{"id":5621,"date":"2026-08-02T16:22:02","date_gmt":"2026-08-02T21:22:02","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5621"},"modified":"2026-08-02T16:22:02","modified_gmt":"2026-08-02T21:22:02","slug":"it-ot-security-weekly-august-2-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5621","title":{"rendered":"IT\/OT Security Weekly \u2014 August 2, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#334155;background:linear-gradient(135deg,#334155 0%,#b45309 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">August 2, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">IT\/OT Security Weekly<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">A coordinated cyberattack hit more than thirty Minnesota water utilities, turning the week&#8217;s abstract warnings about exposed PLCs into a live incident; CISA and SecurityWeek pushed urgent water-sector guidance and a fresh batch of Siemens and ABB ICS advisories; Europe moved against Russia&#8217;s Turla over destructive attacks on Poland&#8217;s grid while US agencies re-warned about Russian and Iranian targeting of control systems; and researchers showed new ways to disrupt power grids and critical systems without a traditional exploit. A week where the OT threat stopped being theoretical.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>At a glance<\/h2>\n<p>The week&#8217;s defining event was on the ground in Minnesota. State and federal agencies confirmed a coordinated cyberattack against operational technology at more than thirty community water systems, hitting the automated controls that run treatment and distribution &mdash; some utilities briefly reverted to manual operation, and at least one took its plant offline as a precaution, though officials stressed drinking water remained safe and made no formal attribution. The incident was covered from three angles: The Record&#8217;s reporting on CISA&#8217;s warning of a spike in water-system attacks, Dark Reading&#8217;s look at what the intrusions expose about the sector&#8217;s risk, and SecurityWeek&#8217;s detailed account of the more-than-thirty affected utilities. It landed as the concrete instance of exactly the exposure defenders have been warning about &mdash; internet-reachable PLCs and cellular-connected remote sites &mdash; and CISA followed with an urgent July 30 alert urging water and wastewater operators to disconnect exposed controllers and lock down remote access.<\/p>\n<p>The advisory machinery ran hot alongside it. CISA published a batch of Industrial Control Systems advisories (the ICSA-26-211 series) plus multiple Siemens SIMATIC bulletins &mdash; S7-PLCSIM Advanced, the S7-1500 CPU line, and Desigo CC &mdash; and an ABB KNX advisory, the steady drumbeat of vendor vulnerabilities that OT asset owners have to triage against the reality that patching a live controller is rarely simple. On the nation-state front, the pressure was explicit: the EU and UK moved against Russia&#8217;s Turla group over espionage and &ldquo;destructive attacks,&rdquo; tied to the earlier assault on Poland&#8217;s energy sector, and US agencies issued a fresh joint advisory warning that Russian FSB-linked actors are targeting network devices in critical infrastructure &mdash; while the foundational reading carries the updated CISA advisory (AA26-097A) on Iranian-affiliated exploitation of internet-connected PLCs across US critical infrastructure.<\/p>\n<p>Two threads pointed at where the risk is heading. Dark Reading reported thousands of data-center controllers left open to takeover &mdash; the building-management and infrastructure layer that underpins the compute everything else now depends on &mdash; and CISA, with Australia&#8217;s ACSC, published joint guidance on isolating vital OT systems so operators can contain an incident and keep essential services running. The research in this week&#8217;s foundational set sharpens the horizon further: a &ldquo;Bit2Watt&rdquo; technique that could let cloud tenants disrupt power grids without a conventional exploit, 6 GHz Wi-Fi flaws that could disrupt critical systems, Iran&#8217;s widening target set beyond critical infrastructure, and the BusySnake infostealer working its way into critical-infrastructure networks. Taken together, it was the week the OT threat model stopped being a briefing slide and became an operations problem.<\/p>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/08\/topic-map-it-ot-security-2026-08-02-1.png\" alt=\"Topic map of this week's IT\/OT Security themes\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&#8217;s topic map &mdash; the coordinated Minnesota water-utility OT attacks and CISA&#8217;s urgent water-sector guidance, the ICS advisory batch (Siemens SIMATIC S7-PLCSIM\/S7-1500\/Desigo CC, ABB KNX, the ICSA-26-211 series), nation-state pressure on critical infrastructure (Turla and the Poland grid attack, the Russian FSB\/Cisco device-targeting advisory, the Iranian PLC campaign AA26-097A), OT exposure and the US&ndash;Australia isolation guidance, and the critical-infrastructure threat research (Bit2Watt, 6 GHz Wi-Fi flaws, Iran&#8217;s widening target set, BusySnake).