{"id":5706,"date":"2026-08-17T18:00:36","date_gmt":"2026-08-17T23:00:36","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5706"},"modified":"2026-08-17T18:00:36","modified_gmt":"2026-08-17T23:00:36","slug":"it-ot-security-weekly-august-16-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5706","title":{"rendered":"IT\/OT Security Weekly \u2014 August 16, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#334155;background:linear-gradient(135deg,#334155 0%,#b45309 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">August 16, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">IT\/OT Security<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">CERT Polska published the first documented case of an attacker pivoting through a private cellular APN into a plant&#8217;s control network &mdash; a turbine and a water treatment system stopped at a combined heat and power facility serving 50,000 people. Meanwhile the multi-state US water campaign added New Jersey and Alabama, with Iran-linked CyberAv3ngers suspected, and finally produced a legislative and philanthropic response: a $300M-a-year Senate bill, a DEF CON-launched Water Watch Center, and five vendors delivering funded MDR to utilities that could never buy it. Around both threads, Dragos counted 1,140 industrial ransomware incidents in Q2, Claroty Team82 pulled apart a refrigeration controller, and a White House memorandum wrote ICS and embedded controllers into the definition of a legitimate offensive-cyber target.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>This week at a glance<\/h2>\n<p>Two threads dominate, and the first is a genuine first. CERT Polska disclosed a multi-stage intrusion into a Polish combined heat and power plant in which the attacker reached the OT network by pivoting through a <em>private APN<\/em> &mdash; the dedicated cellular data network a distribution system operator runs for its own remote sites. CERT Polska describes it as the first instance of that vector being observed in a real-world attack, and the mechanics are unglamorous in a way that should worry every operator: initial access through an internet-exposed FortiGate VPN concentrator with no MFA at a wind farm, lateral movement to a Teltonika RUTX50 cellular router whose SSH management interface was reachable over the APN, and then &mdash; because the APN permitted client-to-client traffic &mdash; a straight path to the CHP plant&#8217;s controllers. On December 29 the attacker put Siemens S7-300, S7-1200 and S7-1500 PLCs into STOP mode, factory-reset seven Moxa serial device servers, reconfigured three switches, and logged into a WAGO PFC200 whose web administration interface still carried default credentials. A turbine stopped and the water treatment system was interrupted at a plant that supplies heat to roughly 50,000 residents. Recovery began at 7:30 a.m. while the intruder was still inside, and the attacker&#8217;s last act was anti-forensic: corrupting the WAGO&#8217;s partition table and factory-resetting the router and the firewall. The Hacker News and Industrial Cyber both carried it. No actor was named.<\/p>\n<p>The second thread is the US water campaign, which stopped widening quietly and started producing policy. SecurityWeek reported New Jersey (Cape May and Woodbine) and Alabama (Childersburg Water, Sewer and Gas) joining the list of targeted states, taking the confirmed count to at least a dozen; Dark Reading&#8217;s account describes the same playbook everywhere &mdash; PLC passwords changed to lock operators out, IP addresses altered to drop controllers off the network, visibility and control lost &mdash; with the worst outcome so far a pressure drop and boil-water advisory in Clayton County, Georgia. Attribution has firmed to a suspicion rather than a finding: the pro-Iran CyberAv3ngers, consistent with the FBI&#8217;s July 22 and CISA&#8217;s July 30 warnings about Iranian actors targeting Rockwell Automation\/Allen-Bradley, Schneider Electric and Siemens PLCs. What is new this week is the response. Senators Adam Schiff and Amy Klobuchar introduced the Water Cyber Shield Act, authorising $300 million a year through the Drinking Water and Clean Water State Revolving Funds and giving EPA explicit authority to assess water systems, enforce corrective action, and set standards with CISA and NIST. At DEF CON, DEF CON Franklin and the National Rural Water Association launched a Water Watch Center for the utilities serving fewer than 10,000 people &mdash; 91% of the country&#8217;s roughly 50,000 community water systems &mdash; with Defendify, Legato Security, L1 Secure, Rapid7 and Sentinel Technologies delivering managed detection and response, seeded by Craig Newmark and, as Cybersecurity Dive reports, explicitly designed as a bridge until &#8220;the federal government has to step in and pay for this.