Daily OT Security News: 2026-08-31 — concise briefing on operational-technology and connected-systems security reports.
Boston Scientific still recovering after cyberattack disrupted manufacturing and shipping
Boston Scientific reported a cyberattack detected on August 25 that caused a global network outage, disrupting product manufacturing, customer order processing, and shipping. The company said existing implantable cardiac rhythm‑management devices were not affected, new remote activations for certain cardiac monitors were disrupted, outside incident‑response support was engaged, and no malicious activity had been observed since August 25 on the systems under review.
Manchester Airports Group reports data theft from airport services; operator says core operations unaffected
Manchester Airports Group disclosed that attackers stole data related to car‑park, lounge, Fast Track, and in‑airport Wi‑Fi registrations at Manchester, London Stansted, and East Midlands airports, including email addresses, phone numbers, vehicle registrations, and postcodes. The operator said payment information, passenger safety, aviation security, and airport operations were not affected. FulcrumSec later claimed responsibility and said it had obtained roughly 86 GB of data, a claim the airport operator had not independently confirmed.
NCSC warning underscores risk from internet‑exposed PLCs and HMIs
A UK National Cyber Security Centre warning emphasizes that internet‑exposed programmable logic controllers and human‑machine interfaces can convert cyber compromise into physical disruption. The report identifies misconfiguration, legacy connectivity, and unmanaged or forgotten devices as common pathways to external exposure and stresses validating actual — not assumed — network segmentation and accessibility.
Source: securityonline.info — NCSC Warning Highlights Internet-Exposed PLC and HMI Risk
Technical follow-up on Polish CHP compromise highlights remote‑access and monitoring gaps
A technical analysis of CERT Polska’s follow‑up on a December 2025 compromise of a Polish combined heat‑and‑power plant describes an attack path from an internet‑facing FortiGate VPN through a cellular 5G router to a WAGO PLC and the plant control network. The analysis notes weak perimeter protection and limited logging complicated forensic reconstruction and highlights the value of segmentation and monitoring traffic entering and leaving OT environments.
Source: Netresec — Polish CHP Incident Follow-Up Reinforces OT Network Monitoring Need
This briefing covers reports published or surfaced on 2026-08-31.