocol, leaving thousands of data centers exposed to remote compromise of the physical hardware layer beneath the compute stack. As data centers scale to meet AI-driven demand, the management interfaces that control power, cooling and remote hardware access are becoming critical infrastructure in their own right — and this is now the second consecutive week this bulletin has covered exposed data-center controllers as a distinct OT risk category.

Sources: SecurityWeek (Bendix EC80) · SecurityWeek (BMC/IPMI)

5. Foundational: the water sector’s wake-up call, and a reminder from Nichirei

CyberScoop · SecurityWeek · July 17 & August 6, 2026

This week’s foundational reading closes the loop on the water-sector story and broadens it to manufacturing. In a CyberScoop op-ed, Nozomi Networks’ CEO argues that the water sector’s “wake-up call” has now sounded more than once — the sector keeps absorbing warnings and incidents without the durable investment and staffing needed to act on them, a point this week’s twelve-state expansion and still-exposed Rockwell controllers make concrete rather than rhetorical.

SecurityWeek’s account of the cyberattack that disrupted operations at Japanese frozen-food giant Nichirei extends the same lesson outside critical infrastructure entirely. Manufacturing operators running automated production lines face the same OT disruption risk as a water utility or an energy grid, without a regulator or a CISA advisory series standing behind them. Read alongside this week’s twelve-state water campaign and the Bendix and BMC items, the foundational set argues that OT exposure is now a cross-sector operating risk, not a critical-infrastructure-specific one.

Sources: CyberScoop (Nozomi op-ed) · SecurityWeek (Nichirei)

On our watch list

  • Water-sector attack count. Watching whether the twelve-state figure keeps growing, whether more states are named, and whether the Iran-linked attribution firms up or expands to additional actors.
  • Rockwell/Allen-Bradley exposure reduction. Watching whether the Forescout findings move utilities and asset owners to actually take exposed controllers offline — the single highest-leverage fix available to the sector.
  • SECURE grant outcomes. Watching whether New York’s $9M in water-system grants produces measurable security improvements, and whether other states adopt a similar targeted-funding model.
  • Heavy-vehicle controller security. Watching whether more safety recalls in trucking and other embedded-controller domains turn out to carry undisclosed security fixes, and whether NMFTA’s program gains broader adoption.
  • Data-center BMC/IPMI exposure. Watching whether the decades-old vulnerability gets patched at scale as data-center capacity keeps expanding for AI workloads.
  • Cross-sector OT risk. Watching whether more manufacturing and non-critical-infrastructure operators report OT disruption incidents like Nichirei’s, signaling the risk model needs to widen beyond regulated sectors.

IT/OT Security Weekly

A weekly intelligence bulletin from Security Radar LLC.
Curated by Paul Davis · paul.davis@security-radar.com

© 2026 Security Radar LLC. All rights reserved.

Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.

*|LIST:ADDRESS|*

View this email in your browser · Unsubscribe

Recent Posts

  • Security Operations Weekly — August 9, 2026
  • IT/OT Security Weekly — August 9, 2026
  • DevSecOps Weekly — August 9, 2026
  • The CISO Brief — August 9, 2026

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • Competitive
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • IT/OT Security
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme