{"id":5793,"date":"2026-08-30T15:14:58","date_gmt":"2026-08-30T20:14:58","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5793"},"modified":"2026-08-30T15:14:58","modified_gmt":"2026-08-30T20:14:58","slug":"it-ot-security-weekly-august-30-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5793","title":{"rendered":"IT\/OT Security Weekly \u2014 August 30, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#334155;background:linear-gradient(135deg,#334155 0%,#b45309 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">August 30, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">IT\/OT Security<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">The week the Iran-linked campaign against Western critical infrastructure stopped being a water-sector story. A UK power plant was shut down for four days, CISA confirmed that more than a hundred internet-exposed US water systems were touched in July, the FBI is examining a breach at a water-sector supplier, and Washington answered with sanctions on Iranian cyber actors, Executive Order 14420 on foreign equipment in the bulk-power system, a White House water-utility protection programme and a bipartisan Senate bill on Q-Day readiness for the grid. Underneath the headlines, CISA published Internet Exposure Reduction guidance, the UK NCSC warned that OT targeting is rising through internet-exposed systems and edge devices, and three fresh ICS advisories plus a pair of serial-to-IP device-server bugs kept the exposure argument concrete.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>This week at a glance<\/h2>\n<p>The week has one centre of gravity: operations against Western critical infrastructure that now produce physical consequences on two continents. A small British power plant stopped generating for four days after a July cyberattack &mdash; broken by The Telegraph on August 22 and covered by SecurityWeek on August 24, with UK Energy Minister Michael Shanks acknowledging it in social-media posts while the NCSC offered virtually no information. No customers lost supply and the wider grid was unaffected; The Record reports the intrusion is understood to have involved an unsecured programmable logic controller. On the same day the US Treasury, under Secretary Scott Bessent, sanctioned Iranian cyber actors tied to the Ministry of Intelligence and Security, naming Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda&rsquo;i and Mojtaba Ghal&rsquo;eh-Kuhi alongside previously designated individuals. Two days later CISA said it was aware of 100 internet-exposed water systems targeted during July, across at least a dozen states including Minnesota, Michigan, South Dakota, Georgia, New Jersey and Alabama, with Rockwell, Schneider Electric and Siemens PLCs &mdash; many wired straight to cellular modems &mdash; as the equipment reached. Some of those intrusions let attackers modify PLCs to disable shutdown processes and alarms. US intelligence believes Iran is likely responsible but has stopped short of concrete attribution, and Dragos CEO Robert M. Lee has cautioned publicly that anyone jumping to conclusions on the UK attack is &ldquo;very susceptible to false flag operations.&rdquo; Reuters added the supply-chain dimension on August 26 with an exclusive on a hack of a water-sector supplier now drawing FBI scrutiny &mdash; the pattern most utilities should worry about, because the small system does not have to be breached directly if the vendor that maintains its telemetry is.<\/p>\n<p>Washington&rsquo;s response arrived in an unusually compressed window. <strong>Executive Order 14420<\/strong>, issued on August 27, prohibits the acquisition, importation, transfer or installation of foreign-produced bulk-power system electric equipment where a foreign country or national holds an interest, and Section 2(d) applies that prohibition notwithstanding any prior contract. It reaches equipment at 69 kV and above plus battery energy storage, grid-connected inverters and uninterruptible power supplies, together with their software, firmware, digital services and remote-access capabilities. The Energy Secretary has 120 days to publish implementing rules and, working with the FAR Council, 180 days to recommend Federal Acquisition Regulation revisions. No country and no company is named; Nextgov notes the order could require operators to isolate or replace equipment already in use, with no cost estimate attached and local distribution out of scope. Alongside it, Nextgov reported that the Office of the National Cyber Director is preparing a water-provider protection programme, possibly starting with Texas as a testbed. And CyberScoop covered the bipartisan <strong>Quantum-GUARD Act<\/strong> from Senators Mike Rounds and Chris Coons, which would require FERC to weigh quantum threats and post-quantum cryptography when reviewing proposed reliability standards. Three instruments, three mechanisms: supply chain, subsidy, and long-horizon cryptographic risk.<\/p>\n<p>The technical guidance moved in the same direction. CISA issued <strong>Internet Exposure Reduction<\/strong> guidance on August 27 covering IT, OT, ICS and industrial systems, and it is concrete enough to work as a checklist: enumerate internet-accessible assets, decide which genuinely need to be reachable, and get SSH, Telnet, HTTP, RDP, VNC, TeamViewer, Modbus, DNP3, EtherNet\/IP, Niagara Fox, OPC UA and BACnet off the public internet, with jump hosts, MFA and traffic monitoring in front of whatever must remain. The UK NCSC arrived at the same conclusion a day later, naming PLCs, HMIs, industrial routers and gateways, firewalls and remote-access appliances as the exposed classes and recommending secure protocol variants &mdash; DNP3-SAv5, CIP Security, Modbus Security, OPC UA &mdash; while removing Telnet and SNMP v1\/v2. CyberScoop&rsquo;s report on CISA advisory AA26-237A supplies the encouraging counterpoint: in two red-team assessments, the water-sector organisation detected and quarantined compromised systems within 2, 10 and 20 minutes, while the government organisation missed the whole intrusion under thousands of false positives. And Dark Reading&rsquo;s argument for cyber deception in OT is the most practical piece in the set &mdash; where you cannot patch on demand and cannot tolerate false positives on the process network, a simulated PLC is one of the few detection mechanisms that costs nothing operationally and produces almost no noise.<\/p>\n<p>Three fresh CISA ICS advisories landed on August 25 &mdash; Siemens SIMATIC IoT2050 Advanced (ICSA-26-237-03), the FURUNO FA-50 Class B AIS transponder (ICSA-26-237-07) and the Bendix EC80 brake ECU (ICSA-26-237-05) &mdash; but Trout Software&rsquo;s round-up of the serial-to-IP device servers is the one to read closely. It covers ICSA-26-069-02 Update A on the Lantronix EDS3000PS and EDS5000, ICSA-26-237-06 on the Ebyte NE2-D11, ICSA-26-239-05 on the Ebyte NA111-M and ICSA-26-239-01 on the Xiiaozet LK100W: dozens of CVEs, several at CVSS v3.1 9.8, on the cheapest box in the panel. On the incident side, Boston Scientific disclosed on August 28 that an incident had cut access to operating systems and business applications including the ability to process and ship customer orders, with staff at its Cork, Ireland plant sent home &mdash; a reminder that the IT\/OT boundary usually fails at order processing and shipping before it fails at the machine. Kaspersky ICS CERT puts numbers under all of it, with malicious objects blocked on 19.15% of ICS computers in Q2 2026, the lowest level since 2022, while Dragos counted 1,140 industrial ransomware incidents in the same quarter, up 12%, with manufacturing absorbing 65% of them. Add Forescout on the exposed devices attacked in US water systems, Tenable on the active threat to Siemens S7 PLCs, the ISA and OT Cybersecurity Coalition partnership and the pipeline sector&rsquo;s case for treating cybersecurity as a safety contribution, and the week reads as a system finally being pushed in the same direction from policy, guidance and the field at once.<\/p>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/08\/topic-map-it-ot-security-2026-08-30.png\" alt=\"Topic map of this week's IT\/OT Security themes\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&rsquo;s topic map &mdash; Iran-linked actors at the centre, linking the July water-system campaign and the four-day UK power plant shutdown to CISA, the FBI, the UK NCSC and the US sanctions that followed; a policy cluster around Executive Order 14420, bulk-power systems, the White House water-provider programme and the Senate Q-Day bill; an exposure cluster tying CISA&rsquo;s Internet Exposure Reduction guidance to internet-exposed OT, edge devices, asset inventory, segmentation, OT deception and the CISA red-team results; the fresh advisory set around Siemens SIMATIC IoT2050, the FURUNO FA-50, the Bendix EC80 and Lantronix\/EByte serial-to-IP device servers; and a research-and-standards thread through Kaspersky ICS CERT, Dragos, Forescout, Tenable, the ISA\/OT Cyber Coalition partnership and ISA\/IEC 62443, with Boston Scientific and industrial ransomware anchoring the manufacturing sector.<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5792\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#334155;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h3>Weekly News<\/h3>\n<h4>The Iran-linked campaign on water and power<\/h4>\n<div class=\"cluster-intro\">A four-day shutdown at a UK power plant, sanctions on Iranian cyber actors, more than a hundred internet-exposed US water systems touched in July, and an FBI look at a breached water-sector supplier &mdash; one campaign, two countries, and a consistently unglamorous access method.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/www.securityweek.com\/iran-linked-hackers-shut-down-uk-power-plant-for-four-days\/\">Iran-Linked Hackers Shut Down UK Power Plant for Four Days<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Aug 24, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/therecord.media\/iran-cyberattacks-us-uk\">US sanctions Iranian cyber actors as UK discloses power plant attack<\/a><\/td>\n<td class=\"src\">The Record<\/td>\n<td class=\"dt\">Aug 24, 2026<\/td>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/www.securityweek.com\/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks\/\">CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Aug 26, 2026<\/td>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/techcrunch.com\/2026\/08\/26\/cisa-confirms-hackers-targeted-over-100-us-water-systems-during-july\/\">CISA confirms hackers targeted over 100 US water systems during July<\/a><\/td>\n<td class=\"src\">TechCrunch<\/td>\n<td class=\"dt\">Aug 26, 2026<\/td>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/www.reuters.com\/world\/hack-water-sector-supplier-draws-fbi-scrutiny-iran-linked-cyber-concerns-grow-2026-08-26\/\">Exclusive: Hack of water sector supplier draws FBI scrutiny as Iran-linked cyber concerns grow<\/a><\/td>\n<td class=\"src\">Reuters<\/td>\n<td class=\"dt\">Aug 26, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Washington&rsquo;s response<\/h4>\n<div class=\"cluster-intro\">Executive Order 14420 on foreign equipment in the bulk-power system, a White House protection programme for water providers, and a bipartisan Senate bill putting Q-Day on the grid&rsquo;s planning horizon. Supply chain, subsidy and cryptography, in one week.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/trump-issues-eo-14420-to-secure-us-bulk-power-systems-from-foreign-equipment-cybersecurity-risks\/\">Trump issues EO 14420 to secure US bulk-power systems from foreign equipment, cybersecurity risks<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 27, 2026<\/td>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/www.nextgov.com\/cybersecurity\/2026\/08\/trump-admin-moves-block-risky-foreign-technology-us-power-grid\/415701\/\">Trump admin moves to block risky foreign technology from US power grid<\/a><\/td>\n<td class=\"src\">Nextgov\/FCW<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/www.nextgov.com\/cybersecurity\/2026\/08\/white-house-soon-launch-water-provider-cyber-protection-program\/415650\/\">White House to soon launch water provider cyber protection program<\/a><\/td>\n<td class=\"src\">Nextgov\/FCW<\/td>\n<td class=\"dt\">Aug 26, 2026<\/td>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/cyberscoop.com\/quantum-guard-act-electric-grid-cybersecurity\/\">Bipartisan Senate bill aims to prepare energy sector for Q-Day<\/a><\/td>\n<td class=\"src\">CyberScoop<\/td>\n<td class=\"dt\">Aug 24, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Exposure reduction and assessment<\/h4>\n<div class=\"cluster-intro\">CISA and the NCSC arrive at the same conclusion from opposite sides of the Atlantic &mdash; the exposed estate is the attack surface &mdash; and CISA&rsquo;s own red teams find the water sector holding up better than the federal government.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/industrialcyber.co\/cisa\/cisa-issues-internet-exposure-reduction-guidance-to-reduce-risks-from-it-ot-ics-and-industrial-systems\/\">CISA issues Internet Exposure Reduction guidance to reduce risks from IT, OT, ICS and industrial systems<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 27, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/industrialcyber.co\/control-device-security\/uk-ncsc-warns-of-increased-ot-targeting-as-threat-actors-exploit-internet-exposed-systems-and-edge-devices\/\">UK NCSC warns of increased OT targeting as threat actors exploit internet-exposed systems and edge devices<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/cyberscoop.com\/cisa-red-team-report-government-water-cybersecurity\/\">Water sector passes, government sector fails attempts to thwart CISA red team<\/a><\/td>\n<td class=\"src\">CyberScoop<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Incidents and the industrial threat landscape<\/h4>\n<div class=\"cluster-intro\">A medical-device manufacturer still recovering from an IT incident that reached order processing, and Kaspersky ICS CERT&rsquo;s quarterly numbers on what is actually blocked on industrial computers.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/industrialcyber.co\/manufacturing\/boston-scientific-faces-ongoing-operational-disruption-after-cybersecurity-incident-impacts-it-systems-order-processing\/\">Boston Scientific faces ongoing operational disruption after cybersecurity incident impacts IT systems, order processing<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/securelist.com\/industrial-threat-report-q2-2026\/121159\/\">Threat landscape for industrial automation systems, Q2 2026<\/a><\/td>\n<td class=\"src\">Securelist (Kaspersky ICS CERT)<\/td>\n<td class=\"dt\">Aug 27, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Fresh ICS advisories<\/h4>\n<div class=\"cluster-intro\">Three CISA advisories from the August 25 release &mdash; an industrial edge gateway, a marine AIS transponder and a commercial-vehicle brake ECU &mdash; plus the serial-to-IP device servers that quietly give legacy field equipment an internet-routable identity.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-237-03\">Siemens SIMATIC IoT2050 Advanced (ICSA-26-237-03)<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-237-07\">FURUNO FA-50 Class B AIS Transponder (ICSA-26-237-07)<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-237-05\">Bendix EC80 Brake ECU (ICSA-26-237-05)<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/www.trout.software\/blog\/serial-to-ip-device-servers-cisa-advisories-lantronix-ebyte\">Serial-to-IP Device Servers: Two CISA Advisories in One Release<\/a><\/td>\n<td class=\"src\">Trout Software<\/td>\n<td class=\"dt\">Aug 27, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>OT programme practice<\/h4>\n<div class=\"cluster-intro\">Detection you can actually run on a process network, a standards body and an advocacy coalition joining forces, and the pipeline sector making the argument that cybersecurity is a contribution to safety rather than a parallel discipline.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>19. <a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/you-need-cyber-deception-ot\">You Need Cyber Deception for OT<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>20. <a href=\"https:\/\/www.isa.org\/news-press-releases\/2026\/august\/isa-and-operational-technology-cybersecurity-coali\">ISA and Operational Technology Cybersecurity Coalition Announce Partnership to Advance OT Cybersecurity<\/a><\/td>\n<td class=\"src\">ISA<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<tr>\n<td>21. <a href=\"https:\/\/www.pipeline-journal.net\/news\/analysis-risk-resilience-how-cybersecurity-contributes-pipeline-safety\">From Risk to Resilience &mdash; How Cybersecurity Contributes to Pipeline Safety<\/a><\/td>\n<td class=\"src\">Pipeline Technology Journal<\/td>\n<td class=\"dt\">Aug 27, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Foundational Reading<\/h3>\n<h4>Exposure and threat research worth re-reading<\/h4>\n<div class=\"cluster-intro\">The evidence base under this week&rsquo;s headlines: which exposed devices were actually attacked in US water systems, what the active threat to Siemens S7 controllers really is, and a protocol family that could widen the surface again.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>22. <a href=\"https:\/\/www.forescout.com\/blog\/ot-security-analysis-exposed-devices-attacked-in-us-water-systems\/\">OT Security Analysis: Exposed Devices Attacked in US Water Systems<\/a><\/td>\n<td class=\"src\">Forescout<\/td>\n<td class=\"dt\">Aug 5, 2026<\/td>\n<\/tr>\n<tr>\n<td>23. <a href=\"https:\/\/www.tenable.com\/blog\/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs\">Frequently Asked Questions About the Active Threat to Siemens S7 Series PLCs<\/a><\/td>\n<td class=\"src\">Tenable<\/td>\n<td class=\"dt\">Aug 20, 2026<\/td>\n<\/tr>\n<tr>\n<td>24. <a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/how-emerging-industrial-protocol-family-put-ot-at-risk\">How an Emerging Industrial Protocol Family Could Put OT at Risk<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 21, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Ransomware and the standards argument<\/h4>\n<div class=\"cluster-intro\">Dragos on where industrial ransomware actually landed in Q2, and on why standards written around prevention keep failing the defenders who have to live with an unpatched plant.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>25. <a href=\"https:\/\/www.dragos.com\/blog\/dragos-industrial-ransomware-analysis-q2-2026\">Dragos Industrial Ransomware Analysis: Q2 2026<\/a><\/td>\n<td class=\"src\">Dragos<\/td>\n<td class=\"dt\">Aug 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>26. <a href=\"https:\/\/www.dragos.com\/blog\/prevention-bias-ot-cybersecurity-standards\">The Prevention Bias Problem: Why Standards Are Failing OT Defenders<\/a><\/td>\n<td class=\"src\">Dragos<\/td>\n<td class=\"dt\">Aug 17, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. Four days dark: a UK power plant stopped generating, and Treasury sanctioned Iranian cyber actors the same day<\/h4>\n<p class=\"meta\">SecurityWeek &middot; The Record &middot; August 24, 2026<\/p>\n<p>A small power plant in the United Kingdom stopped generating for four days after a cyberattack in July. The Telegraph broke the story on August 22; SecurityWeek covered it on August 24. The public detail is thin by design: UK Energy Minister Michael Shanks acknowledged the incident in social-media posts, while the NCSC provided virtually no information, and neither the plant nor its operator has been named. What is on the record matters for calibration. No customers lost supply and the wider grid was unaffected &mdash; this was a generation asset taken off the bar for four days, not a blackout. The Record reports the intrusion is understood to have involved an unsecured programmable logic controller, which is consistent with everything else in this campaign and inconsistent with any claim of exotic tradecraft.<\/p>\n<p>Attribution is where care is required. On August 24 the US Treasury, under Secretary Scott Bessent, sanctioned Iranian cyber actors tied to Iran&rsquo;s Ministry of Intelligence and Security, naming Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda&rsquo;i and Mojtaba Ghal&rsquo;eh-Kuhi alongside individuals already designated, and stating the group is responsible for extensive compromises. Treasury did not tie those designations to the UK plant, and the UK has not published an attribution. Dragos CEO Robert M. Lee warned explicitly that people jumping to conclusions on Iran being behind the UK attack are &ldquo;very susceptible to false flag operations.&rdquo; Read the two events as concurrent rather than causally linked, and treat &ldquo;Iran-linked&rdquo; as the press framing it currently is. Security analyst Markus Mueller called the shift from water utilities to generation a &ldquo;major escalation,&rdquo; and that judgement stands whoever turns out to be responsible.