&#8221;<\/p>\n<p>Around those two, three items reframe the risk. Dragos counted 1,140 ransomware incidents against industrial organisations in Q2 2026, up 12% on Q1, with manufacturing absorbing 747 of them and Qilin, Akira and The Gentlemen leading the claim counts &mdash; and the finding that matters is not the total but the mechanism: production stops because enterprise IT systems supporting the OT environment are encrypted, not because anyone touched a controller. Claroty Team82&#8217;s research on Copeland XWEB Pro supervisory controllers is the week&#8217;s best ICS vulnerability work: 23 flaws, 21 rated high, including an authentication bypass (CVE-2026-25085) and predictable daily admin credentials derived from a publicly readable MAC address (CVE-2026-21718), demonstrated by disabling cooling fans while the temperature display kept reading normal. And the White House&#8217;s August 12 CE-TCO memorandum, which authorises vetted private companies to run offensive cyber operations against transnational criminal organisations, explicitly names industrial control systems and embedded processors inside its definitions of cyber effects and surveillance operations &mdash; Nozomi Networks&#8217; reading is that an exposed, conscripted device becomes a lawful target and its owner has no recourse.<\/p>\n<p>The rest of the week fills in the picture. Make UK found 30% of British manufacturers reporting incidents that affected operations or supply chains; Bridewell reported manufacturing taking 40% of UK critical-infrastructure infostealer victims; the FBI and South Korean authorities warned about the Gunra ransomware group targeting critical infrastructure; and The Register covered a vulnerability sweep that turned up Royal Navy drones sending data to China. On the tooling side, Nozomi and Sophos are pushing OT telemetry into IT security investigations, Crytica Security and Forescout are integrating deterministic detection into Vistaro, and Dragos published its methodology for AI-driven vulnerability detection in OT software. The foundational set closes the loop: Dragos on a decade of the same open water-sector gaps, on defining the xOT environment before you try to defend it, and on MTSA&#8217;s segmentation requirement; Nozomi on what the FBI\/EPA PLC warning actually asks of utilities; Tenable&#8217;s technical breakdown of the Minnesota attacks and CVE-2021-22681; and Industrial Cyber on agentic ransomware compressing the response window OT defenders have always relied on.<\/p>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/08\/topic-map-it-ot-security-2026-08-16.png\" alt=\"Topic map of this week's IT\/OT Security themes\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&#8217;s topic map &mdash; the Polish CHP plant intrusion and its private-APN pivot, FortiGate VPN entry, Siemens S7 and WAGO PFC200 controllers and default credentials, clustered around CERT Polska; the multi-state US water campaign spanning Minnesota, New Jersey and Alabama with CyberAv3ngers and Iran suspected, Rockwell MicroLogix controllers and CVE-2021-22681, the FBI\/EPA warning, the Water Cyber Shield Act, the Water Watch Center and the small-utility funding gap; Dragos&#8217;s Q2 industrial ransomware data and the manufacturing sector; Claroty Team82&#8217;s Copeland XWEB Pro findings; and the CE-TCO offensive-cyber memorandum &mdash; all linked through the shared concepts of internet-exposed PLCs, IT\/OT convergence, OT asset visibility, network segmentation and sector regulation.<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5705\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#334155;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h3>Weekly News<\/h3>\n<h4>Energy &amp; plant intrusions<\/h4>\n<div class=\"cluster-intro\">CERT Polska&#8217;s disclosure of the first observed private-APN pivot into an OT network &mdash; a turbine and a water treatment system stopped at a combined heat and power plant serving 50,000 people.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/cert-polska-exposes-multi-stage-cyberattack-on-energy-infrastructure-involving-vpn-private-apn-ot-network-tunneling\/\">CERT Polska exposes multi-stage cyberattack on energy infrastructure involving VPN, private APN, OT network tunneling<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 12, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/thehackernews.com\/2026\/08\/hackers-breach-polish-power-plant.html\">Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine<\/a><\/td>\n<td class=\"src\">The Hacker News<\/td>\n<td class=\"dt\">Aug 11, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Water sector: attacks and policy<\/h4>\n<div class=\"cluster-intro\">The multi-state campaign widens to New Jersey and Alabama with Iran suspected &mdash; and for the first time draws a structural response: a $300M-a-year Senate bill, a DEF CON-launched Water Watch Center, and philanthropically funded MDR for utilities that could never buy it.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/www.securityweek.com\/us-water-systems-get-cyber-boost-from-new-senate-bill-and-water-watch-center\/\">US Water Systems Get Cyber Boost From New Senate Bill and &#8216;Water Watch Center&#8217;<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Aug 11, 2026<\/td>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/www.securityweek.com\/new-jersey-alabama-join-states-targeted-in-water-cyberattacks\/\">New Jersey, Alabama Join States Targeted in Water Cyberattacks<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Aug 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/multistate-water-system-attacks-widen-iran-suspected\">Multistate Water System Attacks Widen, Iran Suspected<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/water-cybersecurity-mdr-services-def-med-franklin\/827449\/\">Civil-society initiative will pay cybersecurity vendors to protect rural water systems<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Aug 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/industrialcyber.co\/expert\/inside-the-minnesota-water-attacks-exposed-plcs-a-guarded-chip-breach-and-washingtons-ai-patching-plan\/\">Inside the Minnesota Water Attacks: Exposed PLCs, a Guarded Chip Breach, and Washington&#8217;s AI Patching Plan<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/industrialcyber.co\/features\/small-water-utilities-face-cybersecurity-gap-as-rising-threats-collide-with-limited-staffing-funding-aging-infrastructure\/\">Small water utilities face cybersecurity gap as rising threats collide with limited staffing, funding, aging infrastructure<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 11, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Industrial ransomware &amp; manufacturing<\/h4>\n<div class=\"cluster-intro\">Dragos counted 1,140 industrial ransomware incidents in Q2 &mdash; and the through-line is that attackers do not need control-system access to stop production. Manufacturing absorbs most of it; a hospital&#8217;s HVAC shows what facility networks are worth to an attacker.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/www.nozominetworks.com\/blog\/when-ransomware-turns-off-the-hvac-lessons-from-the-winnipeg-hospital-incident\">When Ransomware Turns Off the HVAC: Lessons from the Winnipeg Hospital Incident<\/a><\/td>\n<td class=\"src\">Nozomi Networks<\/td>\n<td class=\"dt\">Aug 12, 2026<\/td>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/11\/industrial-ransomware-attacks-q2-2026\/\">Ransomware gangs don&#8217;t need control system access to disrupt industrial production<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Aug 11, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/industrialcyber.co\/manufacturing\/make-uk-calls-for-cyber-resilience-as-30-of-manufacturers-report-cyber-incidents-affecting-operations-supply-chains\/\">Make UK calls for cyber resilience as 30% of manufacturers report cyber incidents affecting operations, supply chains<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 12, 2026<\/td>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/industrialcyber.co\/manufacturing\/bridewell-reports-infostealer-threat-to-uk-critical-infrastructure-sector-as-manufacturing-takes-40-of-victims\/\">Bridewell reports infostealer threat to UK critical infrastructure sector as manufacturing takes 40% of victims<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 13, 2026<\/td>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/therecord.media\/ransomware-south-korea-fbi-gunra\">FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure<\/a><\/td>\n<td class=\"src\">The Record<\/td>\n<td class=\"dt\">Aug 10, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>ICS vulnerabilities &amp; vendor research<\/h4>\n<div class=\"cluster-intro\">Claroty Team82 takes apart a refrigeration supervisory controller and demonstrates spoiled stock behind a normal-looking temperature display; Dragos publishes how it uses AI to find vulnerabilities in OT software; and a UK sweep finds naval drones phoning home.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/industrialcyber.co\/critical-infrastructure\/claroty-team82-exposes-copeland-xweb-pro-vulnerabilities-that-could-disrupt-commercial-refrigeration-systems\/\">Claroty Team82 exposes Copeland XWEB Pro vulnerabilities that could disrupt commercial refrigeration systems<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 12, 2026<\/td>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.dragos.com\/blog\/ai-vulnerability-detection-ot-security-methodology\">Refuted by Default: Dragos&#8217; Methodology for AI-Driven Vulnerability Detection in OT Security Software<\/a><\/td>\n<td class=\"src\">Dragos<\/td>\n<td class=\"dt\">Aug 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/www.theregister.com\/edge-and-iot\/2026\/08\/10\/cyber-vulnerability-sweep-picks-up-royal-navy-drones-sending-data-to-china\/5285430\">Cyber vulnerability sweep picks up Royal Navy drones sending data to China<\/a><\/td>\n<td class=\"src\">The Register<\/td>\n<td class=\"dt\">Aug 10, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>OT security programs &amp; tooling<\/h4>\n<div class=\"cluster-intro\">A White House memorandum writes ICS and embedded controllers into the definition of an offensive-cyber target, while two vendor integrations push OT context into the IT security stack.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/www.nozominetworks.com\/blog\/if-you-dont-secure-it-theyll-remove-it-what-the-new-ce-tco-offensive-cyber-memorandum-means-for-industrial-operators\">If You Don&#8217;t Secure It, They&#8217;ll Remove It: What the New CE-TCO Offensive Cyber Memorandum Means for Industrial Operators<\/a><\/td>\n<td class=\"src\">Nozomi Networks<\/td>\n<td class=\"dt\">Aug 13, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/industrialcyber.co\/news\/nozomi-sophos-bring-ot-intelligence-into-it-security-investigations-target-detection-and-visibility-gap\/\">Nozomi, Sophos bring OT intelligence into IT security investigations, target detection and visibility gap<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 14, 2026<\/td>\n<\/tr>\n<tr>\n<td>19. <a href=\"https:\/\/industrialcyber.co\/news\/crytica-security-forescout-integrate-deterministic-threat-detection-with-vistaro-to-strengthen-device-security\/\">Crytica Security, Forescout integrate deterministic threat detection with Vistaro to strengthen device security<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 14, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Foundational Reading<\/h3>\n<h4>Scoping and defending the OT estate<\/h4>\n<div class=\"cluster-intro\">Three pieces on the shape of the problem: how fast the response window is closing, how wide the environment you actually have to defend really is, and what a regulator means when it says &#8220;segment&#8221;.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>20. <a href=\"https:\/\/industrialcyber.co\/expert\/agentic-ransomware-and-kernel-level-evasion-are-compressing-the-window-ot-defenders-rely-on\/\">Agentic Ransomware and Kernel-Level Evasion Are Compressing the Window OT Defenders Rely On<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 6, 2026<\/td>\n<\/tr>\n<tr>\n<td>21. <a href=\"https:\/\/www.dragos.com\/blog\/xot-environment-security-program\">What Changes When You Define the xOT Environment Correctly<\/a><\/td>\n<td class=\"src\">Dragos<\/td>\n<td class=\"dt\">Aug 13, 2026<\/td>\n<\/tr>\n<tr>\n<td>22. <a href=\"https:\/\/www.dragos.com\/blog\/whos-allowed-on-the-bridge-mtsas-network-segmentation-requirement\">Who&#8217;s Allowed on the Bridge: MTSA&#8217;s Network Segmentation Requirement<\/a><\/td>\n<td class=\"src\">Dragos<\/td>\n<td class=\"dt\">Aug 3, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Water: a decade of the same warnings<\/h4>\n<div class=\"cluster-intro\">Background for the campaign that dominates this issue &mdash; the historical pattern, what the FBI\/EPA PLC warning actually asks of a utility, and the technical anatomy of the Minnesota attacks.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>23. <a href=\"https:\/\/www.dragos.com\/blog\/water-utility-attacks-decade-of-gaps\">Water Under Attack: A Decade of Warnings, and the Same Gaps Still Open<\/a><\/td>\n<td class=\"src\">Dragos<\/td>\n<td class=\"dt\">Aug 13, 2026<\/td>\n<\/tr>\n<tr>\n<td>24. <a href=\"https:\/\/www.nozominetworks.com\/blog\/what-the-fbi-epa-plc-warning-means-for-water-utilities\">Seven States, One Weak Spot: What the FBI\/EPA PLC Warning Means for Water Utilities<\/a><\/td>\n<td class=\"src\">Nozomi Networks<\/td>\n<td class=\"dt\">Jul 31, 2026<\/td>\n<\/tr>\n<tr>\n<td>25. <a href=\"https:\/\/www.tenable.com\/blog\/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know\">Coordinated Cyberattack on Minnesota Water Utilities: What You Need to Know<\/a><\/td>\n<td class=\"src\">Tenable<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. CERT Polska: the first observed private-APN pivot into an OT network<\/h4>\n<p class=\"meta\">Industrial Cyber &middot; The Hacker News &middot; August 11&ndash;12, 2026<\/p>\n<p>CERT Polska&#8217;s report on a multi-stage intrusion into a Polish combined heat and power plant is the most operationally significant disclosure of the week, because it documents an attack path most OT architectures do not model. The attacker&#8217;s entry point was not the plant. It was a wind farm on the same distribution system operator&#8217;s network, reached through an internet-exposed FortiGate firewall acting as a VPN concentrator that permitted VPN access without multi-factor authentication. Administrative privileges on that device yielded credentials good across network segments. From there the pivot ran through a Teltonika RUTX50 cellular router whose SSH management interface was reachable from the operator&#8217;s <em>private APN<\/em> &mdash; the dedicated cellular data network used to reach remote sites. Because that APN allowed client-to-client traffic, every device attached to it was reachable from every other, and the plant&#8217;s controller network was one hop away. CERT Polska calls this the first instance of the private-APN vector being observed in a real-world cyberattack. Investigators could not establish how the attacker obtained the router&#8217;s SSH credentials.<\/p>\n<p>Reconnaissance ran from December 18 to 25, including port scans against the SCADA system, with successful S7-protocol connections to three Siemens PLCs on December 25. The destructive phase came on December 29, between roughly 5:30 and 10:10 a.m.: Siemens S7-300, S7-1200 and S7-1500 controllers switched to STOP mode, seven Moxa serial device servers factory-reset, three network switches reconfigured, and a WAGO PFC200 controller accessed through a web administration interface still carrying default credentials. A turbine shut down and the water treatment system was interrupted at a facility that supplies heat to roughly 50,000 residents. Recovery began at 7:30 a.m. with the intruder still active, and neither heat nor electricity was ultimately lost to customers &mdash; but the attacker&#8217;s exit was deliberately destructive to the investigation, corrupting the WAGO&#8217;s partition table and factory-resetting both the Teltonika router and the FortiGate. No threat actor was named.