Daily OT security briefing — August 28, 2026. Three concise items drawn from recent reporting to inform OT, ICS, CPS, and IoT security practitioners; summaries distinguish reported findings from confirmed facts.
Federal authorities seize domains linked to operation attributed to China‑nexus group QTFY, report says
Federal authorities reportedly seized domains connected to a long‑running operation attributed in reporting to a China‑nexus group called QTFY that targeted U.S. federal agencies and multiple critical‑infrastructure sectors. Cybersecurity Dive reports the campaign used compromised IoT devices and affected telecommunications firms, hospitals, defense contractors, power companies, and financial institutions; it also notes a water district was targeted via exploitation of BeyondTrust flaw CVE-2026-1731. The piece cites NSA guidance to update IoT and network‑device firmware, separate critical systems from edge devices, and review internet‑facing applications.
Shadowserver reporting summarized: Dysphoria botnet had compromised nearly 296,000 IoT devices, article indicates
The Hacker News summarizes Shadowserver reporting that the Dysphoria botnet had compromised nearly 296,000 IoT devices and was apparently being used for distributed‑denial‑of‑service activity; the reporting also notes the botnet had recently added residential‑proxy functionality. The article’s headline references a separate report about more than 100 water systems, but those details are not verified in the supplied summary. Practitioners should treat the Shadowserver figures as reported by the article and consult the original Shadowserver data and affected‑device telemetry before drawing operational conclusions.
https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html
CRS: July 2026 water system incidents in at least seven states prompt congressional considerations on municipal‑water cybersecurity
The Congressional Research Service report outlines that reported cyber incidents affecting water systems in July 2026 occurred in at least seven states and have renewed attention to municipal‑water cybersecurity. The CRS describes EPA’s sector risk‑management role and explains that risk‑and‑resilience assessments for larger community water systems must evaluate electronic, computer, and automated systems. It also notes that the Infrastructure Investment and Jobs Act expanded the scope for cybersecurity assistance and classifies cybersecurity events as an emergency for related response and assistance authorities.