<\/p>\n<p>The operational lesson does not depend on attribution. An unsecured PLC and a four-day generation loss is a control-system exposure problem, and the pattern across this campaign has consistently been exposed systems, weak authentication and remote-access paths installed for legitimate reasons and never re-reviewed. If your generation, water or process site has a remote-support arrangement with an OEM or an integrator, that arrangement is the single highest-value thing to audit. Ask three concrete questions this week: which external parties can reach anything on the process network, through what appliance, and with what authentication; when was each of those paths last used, and by whom; and whether any controller answers on a routable interface without authentication in front of it. If the answer to any of it is &ldquo;we would have to ask the vendor,&rdquo; treat that as a finding. Four days of lost generation is the price of not knowing.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.securityweek.com\/iran-linked-hackers-shut-down-uk-power-plant-for-four-days\/\">SecurityWeek<\/a> &middot; <a href=\"https:\/\/therecord.media\/iran-cyberattacks-us-uk\">The Record<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. CISA confirms 100+ internet-exposed US water systems targeted in July &mdash; and the supplier problem behind them<\/h4>\n<p class=\"meta\">SecurityWeek &middot; TechCrunch &middot; Reuters &middot; August 26, 2026<\/p>\n<p>CISA said in its exposure-reduction resources on August 26 that it is aware of 100 internet-exposed water systems targeted in cyberattacks during July. SecurityWeek counts at least twelve affected states and names Minnesota, Michigan, South Dakota, Georgia, New Jersey and Alabama; Nextgov reports more than thirty Minnesota water systems alone were hit in late July and early August. The equipment reached was programmable logic controllers from Rockwell Automation, Schneider Electric and Siemens, in many cases connected directly to cellular modems &mdash; a deployment pattern that gives a controller a public address with nothing in front of it. TechCrunch reports the intrusions had little effect on water or wastewater supply to communities but did produce outages and disruption, and that in some cases the attackers modified PLCs to disable shutdown processes and alarms, which is a safety-system consequence rather than a data one. US intelligence believes Iran is likely behind the activity; officials have stopped short of a concrete attribution. TechCrunch also notes the attackers relied in part on AI tools working from public information to generate scripts, which is the mechanism that turns a hundred small utilities from a target list into a sweep.<\/p>\n<p>Reuters&rsquo; exclusive on August 26 supplies the piece that makes this hard to fix with utility-level advice: a hack of a water-sector supplier is drawing FBI scrutiny amid growing Iran-linked cyber concerns. The adversary does not need to find a hundred exposed utilities one at a time if it can reach the vendor whose telemetry, SCADA hosting or remote maintenance touches all of them. This is the structural weakness that made managed service providers such productive targets in the IT world, transplanted into a sector with far less capacity to audit its suppliers. For a small utility, the vendor relationship is not a procurement detail; it is the primary attack path, and it is the one the utility has no technical ability to inspect.<\/p>\n<p>What can be done in a week is narrow and worth doing anyway. Find out whether anything in your plant answers from the public internet &mdash; not by asking, but by scanning your own address ranges and, critically, the carrier-assigned ranges behind every cellular modem, since that is where the targeted PLCs were found. Change every default credential on anything that speaks to a controller, including the cellular router and the HMI nobody logs into. Verify that shutdown logic and alarming on your PLCs match the approved configuration, because that is what was tampered with. Put multi-factor authentication on every remote-access path, and where a vendor says it is not supported, write that down as a risk with the vendor&rsquo;s name attached. And ask each supplier, in writing, whether they have been affected by the incident under FBI review and what access they retain into your environment. The written answer is the artefact that matters when the regulator or the insurer asks later.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.securityweek.com\/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks\/\">SecurityWeek<\/a> &middot; <a href=\"https:\/\/techcrunch.com\/2026\/08\/26\/cisa-confirms-hackers-targeted-over-100-us-water-systems-during-july\/\">TechCrunch<\/a> &middot; <a href=\"https:\/\/www.reuters.com\/world\/hack-water-sector-supplier-draws-fbi-scrutiny-iran-linked-cyber-concerns-grow-2026-08-26\/\">Reuters<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. Executive Order 14420: foreign equipment out of the bulk-power system<\/h4>\n<p class=\"meta\">Industrial Cyber &middot; Nextgov\/FCW &middot; August 27&ndash;28, 2026<\/p>\n<p>Executive Order 14420, issued August 27, prohibits the acquisition, importation, transfer or installation of foreign-produced bulk-power system electric equipment in the US where the transaction involves property in which a foreign country or national has an interest. Two provisions give it teeth. Section 2(d) applies the prohibitions notwithstanding any prior contract, so an existing purchase order is not a shield. And the scope reaches further than the NERC CIP asset list: equipment at 69 kV and above, plus battery energy storage systems, grid-connected inverters and uninterruptible power supply systems, together with associated software, firmware, digital services and remote-access capabilities. Trump&rsquo;s stated rationale is that &ldquo;certain foreign actors are increasingly creating and exploiting vulnerabilities in the United States bulk-power system&rdquo; and that the threat &ldquo;has become even more acute.&rdquo; No country and no company is named &mdash; Nextgov notes explicitly that the directive does not name China or any individual firm. Unlike the 2020 attempt, which lapsed before a rule existed to argue about, this one carries dates.<\/p>\n<p>Those dates are what to put in the plan. The Secretary of Energy has 120 days to publish rules and regulations implementing the order&rsquo;s authorities, and is to work with the Secretaries of War, Commerce and Homeland Security and the Director of National Intelligence to identify problematic bulk-power equipment as soon as practicable. Separately, Energy and the FAR Council have 180 days to develop recommended Federal Acquisition Regulation revisions, and the FAR Council then has 90 days to consider proposing amendments. The compliance question all of that will generate is provenance: for each item in the bulk-power path, who manufactured it, where its critical subcomponents were made, whose firmware runs on it, and who can update that firmware remotely. Most utilities cannot answer at that level today, because the asset register was built for maintenance and outage planning rather than country-of-origin analysis two tiers down. Start with the classes the order already enumerates &mdash; 69 kV and above, storage, inverters, UPS and their remote-monitoring appliances &mdash; rather than the whole estate.