<\/p>\n<p>CERT Polska&#8217;s remediation guidance reads as a direct indictment of the assumptions that made this work: audit private APN configurations, enable client isolation so devices on the APN cannot reach each other, treat the APN as untrusted from an OT perspective rather than as an extension of the plant network, segment and restrict traffic across it, remove unnecessary management services from field devices, and change default credentials everywhere. If your organisation runs a private APN and has been treating it as a trusted transport because it is not the public internet, this is the week to revisit that.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/cert-polska-exposes-multi-stage-cyberattack-on-energy-infrastructure-involving-vpn-private-apn-ot-network-tunneling\/\">Industrial Cyber<\/a> &middot; <a href=\"https:\/\/thehackernews.com\/2026\/08\/hackers-breach-polish-power-plant.html\">The Hacker News<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. The water campaign adds New Jersey and Alabama, and the Iran suspicion hardens<\/h4>\n<p class=\"meta\">SecurityWeek &middot; Dark Reading &middot; Industrial Cyber &middot; August 10, 2026<\/p>\n<p>SecurityWeek reported two more states drawn into the multi-state campaign against US water systems. In New Jersey, the Cape May and Woodbine water systems were targeted on July 27, with officials saying only phone systems were disrupted and drinking water safety unaffected. In Alabama, the Childersburg Water, Sewer and Gas system was attacked the same day; industrial control systems were targeted but water service stayed up. That brings the confirmed count to at least a dozen states &mdash; Minnesota, where more than 30 systems were hit, plus Michigan, South Dakota, Georgia, New Jersey and Alabama among those named, with Wisconsin, Pennsylvania and Washington issuing warnings without confirmed intrusions.<\/p>\n<p>Dark Reading&#8217;s account is the clearest on technique, and it is consistent across states: the attackers go after programmable logic controllers directly, changing PLC passwords to lock operators out and altering IP addresses so controllers drop off the network, with the practical result being loss of visibility and loss of control rather than manipulation of the process itself. The most serious consequence so far was in Clayton County, Georgia, where a water pressure drop triggered a boil-water advisory. Attribution remains a suspicion rather than a finding &mdash; the pro-Iran hacktivist group CyberAv3ngers is the leading candidate, in line with the FBI&#8217;s July 22 warning and CISA&#8217;s July 30 alert about Iranian actors targeting PLCs from Rockwell Automation\/Allen-Bradley, Schneider Electric and Siemens. CISA&#8217;s instruction has not changed: remove publicly exposed PLCs and other OT from the internet as soon as possible.<\/p>\n<p>Why these devices are reachable at all is the part worth internalising. As Viakoo&#8217;s John Gallagher put it, PLCs were &#8220;engineered for physical isolation and reliability rather than Internet exposure&#8221;; Nozomi Networks&#8217; Markus Mueller points at the structural problem behind it, that most of the roughly 170,000 US water systems are small, decentralised and effectively unstaffed for cyber. Industrial Cyber&#8217;s expert round-up on the Minnesota attacks makes the same point from the incident side: exposed PLCs, reached over cellular links installed for legitimate remote monitoring, are the common denominator. This is not a sophistication problem. It is an inventory-and-exposure problem that nobody has funded.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.securityweek.com\/new-jersey-alabama-join-states-targeted-in-water-cyberattacks\/\">SecurityWeek<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/multistate-water-system-attacks-widen-iran-suspected\">Dark Reading<\/a> &middot; <a href=\"https:\/\/industrialcyber.co\/expert\/inside-the-minnesota-water-attacks-exposed-plcs-a-guarded-chip-breach-and-washingtons-ai-patching-plan\/\">Industrial Cyber<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. Washington and philanthropy finally answer: the Water Cyber Shield Act, the Water Watch Center, and funded MDR<\/h4>\n<p class=\"meta\">SecurityWeek &middot; Cybersecurity Dive &middot; Industrial Cyber &middot; August 10&ndash;11, 2026<\/p>\n<p>For the first time since the campaign began, the water sector got a structural response rather than another advisory. Senators Adam Schiff and Amy Klobuchar introduced the Water Cyber Shield Act, which authorises $300 million a year through the Drinking Water and Clean Water State Revolving Funds and, more consequentially, gives the EPA explicit authority it has lacked: to perform cybersecurity assessments of water systems, enforce corrective measures, set security standards jointly with CISA and NIST, mandate risk assessments for large systems, and extend mandatory incident reporting to state and locally owned facilities &mdash; with protection for sensitive utility data from public disclosure. Whether or not the bill passes in this form, it is the clearest statement yet of what a regulated water-sector cyber regime would look like.