<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5620\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#334155;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h3>Weekly News<\/h3>\n<h4>Water-sector OT attacks<\/h4>\n<div class=\"cluster-intro\">The week&#8217;s live incident: a coordinated attack on more than thirty Minnesota water utilities&#8217; operational technology, and the urgent CISA guidance that followed.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/therecord.media\/cisa-warns-of-spike-in-water-system-attacks\">CISA warns of spike in attacks on water systems as Minnesota incidents probed<\/a><\/td>\n<td class=\"src\">The Record<\/td>\n<td class=\"dt\">Jul 31, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/minnesota-water-utility-attacks-expose-sector-cyber-risks\">Minnesota Water Utility Attacks Expose Sector&#8217;s Cyber-Risks<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Jul 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/www.securityweek.com\/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks\/\">Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Jul 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/www.securityweek.com\/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs\/\">CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Jul 30, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>CISA &amp; ICS advisories<\/h4>\n<div class=\"cluster-intro\">The week&#8217;s vendor-vulnerability drumbeat: a fresh CISA advisory batch plus multiple Siemens SIMATIC bulletins and an ABB KNX advisory for OT asset owners to triage.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/30\/cisa-releases-industrial-control-systems-advisories\">CISA Releases Industrial Control Systems Advisories (ICSA-26-211 series)<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Jul 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-209-03\">Siemens SIMATIC S7-PLCSIM Advanced (ICSA-26-209-03)<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-209-04\">Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN\/DP MFP (ICSA-26-209-04)<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-209-01\">Siemens Desigo CC (ICSA-26-209-01)<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-209-07\">ABB KNX Update Tool (ICSA-26-209-07)<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Nation-state activity against critical infrastructure<\/h4>\n<div class=\"cluster-intro\">Explicit state pressure: Europe sanctioning Russia&#8217;s Turla over destructive grid attacks, and a fresh US warning that Russian actors are targeting critical-infrastructure network devices.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/cyberscoop.com\/eu-uk-russian-cyberespionage-sanctions\/\">Europe strikes out against Russia&#8217;s Turla over espionage, &#8216;destructive attacks&#8217;<\/a><\/td>\n<td class=\"src\">CyberScoop<\/td>\n<td class=\"dt\">Aug 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/cyberscoop.com\/russian-fsb-cisco-joint-cybersecurity-advisory\/\">Officials warn defenders that Russian hackers are targeting network devices<\/a><\/td>\n<td class=\"src\">CyberScoop<\/td>\n<td class=\"dt\">Aug 1, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>OT exposure &amp; isolation guidance<\/h4>\n<div class=\"cluster-intro\">Where the exposure is widening &mdash; data-center controllers left open to takeover &mdash; and the binational guidance on isolating vital OT to contain an incident.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/www.darkreading.com\/cyber-risk\/flaw-exposes-data-centers-server-takeover\">Thousands of Data Center Controllers Open to Takeover<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/www.securityweek.com\/us-australia-release-ot-isolation-guidance-for-critical-infrastructure\/\">US, Australia Release OT Isolation Guidance for Critical Infrastructure<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Jul 29, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Foundational Reading<\/h3>\n<h4>Critical-infrastructure threat research<\/h4>\n<div class=\"cluster-intro\">The longer-horizon research shaping the OT threat model &mdash; new grid- and critical-system-disruption techniques, Iran&#8217;s widening target set, an infostealer reaching into critical-infrastructure networks, and the standing Iranian PLC advisory.