<\/p>\n<p>Two cautions. Nextgov reports the order could require operators to isolate or replace equipment already in use, and no cost estimate accompanies it; replacement cycles in the bulk-power system are measured in decades, and a restriction that outruns the supply of compliant alternatives creates reliability risk of its own. The second is scope: the order covers the bulk-power system and excludes local distribution, and supply-chain restriction is not the same control as exposure reduction. Excluding a vendor by nationality does nothing about an internet-exposed relay from an allied manufacturer, and the campaign described elsewhere in this issue exploited exposure, not provenance. The productive reading is that EO 14420 sets procurement direction for the next decade, and that the useful action this quarter is inventory and provenance data &mdash; the input every subsequent rule will require, however the final restrictions are drawn.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/trump-issues-eo-14420-to-secure-us-bulk-power-systems-from-foreign-equipment-cybersecurity-risks\/\">Industrial Cyber<\/a> &middot; <a href=\"https:\/\/www.nextgov.com\/cybersecurity\/2026\/08\/trump-admin-moves-block-risky-foreign-technology-us-power-grid\/415701\/\">Nextgov\/FCW<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. Help for water utilities, and Q-Day arrives on the grid&rsquo;s planning horizon<\/h4>\n<p class=\"meta\">Nextgov\/FCW &middot; CyberScoop &middot; August 24&ndash;26, 2026<\/p>\n<p>The Office of the National Cyber Director is preparing a cyber protection programme for water providers that Nextgov reported could be announced within a week, with Texas possibly serving as the initial testbed. The mechanism is the interesting part: rather than issuing another requirement, ONCD would enlist private firms to help states with few cyber resources defend the platforms that manage water and wastewater transmission. Funding has not been disclosed, and it is not yet clear how many companies or which ones would take part. The trigger is plain enough &mdash; more than thirty Minnesota water systems were targeted in late July and early August, around a dozen states reported similar activity, and officials suspect an Iranian link, though state officials said the systems continued operating safely with no known effects on public health. Cynthia Kaiser, the FBI&rsquo;s former cyber deputy director, put the sector&rsquo;s standing bluntly: &ldquo;When policymakers used to ask what systems I was most concerned about, my answer was always water.&rdquo; Whether this programme reaches below the largest few hundred utilities will depend on whether it delivers a staffed service or another application form.<\/p>\n<p>Running on a much longer clock, Senators Mike Rounds and Chris Coons have introduced the Quantum Grid Utility Assurance and Resilient Defense Act &mdash; the Quantum-GUARD Act. It would require FERC to consider quantum-computing threats and post-quantum cryptography when reviewing proposed reliability standards for electricity owners and operators under the Federal Power Act, direct FERC to explore uses of post-quantum cryptography across IT and OT systems, and create a technical sandbox to study how the technology affects both. The reason this belongs in an OT bulletin rather than a cryptography one is field-device lifetime. A protective relay, an RTU or a teleprotection link installed today will plausibly still be in service in 2045, with cryptographic primitives baked into firmware that cannot be replaced without a hardware refresh. Harvest-now-decrypt-later is a modest concern for most grid traffic; authentication is not. As SafeLogic&rsquo;s Evgeny Gervis framed it, &ldquo;it is essential that quantum computers do not undermine the integrity and authenticity of SCADA communications.&rdquo;<\/p>\n<p>The practical implication is procurement rather than migration. Nobody is swapping the cryptography in a substation this year, and the bill does not ask anyone to &mdash; it sets no deadlines and routes the work through FERC&rsquo;s standards review. What can be done now is to require crypto-agility in specifications for new field equipment, meaning the ability to update algorithms in the field without replacing hardware, and to build the inventory of where public-key cryptography is actually used in the OT estate, which for most operators is an unanswered question. Read together with EO 14420, both instruments show a policy apparatus that has understood the constraint defining this sector: you cannot patch or replace your way out of a problem on a twenty-year asset. You can only specify your way out of it, one procurement at a time.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.nextgov.com\/cybersecurity\/2026\/08\/white-house-soon-launch-water-provider-cyber-protection-program\/415650\/\">Nextgov\/FCW<\/a> &middot; <a href=\"https:\/\/cyberscoop.com\/quantum-guard-act-electric-grid-cybersecurity\/\">CyberScoop<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. CISA&rsquo;s Internet Exposure Reduction guidance, and the NCSC saying the same thing louder<\/h4>\n<p class=\"meta\">Industrial Cyber &middot; August 27&ndash;28, 2026<\/p>\n<p>CISA published its Internet Exposure Reduction guidance on August 27, one day after confirming the July water-system targeting, and it is specific enough to work from directly. The prescribed sequence is seven steps: identify internet-accessible assets with scanning tools; determine which actually require internet access; remove or restrict the rest; for anything that must stay reachable, change default passwords, apply patches and replace unsupported software; front it with a monitored jump host; monitor ingress and egress traffic; and enforce multifactor authentication. The device classes it names are the ones in every plant &mdash; PLCs, HMIs, RTUs, SCADA systems, industrial IoT and CIP devices &mdash; and it is explicit about what should not be answering from the public internet: SSH, Telnet, HTTP, HTTPS, RDP, VNC and TeamViewer on the management side, and Modbus, DNP3, EtherNet\/IP, Niagara Fox, OPC UA and BACnet on the process side. That last list is the one to hand to whoever runs your external scans, because it converts a policy statement into a query.<\/p>\n<p>The UK NCSC published its own warning on August 28, naming PLCs, HMIs, industrial routers, industrial gateways, firewalls and remote-access appliances as the classes under pressure from a range of threat actors it did not identify. Its recommendations run parallel to CISA&rsquo;s but add the protocol dimension: build a definitive OT architecture view covering all assets and connections, change default credentials and issue unique administrator accounts with MFA, harden OT boundaries with strict external access controls, adopt secure protocol versions &mdash; DNP3-SAv5, CIP Security, Modbus Security and OPC UA &mdash; and remove Telnet and SNMP v1\/v2 outright. It also points to logging and monitoring, segmentation of management, control and business IT networks, ransomware-resistant backups that have actually been restored in a test, and registration for the NCSC&rsquo;s free Early Warning service, which costs nothing and is the cheapest item on this page.