<\/p>\n<p>Alongside it, and moving faster, DEF CON Franklin and the National Rural Water Association launched the Water Watch Center at DEF CON in Las Vegas. Its target is the part of the sector that legislation reaches last: utilities serving fewer than 10,000 people, which make up 91% of the roughly 50,000 community water systems in the country. Five firms &mdash; Defendify, Legato Security, L1 Secure, Rapid7 and Sentinel Technologies &mdash; will deliver managed detection and response and share threat intelligence through the centre, with the NRWA operating the intelligence-sharing function and Vanderbilt University working on AI-driven defensive agents built on DARPA CASTLE research. Seed funding came from Craigslist founder Craig Newmark; DEF CON Franklin&#8217;s Jake Braun told Cybersecurity Dive the group is waiting on two further large grants and has partnered with Maryland&#8217;s state cybersecurity program for initial onboarding.<\/p>\n<p>Braun is refreshingly blunt about the model&#8217;s limits: &#8220;This is all about scale. Scaling delivery of cyber is where all the challenges fall,&#8221; and &#8220;eventually, the federal government has to step in and pay for this.&#8221; Industrial Cyber&#8217;s feature on small water utilities explains why that is true &mdash; the constraint is not awareness but the collision of rising threat activity with skeleton staffing, no capital budget, and aging infrastructure that predates any notion of network security. Philanthropy can prove a delivery model works at a few hundred utilities. It cannot fund tens of thousands.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.securityweek.com\/us-water-systems-get-cyber-boost-from-new-senate-bill-and-water-watch-center\/\">SecurityWeek<\/a> &middot; <a href=\"https:\/\/www.cybersecuritydive.com\/news\/water-cybersecurity-mdr-services-def-med-franklin\/827449\/\">Cybersecurity Dive<\/a> &middot; <a href=\"https:\/\/industrialcyber.co\/features\/small-water-utilities-face-cybersecurity-gap-as-rising-threats-collide-with-limited-staffing-funding-aging-infrastructure\/\">Industrial Cyber<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. Dragos Q2: 1,140 industrial ransomware incidents, and no controller was touched<\/h4>\n<p class=\"meta\">Help Net Security &middot; August 11, 2026<\/p>\n<p>Dragos&#8217;s Q2 2026 industrial ransomware analysis, drawn from publicly disclosed victims and leak-site posts, counted 1,140 incidents against industrial organisations &mdash; a 12% increase on the 1,020 recorded in Q1. Qilin led with 140 victim claims (down from 198), Akira followed with 129 (up from 100) and The Gentlemen posted 125 (up from 83). Manufacturing absorbed 747 incidents, 65% of the total, with construction at 176, equipment manufacturing at 114, supporting organisations such as engineering firms and system integrators at 117, transportation and logistics at 95 and food and beverage at 70. Geographically, North America took 514 incidents (431 in the US), Europe 316, Asia 172 and South America 64.<\/p>\n<p>The headline number is less useful than the mechanism behind it. Dragos&#8217;s finding is that production stops without the adversary ever reaching a control system: encrypt the enterprise IT that the OT environment depends on &mdash; MES, ERP, historians, engineering workstations, scheduling and shipping &mdash; and the plant halts anyway. As the researchers put it, risk &#8220;is shaped less by novel ICS-specific malware and more by adversaries&#8217; focus on enterprise IT systems.&#8221; For anyone justifying an OT security budget on the threat of Stuxnet-class tooling, this is the corrective: the far likelier outage comes from a commodity ransomware crew that never learned what a PLC is. It also reframes segmentation from a compliance line item into the control that decides whether an IT encryption event becomes an operational one.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/11\/industrial-ransomware-attacks-q2-2026\/\">Help Net Security<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. Claroty Team82: 23 flaws in Copeland XWEB Pro, and a temperature display that lies<\/h4>\n<p class=\"meta\">Industrial Cyber &middot; August 12, 2026<\/p>\n<p>Claroty&#8217;s Team82 disclosed 23 vulnerabilities in Copeland XWEB Pro supervisory controllers &mdash; the XWEB300D Pro and XWEB500D Pro models used to manage commercial refrigeration &mdash; with 21 rated high severity. The two that matter most are an authentication bypass, CVE-2026-25085, which lets an unauthenticated attacker slip past the login by using an HTTP authorization mode the controller does not recognise, and CVE-2026-21718, a predictable-credential flaw in which the daily administrator password is derived from the device&#8217;s publicly readable MAC address combined with hard-coded values in the firmware. Chained, they give unauthenticated attackers root-level remote code execution on the controller.