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/thehackernews.com\/2026\/07\/new-bit2watt-attack-could-let-cloud.html\">New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit<\/a><\/td>\n<td class=\"src\">The Hacker News<\/td>\n<td class=\"dt\">Jul 21, 2026<\/td>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.darkreading.com\/perimeter\/6-ghz-wi-fi-flaws-disrupt-critical-systems\">6 GHz Wi-Fi Flaws Could Disrupt Critical Systems<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Jul 14, 2026<\/td>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/www.darkreading.com\/cyber-risk\/iran-cyber-crosshairs-beyond-critical-infrastructure\">Iran&#8217;s Cyber Crosshairs Focus Beyond Critical Infrastructure<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Jul 9, 2026<\/td>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/busysnake-infostealer-critical-infrastructure-networks\">&#8216;BusySnake&#8217; Infostealer Slithers Into Critical Infrastructure Networks<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Jul 6, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-097a\">Iranian-Affiliated Actors Exploit PLCs Across US Critical Infrastructure (AA26-097A)<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Jul 22, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. Minnesota: the OT attack stops being theoretical<\/h4>\n<p class=\"meta\">The Record &middot; Dark Reading &middot; SecurityWeek &middot; July 29&ndash;31, 2026<\/p>\n<p>More than thirty Minnesota community water systems were hit in a coordinated cyberattack on their operational technology, and the incident is the concrete version of every warning the sector has absorbed for years. According to state and federal reporting, the attacks struck the automated control systems that run water treatment and distribution; several utilities activated contingency procedures and reverted to manual operation, and at least one city took its plant offline as a precaution, with officials emphasizing that drinking water remained safe and declining, for now, to formally attribute the activity. The recurring technical detail across accounts is the exposure of internet-reachable controllers and cellular-connected remote assets &mdash; water towers, lift stations and pump stations that phone home over links often overlooked in risk assessments &mdash; which is precisely the attack surface CISA has been urging the sector to eliminate.<\/p>\n<p>CISA&#8217;s response was immediate and specific. Its July 30 alert reported a significant increase in threat actors targeting PLCs in the water and wastewater sector and urged operators to take three steps now: disconnect PLCs from the public internet and route any remote access through a monitored VPN or gateway, enable password protection and change default credentials, and allowlist remote access to known engineering assets &mdash; plus keep a clean PLC image on hand in case attackers lock operators out by changing a device password. For water utilities, most of them small and resource-constrained, the hard part is not knowing what to do but having the staff and budget to do it; the incident is the argument for prioritizing exposure reduction over every other line item, and for treating secondary cellular links as first-class attack surface rather than an afterthought.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/therecord.media\/cisa-warns-of-spike-in-water-system-attacks\">The Record<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/minnesota-water-utility-attacks-expose-sector-cyber-risks\">Dark Reading<\/a> &middot; <a href=\"https:\/\/www.securityweek.com\/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks\/\">SecurityWeek (Minnesota)<\/a> &middot; <a href=\"https:\/\/www.securityweek.com\/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs\/\">SecurityWeek (CISA alert)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. The ICS advisory drumbeat: Siemens, ABB, and the patch-triage reality<\/h4>\n<p class=\"meta\">CISA &middot; July 28&ndash;30, 2026<\/p>\n<p>CISA&#8217;s advisory output kept its steady weekly cadence, publishing the ICSA-26-211 batch of Industrial Control Systems advisories alongside a cluster of Siemens SIMATIC bulletins &mdash; covering S7-PLCSIM Advanced, the S7-1500 CPU line, and the Desigo CC building-management platform &mdash; and an advisory for ABB&#8217;s KNX update tool. The specifics vary (denial-of-service conditions, authentication weaknesses, resource-handling flaws), but the operational significance is cumulative: these are the controllers, engineering tools and building systems that run plants and facilities, and each advisory adds to a patch backlog that OT teams cannot clear at IT speed.<\/p>\n<p>The uncomfortable truth OT defenders live with is that &ldquo;apply the patch&rdquo; is rarely available on demand. A live PLC or building controller often cannot be taken down outside a scheduled maintenance window, vendor-validated fixes lag disclosure, and some affected devices will never receive a patch at all. That is why CISA&#8217;s advisories pair vulnerability details with compensating controls &mdash; network segmentation, minimizing internet exposure, restricting access to known engineering systems &mdash; and why the practical posture for asset owners is to treat these bulletins as a prioritization input against exposure and criticality rather than a patch-now list. The advisories that matter most this week are the ones affecting devices that are both internet-reachable and safety-relevant; those are where the compensating controls need to go in immediately, patch window or not.