<\/p>\n<p>The edge-device emphasis is the part worth dwelling on. Firewalls, VPN concentrators, cellular gateways and remote-access appliances sit precisely at the boundary an OT programme relies on, they are internet-facing by design, and they have been the most consistently productive vulnerability class in the industry for two years. A programme built on the assumption that the perimeter appliance is a control rather than a target is built on the wrong assumption; if the concentrator in front of your process network is what gets exploited, every architecture diagram behind it becomes decorative. Ric Derbyshire, principal security researcher at Orange Cyberdefense, framed the moment accurately: &ldquo;we&rsquo;ve moved beyond warning about the risk of OT disruption to actively seeing real-world impact.&rdquo; None of this is new advice. What is new is that there is now a federal document and an NCSC publication you can hand to a budget holder, in the same week that a hundred water systems and a UK power plant demonstrated the cost of not doing it.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/cisa\/cisa-issues-internet-exposure-reduction-guidance-to-reduce-risks-from-it-ot-ics-and-industrial-systems\/\">Industrial Cyber (CISA guidance)<\/a> &middot; <a href=\"https:\/\/industrialcyber.co\/control-device-security\/uk-ncsc-warns-of-increased-ot-targeting-as-threat-actors-exploit-internet-exposed-systems-and-edge-devices\/\">Industrial Cyber (NCSC)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>6. The water sector passed the red team. The government sector did not.<\/h4>\n<p class=\"meta\">CyberScoop &middot; Dragos &middot; August 17&ndash;25, 2026<\/p>\n<p>CISA advisory AA26-237A, published August 25 and covered by CyberScoop, sets two red-team assessments side by side. In the government organisation, the team phished its way onto multiple workstations, escalated to domain-level privileges and moved laterally into sensitive business systems and cloud resources without being caught; the organisation did not respond effectively to the alerts its security centre did raise, because, in CISA&rsquo;s account, false positives by the thousands obscured the alerts red-team activity triggered. In the water-sector organisation, defenders detected and quarantined the affected systems within 2, 10 and 20 minutes of initial compromise. That is not a marginal difference in maturity. It is the difference between an alert queue someone reads and one nobody can.<\/p>\n<p>Two caveats keep this from being a victory lap for the sector. This is two assessments, not a survey: one water organisation and one government organisation, both of which volunteered, and neither necessarily representative of a sector where most systems serve fewer than ten thousand people. And detecting a red team operating within agreed rules of engagement is a different problem from detecting an adversary resident for months through a vendor&rsquo;s remote-access appliance. Still, the result is a real data point, and the failure mode on the government side &mdash; alert volume defeating alert quality &mdash; is the most transferable finding in the report.<\/p>\n<p>Jacob Benjamin, Dragos&rsquo;s Global Practice Lead for ICS\/OT Consulting, supplies the frame that makes this legible, with numbers. In NIST CSF 2.0, Identify and Protect account for 60% of the controls, leaving 40% split across Detect, Respond and Recover. NIST SP 800-53 is 95% preventative, 3% active and 2% mapping to both. ISA\/IEC 62443 averages roughly 75% prevention against 25% detection, response and recovery across its parts. Standards weighted that way fit IT environments where a patch can be applied on Tuesday and fail OT environments where the patch waits for an outage eighteen months out. Dragos adds that fewer than 10% of OT networks worldwide have visibility and monitoring in place, and that organisations typically fail to account for nearly 30% of their connected devices &mdash; which is the same gap the government organisation fell into. Its recommendations are continuous improvement over project-based security, asset visibility, and regularly tested incident response. Dark Reading&rsquo;s case for OT deception, written by Velaspan CISO Scott Hawk, is the concrete version: simulated PLCs, decoy engineering workstations, honey credentials, fake OT network diagrams and decoy printers, cameras and badge controllers, all of which generate high-confidence alerts precisely because nothing legitimate should ever touch them.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/cyberscoop.com\/cisa-red-team-report-government-water-cybersecurity\/\">CyberScoop<\/a> &middot; <a href=\"https:\/\/www.dragos.com\/blog\/prevention-bias-ot-cybersecurity-standards\">Dragos<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/you-need-cyber-deception-ot\">Dark Reading<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>7. Three advisories and a converter: where the exposed estate actually comes from<\/h4>\n<p class=\"meta\">CISA &middot; Trout Software &middot; August 25&ndash;27, 2026<\/p>\n<p>The August 25 CISA release carried three advisories worth separating out. ICSA-26-237-03 covers the Siemens SIMATIC IoT2050 Advanced, an industrial edge gateway &mdash; precisely the class of device deployed to bridge the plant floor to a cloud analytics platform, which means it is dual-homed by design and sits on the boundary that matters. ICSA-26-237-07 covers the FURUNO FA-50 Class B AIS transponder, a maritime device that broadcasts vessel identity and position; the security consequences there run to navigational safety and vessel tracking rather than to a process upset, and the fleet is large, distributed and effectively unpatchable at sea. ICSA-26-237-05 covers the Bendix EC80 brake ECU, which puts a commercial-vehicle safety controller into the same advisory stream as plant equipment &mdash; a reminder that the ICS advisory pipeline now covers embedded systems whose failure mode is a road accident.<\/p>\n<p>Trout Software&rsquo;s round-up of the serial-to-IP device servers is the piece with the widest applicability, and it spans four advisories across two releases. ICSA-26-069-02 Update A, originally published March 10 and revised August 25, covers the Lantronix EDS3000PS and EDS5000: eight CVEs, of which CVE-2025-67038 and CVE-2025-67039 are rated 9.8 on CVSS v3.1 and 9.3 on v4.0, with the remainder between 7.2 and 2.7. Fixes exist &mdash; EDS5000 below 2.1.0.0R3 goes to 2.2.0.0R1 or later, EDS3000PS below 3.1.0.0R2 goes to 3.2.0.0R2 or later &mdash; and the same advisory family reaches the G520 and X300 series below 2.6.0.4R6 and the E210 and E220 series below 3.21.0.0R1. ICSA-26-237-06 covers the Ebyte NE2-D11 on firmware FW-9167-0-11 with eleven CVEs, four at 9.8 v3.1 and 9.3 v4.0; ICSA-26-239-05, from CISA&rsquo;s August 27 release, covers the Ebyte NA111-M on firmware 9013-2-17 with thirteen CVEs, six at the same severity. The vulnerability classes are the ones that leave nothing to exploit skill: missing authentication for a critical function (CWE-306), client-side authentication (CWE-603) and cleartext transmission of sensitive information (CWE-319). A fourth advisory in the same window, ICSA-26-239-01, covers the Xiiaozet LK100W below v2.1.240 with three CVEs including OS command injection (CWE-78). The Lantronix work is credited to Francesco La Spina and Stanislav Dashevskyi of Forescout, the Ebyte findings to Jithin Nambiar, and the Xiiaozet findings to Byron Guernsey of Okachobi.