<\/p>\n<p>The demonstration is what makes this research land. Team82 showed an attacker disabling cooling fans while the controller&#8217;s temperature display continued to read normal &mdash; silent spoilage, with no alarm and no operator signal until someone opens a case of stock. The exposure runs straight through supermarkets, food storage and pharmaceutical cold chains, sectors where the security consequence is inventory loss and, in the pharmaceutical case, potency and patient-safety failures that may not be detectable at the point of use. Copeland has published a fix in firmware version 1.13. The accompanying guidance is the familiar list, and it applies whether or not you can patch this week: get management interfaces off the internet, segment the OT network, and monitor for unexpected controller configuration changes. Refrigeration supervisory controllers are exactly the class of &#8220;not really OT&#8221; device that Dragos&#8217;s xOT argument this week says belongs inside your programme.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/critical-infrastructure\/claroty-team82-exposes-copeland-xweb-pro-vulnerabilities-that-could-disrupt-commercial-refrigeration-systems\/\">Industrial Cyber<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>6. The CE-TCO memorandum names ICS and embedded controllers &mdash; and your exposed device may be someone&#8217;s target<\/h4>\n<p class=\"meta\">Nozomi Networks &middot; August 13, 2026<\/p>\n<p>On August 12 the White House issued a National Security Presidential Memorandum titled &#8220;Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,&#8221; standing up a federal programme through the National Coordination Center with co-executive directors from DOJ and DHS. It permits vetted US private companies to conduct offensive cyber operations &mdash; both surveillance and disruptive effects &mdash; against foreign criminal organisations targeting Americans, subject to written approval from both co-directors for every operation, a minimum $1 million bond, an outright prohibition on operations causing loss of life, and legal review with judicial authorisation where US persons or domestic systems are touched. Operating procedures are due within 60 days, by October 11.<\/p>\n<p>Nozomi Networks&#8217; analysis focuses on a detail industrial operators should not skim past: the memorandum explicitly names industrial control systems and embedded processors and controllers inside its definitions of both &#8220;Cyber Effects Operations&#8221; and &#8220;Cyber Surveillance Operations.&#8221; OT is not incidental to this programme&#8217;s scope; it is written into it. The practical risk is not that a US contractor comes after your plant deliberately. It is that an internet-exposed device conscripted into a criminal relay network becomes a legitimate disruption target, and Section 5(c) states the memorandum creates no right or benefit enforceable at law against the United States &mdash; so the owner has no recourse. Protections extend to US persons and US-located systems, which leaves overseas industrial assets materially less covered.<\/p>\n<p>Nozomi&#8217;s framing is uncomfortable and correct: &#8220;If you do not fix your exposed infrastructure, someone eventually will, and you will have no say in how or when.&#8221; They also flag the attribution problem cutting the other way &mdash; &#8220;attribution is forgeable. Infrastructure can be rented, tooling can be borrowed, language artifacts can be staged.&#8221; The recommended 30-day actions are the same exposure-reduction work this bulletin keeps returning to: find your internet-facing OT with tools like Shodan, build a real asset inventory, rotate credentials on every reachable device, watch outbound traffic for signs of conscription, and apply heightened scrutiny to non-US facilities. The programme targets financially motivated criminals rather than nation-states &mdash; which, given Dragos&#8217;s Q2 numbers, is precisely the population most likely to be standing on your equipment.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.nozominetworks.com\/blog\/if-you-dont-secure-it-theyll-remove-it-what-the-new-ce-tco-offensive-cyber-memorandum-means-for-industrial-operators\">Nozomi Networks<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Calls to action \/ Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>Calls to action<\/h2>\n<ul>\n<li><strong>Audit every private APN and cellular transport you own.<\/strong> Enable client isolation, treat the APN as untrusted from the OT side, and remove SSH and web management from field routers reachable over it. The Polish CHP plant is the proof that &#8220;not the public internet&#8221; is not a security boundary.<\/li>\n<li><strong>Enumerate internet-facing OT before someone else does.<\/strong> Run the Shodan\/Censys sweep against your own address space and cellular ranges, and prioritise PLCs, refrigeration and building controllers, and remote-access appliances. Under the CE-TCO memorandum an exposed, conscripted device is a lawful target with no owner recourse.