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/30\/cisa-releases-industrial-control-systems-advisories\">CISA (ICSA-26-211 series)<\/a> &middot; <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-209-03\">Siemens S7-PLCSIM<\/a> &middot; <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-209-04\">Siemens S7-1500<\/a> &middot; <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-209-01\">Siemens Desigo CC<\/a> &middot; <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-209-07\">ABB KNX<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. Nation-state pressure gets explicit: Turla, Russian device targeting, and Iranian PLC exploitation<\/h4>\n<p class=\"meta\">CyberScoop &middot; CISA &middot; July 22&ndash;August 1, 2026<\/p>\n<p>The geopolitical layer of the OT threat moved from background to foreground. CyberScoop reported that the EU and UK took action against Russia&#8217;s Turla group over espionage and &ldquo;destructive attacks,&rdquo; tied to the earlier assault on Poland&#8217;s energy sector &mdash; the incident in which adversaries reached OT through vulnerable internet-facing edge devices and deployed destructive tooling that damaged remote terminal units and wiped human-machine-interface data across dozens of renewable and heat-generation sites. In parallel, US agencies issued a fresh joint advisory warning defenders that Russian FSB-linked actors are actively targeting network devices in critical infrastructure &mdash; the routers, firewalls and edge appliances that sit between IT and OT and, once compromised, become the pivot into control-system networks.<\/p>\n<p>The Iranian thread runs alongside it in this week&#8217;s foundational reading: CISA&#8217;s updated advisory AA26-097A documents Iranian-affiliated actors exploiting internet-connected PLCs &mdash; Rockwell, Schneider and Siemens devices &mdash; across US water, energy and government facilities, manipulating project files and HMI\/SCADA displays and, in some cases, causing operational disruption. Read together, the three sources describe a consistent adversary playbook: reach OT through exposed edge and network devices, then interact directly with controllers. The defensive implication is unambiguous and reinforces the water-sector guidance &mdash; the edge and the network layer are the battleground, so removing internet-facing OT, hardening and monitoring network devices, and verifying controller logic against trusted baselines are the controls that actually blunt this class of attacker.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/cyberscoop.com\/eu-uk-russian-cyberespionage-sanctions\/\">CyberScoop (Turla)<\/a> &middot; <a href=\"https:\/\/cyberscoop.com\/russian-fsb-cisco-joint-cybersecurity-advisory\/\">CyberScoop (Russian device targeting)<\/a> &middot; <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-097a\">CISA (AA26-097A)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. Widening exposure &mdash; and a playbook for containment<\/h4>\n<p class=\"meta\">Dark Reading &middot; SecurityWeek &middot; July 28&ndash;29, 2026<\/p>\n<p>Two stories framed both the problem and the response. Dark Reading reported that thousands of data-center controllers &mdash; the building-management and infrastructure systems that keep facilities powered and cooled &mdash; are exposed and open to takeover. It is an easy category to overlook because it sits between traditional IT and traditional OT, but it is load-bearing in the most literal sense: as data centers become the backbone of the AI build-out, their environmental and power controllers are critical infrastructure in their own right, and an attacker who can manipulate cooling or power sequencing can cause physical disruption without ever touching a server.<\/p>\n<p>The counterpart was a concrete defensive playbook. CISA, with Australia&#8217;s ACSC, published joint guidance on isolating vital OT and enabling systems &mdash; the capability to cut critical operational technology off from other networks to contain an active incident and keep essential services running. That directly matches what Minnesota&#8217;s utilities needed in practice: the ability to fall back to a known-safe, isolated mode of operation when the automated layer is compromised. For OT operators the guidance is a useful checklist for a control they may not have exercised &mdash; segmentation and isolation as an incident-response capability, tested before it is needed, not improvised during a live event. The pairing captures the week&#8217;s throughline: the exposure is widening faster than most programs are maturing, and the near-term priority is the ability to contain and keep operating rather than to prevent every intrusion.