<\/p>\n<p>The reason this matters more than the CVE count suggests is how these boxes get installed. A device server takes a legacy field device that speaks RS-232 or RS-485 &mdash; a meter, a pump controller, an analyser, a protection relay &mdash; and gives it a TCP port. As Trout puts it, the requisition says the flow computer needs to be readable from the SCADA server, and an 80 mm DIN-rail box solves that for a small sum; nobody files it as a networked asset because, to the person installing it, it is a cable. The converter then becomes the security boundary for a device with no security model at all, sitting directly in the path between operators and a physical process while falling outside traditional monitoring. Forescout&rsquo;s BRIDGE:BREAK research reported finding tens of thousands of serial-to-IP converters from major vendors exposed online, with press coverage of the same work citing nearly 20,000; treat those as an order of magnitude rather than a census. When someone asks how a hundred water systems ended up with controllers answering from the internet, this is a substantial part of the answer.<\/p>\n<p>The practical sequence is short. Find the converters &mdash; look for the vendor names on panel photos, check procurement records for anything described as a device server or terminal server, and scan for the management ports they expose by default. Confirm none of them is internet-reachable. Patch the Lantronix units to the fixed versions above. For the Ebyte devices, where no fix is published, plan replacement or put compensating controls in writing; update Xiiaozet LK100W units to v2.1.240. Get management traffic off general network access entirely, and where a converter must be reachable, put it behind an access gateway with MFA rather than exposing it directly. Then document the class in your network diagrams and asset inventory permanently, because the next contractor to commission a skid will install another one, and the exposure re-appears the moment nobody is looking for it.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-237-03\">CISA (SIMATIC IoT2050)<\/a> &middot; <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-237-07\">CISA (FURUNO FA-50)<\/a> &middot; <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-237-05\">CISA (Bendix EC80)<\/a> &middot; <a href=\"https:\/\/www.trout.software\/blog\/serial-to-ip-device-servers-cisa-advisories-lantronix-ebyte\">Trout Software<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>8. Boston Scientific, order processing, and what the quarterly numbers say about manufacturing<\/h4>\n<p class=\"meta\">Industrial Cyber &middot; Securelist (Kaspersky ICS CERT) &middot; Dragos &middot; August 10&ndash;28, 2026<\/p>\n<p>Boston Scientific disclosed on August 28, in a Form 8-K signed by VP and Chief Corporate Counsel Susan Thompson, that a cybersecurity incident &ldquo;has impacted access to certain operating systems and business applications, including the ability to process and ship customer orders.&rdquo; Employees at the company&rsquo;s Cork, Ireland manufacturing facility were sent home. Third-party cybersecurity experts have been engaged, no threat actor has been named, no financial impact has been disclosed, and the company says the timeline for full restoration is not yet known. Note where the damage is. Nothing in the filing suggests a production line stopped because a controller was touched; the disruption is in the systems that decide what to make, where to ship it and how to bill for it &mdash; and yet the plant still emptied. That is the characteristic shape of a manufacturing cyber incident in 2026, and the shape most OT security programmes are worst positioned to prevent, because the ERP and order-management stack sits firmly on the IT side of a boundary the OT team does not own. For a medical-device manufacturer the consequence extends past revenue into the supply of clinical products.<\/p>\n<p>Kaspersky ICS CERT&rsquo;s Q2 2026 report puts an incident like this in proportion, and its headline number is counter-intuitive: the share of ICS computers on which malicious objects were blocked fell again, to 19.15%, the lowest level since 2022. The regional spread is wide &mdash; Africa highest at 27.9%, Northern Europe lowest at 8.1% &mdash; and the figure rose in five regions over the quarter, most notably East Asia by 2.0 percentage points. By source, the internet remains dominant at 7.61%, followed by email at 2.84%, removable media at 0.24% and network folders at 0.023%; ransomware was blocked on 0.16% of ICS computers, which is small in frequency and large in consequence. Reading these against your own detection data is the cheapest sanity check available on whether your environment is typical, and an outlier here usually indicates a monitoring gap rather than unusual good fortune.<\/p>\n<p>Dragos&rsquo;s Q2 analysis completes the picture and reinforces the Boston Scientific reading. It counted 1,140 ransomware incidents affecting industrial organisations worldwide, up 12% from 1,020 in Q1, with 747 &mdash; 65% of the total &mdash; landing in manufacturing subsectors, led by construction at 176, equipment at 114 and food and beverage at 70. North America absorbed 514 incidents to Europe&rsquo;s 316 and Asia&rsquo;s 172. Qilin led the groups with 140 claims, followed by Akira at 129, The Gentlemen at 125, DragonForce at 76 and LockBit 5.0 at 62. The operational impact in these cases is usually delivered through IT systems the plant depends on rather than through the control system itself, which makes the planning consequence specific: your OT incident-response plan needs a scenario in which the control system is entirely healthy and you still cannot operate the business. Which production lines can run in a degraded manual mode, for how long, with what paper process, and who is authorised to release product without the usual electronic quality record? Those questions get answered badly under pressure and well in a tabletop exercise, and this week supplied an unusually good excuse to run one.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/manufacturing\/boston-scientific-faces-ongoing-operational-disruption-after-cybersecurity-incident-impacts-it-systems-order-processing\/\">Industrial Cyber<\/a> &middot; <a href=\"https:\/\/securelist.com\/industrial-threat-report-q2-2026\/121159\/\">Securelist (Kaspersky ICS CERT)<\/a> &middot; <a href=\"https:\/\/www.dragos.com\/blog\/dragos-industrial-ransomware-analysis-q2-2026\">Dragos<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Calls to action \/ Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>Calls to action<\/h2>\n<ul>\n<li><strong>Scan your own exposure the way the adversary does, this week.<\/strong> More than a hundred US water systems were reached in July because they answered from the internet. Scan your own address ranges and your carrier-assigned ranges, and search the commercial scanning services for your own assets. Anything that answers goes behind an access gateway enforcing MFA, or off the path.