<\/li>\n<li><strong>Kill default and derivable credentials on field devices.<\/strong> WAGO PFC200 web admin in Poland and Copeland XWEB Pro&#8217;s MAC-derived daily password are the same failure in two forms. Inventory devices whose credentials are guessable from public data.<\/li>\n<li><strong>Patch Copeland XWEB300D\/500D Pro to firmware 1.13<\/strong> and get their management interfaces off any routable path; if you run cold chain, treat silent-spoilage detection as a monitoring requirement, not a display you trust.<\/li>\n<li><strong>Set PLC mode switches to RUN and get controllers off cellular-exposed links.<\/strong> Where remote access is genuinely required, front it with an industrial gateway enforcing VPN plus MFA, and keep offline backups of PLC logic and configuration so a password change is an inconvenience, not an outage.<\/li>\n<li><strong>Test the IT-side ransomware scenario, not just the ICS one.<\/strong> Dragos&#8217;s Q2 data says production stops when MES, ERP, historians and engineering workstations are encrypted. Validate that your segmentation actually holds and that the plant can run manually while IT is down.<\/li>\n<li><strong>Redraw your OT scope using the xOT definition.<\/strong> Building automation, HVAC, door access, refrigeration, machine vision and cloud analytics influence physical outcomes; the Winnipeg hospital incident shows what happens when they are outside the programme.<\/li>\n<li><strong>Small utilities: get in line for the Water Watch Center.<\/strong> If you serve fewer than 10,000 people, funded MDR through DEF CON Franklin and the NRWA is currently the cheapest detection capability available to you.<\/li>\n<\/ul><\/div>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>Private-APN attacks as a repeatable pattern.<\/strong> Watching whether CERT Polska&#8217;s disclosure is followed by similar findings elsewhere in European energy, and whether mobile operators start shipping client isolation as a default rather than an option.<\/li>\n<li><strong>Attribution for the Polish CHP intrusion.<\/strong> No actor was named. Watching whether Polish authorities, ESET or Dragos tie it to the wider December energy-sector campaign.<\/li>\n<li><strong>The water campaign&#8217;s state count and the CyberAv3ngers attribution.<\/strong> Watching whether the dozen-state figure keeps climbing, whether Wisconsin, Pennsylvania or Washington move from warning to confirmed incident, and whether the Iran link is formally asserted rather than suspected.<\/li>\n<li><strong>The Water Cyber Shield Act&#8217;s progress.<\/strong> Watching whether the $300M authorisation survives committee and, more importantly, whether EPA&#8217;s new assessment and enforcement authority stays in the text.<\/li>\n<li><strong>Water Watch Center scale-up.<\/strong> Watching the two pending &#8220;massive grants&#8221; Jake Braun referenced, how many utilities onboard beyond the Maryland pilot, and whether federal funding actually arrives to replace philanthropy.<\/li>\n<li><strong>CE-TCO operating procedures, due October 11.<\/strong> Watching what the DOJ\/DHS procedures say about deconfliction with owners of conscripted infrastructure, and whether any carve-out for critical-infrastructure assets appears.<\/li>\n<li><strong>Copeland XWEB Pro exploitation in the wild.<\/strong> Watching for scanning against XWEB management interfaces and for a CISA ICS advisory picking up the Team82 findings.<\/li>\n<li><strong>Q3 industrial ransomware trajectory.<\/strong> Watching whether the 12% quarter-on-quarter growth holds, whether The Gentlemen keeps climbing, and whether Gunra&#8217;s critical-infrastructure targeting shows up in the leak-site counts.<\/li>\n<li><strong>Agentic ransomware in OT incidents.<\/strong> Watching for the first confirmed case where AI-driven tooling measurably compressed dwell time to detection in an industrial environment.<\/li>\n<\/ul><\/div>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">IT\/OT Security<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>August 16, 2026 &middot; Weekly Edition IT\/OT Security CERT Polska published the first documented case of an attacker pivoting through a private cellular APN into a plant&#8217;s control network &mdash; a turbine and a water treatment system stopped at a combined heat and power facility serving 50,000 people. Meanwhile the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[],"class_list":["post-5706","post","type-post","status-publish","format-standard","hentry","category-it-ot-security"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5706","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5706"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5706\/revisions"}],"predecessor-version":[{"id":5716,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5706\/revisions\/5716"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5706"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5706"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5706"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}