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.darkreading.com\/cyber-risk\/flaw-exposes-data-centers-server-takeover\">Dark Reading<\/a> &middot; <a href=\"https:\/\/www.securityweek.com\/us-australia-release-ot-isolation-guidance-for-critical-infrastructure\/\">SecurityWeek<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. Foundational research: new disruption paths and a widening target set<\/h4>\n<p class=\"meta\">The Hacker News &middot; Dark Reading &middot; July 6&ndash;21, 2026<\/p>\n<p>This week&#8217;s foundational reading extends the threat model past the current incidents. The Hacker News detailed &ldquo;Bit2Watt,&rdquo; a technique that could let cloud tenants disrupt power grids without a conventional exploit &mdash; manipulating aggregate power draw in shared data-center environments to induce grid-level effects, a novel bridge between the cloud and the physical grid that does not fit existing detection models. Dark Reading covered 6 GHz Wi-Fi flaws with the potential to disrupt critical systems, a reminder that the wireless expansion into industrial environments brings its own disruption surface, and separately reported on Iran widening its cyber crosshairs beyond critical infrastructure &mdash; a signal that target selection is broadening even as the critical-infrastructure focus persists.<\/p>\n<p>Dark Reading&#8217;s account of the BusySnake infostealer working into critical-infrastructure networks grounds the research back in present operations: information-stealing malware inside OT-adjacent IT environments is how many of these intrusions begin, harvesting the credentials and network knowledge that make the eventual control-system access possible. For OT security teams the collective value of the foundational set is horizon-scanning &mdash; the disruption techniques that do not yet have signatures (Bit2Watt), the expanding wireless and IT\/OT-boundary surface (6 GHz Wi-Fi, BusySnake), and the shifting intent of the most active state actors (Iran&#8217;s widening set). None require action this week, but all belong in the risk register that shapes next year&#8217;s OT security investment.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/thehackernews.com\/2026\/07\/new-bit2watt-attack-could-let-cloud.html\">The Hacker News (Bit2Watt)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/perimeter\/6-ghz-wi-fi-flaws-disrupt-critical-systems\">Dark Reading (6 GHz Wi-Fi)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cyber-risk\/iran-cyber-crosshairs-beyond-critical-infrastructure\">Dark Reading (Iran)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/busysnake-infostealer-critical-infrastructure-networks\">Dark Reading (BusySnake)<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>Minnesota attribution and scope.<\/strong> Watching whether investigators attribute the water-utility attacks, whether the count of affected systems grows, and whether the same actor moves to other states&#8217; utilities.<\/li>\n<li><strong>Water-sector exposure reduction.<\/strong> Watching whether CISA&#8217;s urgent guidance actually moves small utilities to disconnect exposed PLCs and secure cellular links &mdash; and how the funding gap for under-resourced operators gets addressed.<\/li>\n<li><strong>Edge and network-device targeting.<\/strong> After the Russian FSB advisory, watching for active exploitation of the IT\/OT-boundary devices (routers, firewalls, VPNs) adversaries use to pivot into control systems.<\/li>\n<li><strong>Iranian PLC campaign progression.<\/strong> Watching whether AA26-097A activity expands to more vendors and sectors, and whether any incident moves from targeting to confirmed operational impact.<\/li>\n<li><strong>Data-center controller exposure.<\/strong> Watching whether the exposed building-management systems get remediated as data centers scale for AI &mdash; and whether an attacker weaponizes cooling\/power control.<\/li>\n<li><strong>OT isolation in practice.<\/strong> Watching whether the US&ndash;Australia isolation guidance translates into operators actually testing fallback-to-isolated modes before an incident forces it.<\/li>\n<li><strong>Novel grid-disruption research.<\/strong> Watching whether Bit2Watt-style, exploit-free disruption techniques move from research to real-world attempts as data-center power demand keeps climbing.<\/li>\n<\/ul><\/div>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">IT\/OT Security Weekly<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>August 2, 2026 &middot; Weekly Edition IT\/OT Security Weekly A coordinated cyberattack hit more than thirty Minnesota water utilities, turning the week&#8217;s abstract warnings about exposed PLCs into a live incident; CISA and SecurityWeek pushed urgent water-sector guidance and a fresh batch of Siemens and ABB ICS advisories; Europe moved&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[],"class_list":["post-5621","post","type-post","status-publish","format-standard","hentry","category-it-ot-security"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5621","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5621"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5621\/revisions"}],"predecessor-version":[{"id":5633,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5621\/revisions\/5633"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}