<\/li>\n<li><strong>Audit every remote-support path an OEM, integrator or supplier holds into your process network.<\/strong> Who can reach what, through which appliance, with what authentication, and when was it last used. The four-day UK plant outage and the FBI&rsquo;s look at a water-sector supplier are the same lesson from two directions. &ldquo;We would have to ask the vendor&rdquo; is a finding.<\/li>\n<li><strong>Work CISA&rsquo;s Internet Exposure Reduction guidance as a checklist, not a read.<\/strong> Enumerate what is exposed, decide deliberately what stays, put controlled access in front of it, and re-check on a schedule &mdash; exposure returns every time a skid is commissioned or a router is swapped.<\/li>\n<li><strong>Treat your edge devices as targets rather than controls.<\/strong> The NCSC named internet-exposed systems and edge devices explicitly. Inventory every firewall, VPN concentrator, cellular gateway and remote-access appliance in front of OT, get them onto a patch cadence measured in days, and confirm none of them still holds a vendor default.<\/li>\n<li><strong>Hunt your serial-to-IP converters.<\/strong> Lantronix and EByte device servers are this week&rsquo;s reminder that the cheapest box in the panel is often the one giving a legacy field device an internet-routable identity. Find them, get their management interfaces off routable networks, rotate credentials, and add the whole class to the asset register permanently.<\/li>\n<li><strong>Apply the August 25 advisories where they land in your estate.<\/strong> SIMATIC IoT2050 Advanced gateways, FURUNO FA-50 AIS transponders and Bendix EC80 brake ECUs. For fleet and vessel equipment that cannot be patched quickly, document the compensating controls now rather than at the next audit.<\/li>\n<li><strong>Start the provenance record EO 14420 will require.<\/strong> For bulk-power equipment &mdash; transformers, inverters, relays and their remote-monitoring appliances &mdash; capture manufacturer, subcomponent origin, firmware owner and who can update it remotely. Begin with the equipment classes most likely to be named rather than the whole estate.<\/li>\n<li><strong>Specify crypto-agility in new OT procurement.<\/strong> You will not migrate a substation&rsquo;s cryptography this decade, but you can stop buying field equipment whose algorithms are welded into firmware. Pair that with an inventory of where public-key cryptography is actually used across the OT estate.<\/li>\n<li><strong>Put a decoy in the process network.<\/strong> Deception is one of the very few OT detection mechanisms with effectively no operational risk and almost no false-positive cost. A single well-placed decoy controller answers the question the red-team results really pose: would you see it?<\/li>\n<li><strong>Run the tabletop where the control system is fine and you still cannot ship.<\/strong> Boston Scientific lost order processing, not production control. Establish which lines can run degraded, for how long, on what paper process, and who can release product without the electronic quality record.<\/li>\n<\/ul><\/div>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>Whether the UK power plant incident produces a technical account.<\/strong> Four days of lost generation is the most consequential Western OT effect in years. Watching for a regulator or operator post-incident report with the initial access vector named, and for whether the plant&rsquo;s remote-support arrangement turns out to be the path.<\/li>\n<li><strong>Attribution firming up around the water campaign.<\/strong> Watching whether CISA or the FBI formally connects the 100+ targeted water systems to the same Iran-linked cluster now under sanction, and whether an indicator set is published that utilities can actually hunt with.<\/li>\n<li><strong>The water-sector supplier under FBI scrutiny.<\/strong> Watching how many downstream utilities are named, what access the supplier held, and whether this becomes the sector&rsquo;s managed-service-provider moment.<\/li>\n<li><strong>What EO 14420&rsquo;s implementing rules actually cover.<\/strong> Watching which equipment classes and vendors are named, what happens to already-energised equipment, and whether the compliance burden lands on utilities or on their suppliers.<\/li>\n<li><strong>Whether the White House water programme delivers a service or a document.<\/strong> Watching for funded technical assistance and shared monitoring that reaches systems serving under ten thousand people &mdash; and for whether the application burden is small enough that those systems can actually use it.<\/li>\n<li><strong>The Q-Day bill&rsquo;s progress and its testbed.<\/strong> Watching whether it advances out of committee, and more usefully whether it produces concrete migration guidance for relays, RTUs and teleprotection rather than another algorithm-selection paper.<\/li>\n<li><strong>Uptake of the Internet Exposure Reduction guidance.<\/strong> Watching whether it stays voluntary, gets cited in sector rules, or turns up as an expectation in insurance and audit questionnaires &mdash; the third of those usually changes behaviour fastest.<\/li>\n<li><strong>Whether the red-team result holds outside the volunteers.<\/strong> Water passed and government failed among self-selected participants. Watching for a broader assessment sample, and for whether federal civilian agencies respond to a public failure with anything measurable.<\/li>\n<li><strong>The ISA and OT Cybersecurity Coalition partnership.<\/strong> Watching whether it produces movement toward ISA\/IEC 62443 as the recognised baseline in federal policy, or another set of well-argued papers that regulators do not adopt.<\/li>\n<li><strong>The emerging industrial protocol family Dark Reading flagged.<\/strong> Watching whether it shows up in advisories and vendor deployments over the next two quarters, and whether the exposure pattern repeats before anyone has tooling that can see it.<\/li>\n<\/ul><\/div>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">IT\/OT Security<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>August 30, 2026 &middot; Weekly Edition IT\/OT Security The week the Iran-linked campaign against Western critical infrastructure stopped being a water-sector story. A UK power plant was shut down for four days, CISA confirmed that more than a hundred internet-exposed US water systems were touched in July, the FBI is&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[],"class_list":["post-5793","post","type-post","status-publish","format-standard","hentry","category-it-ot-security"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5793","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5793"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5793\/revisions"}],"predecessor-version":[{"id":5806,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5793\/revisions\/5806"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5793"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5793"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}