Daily OT Security News: August 02, 2026

Daily OT Security News briefing for August 02, 2026: a mix of water-sector incident reporting and several authoritative CISA ICS advisories affecting controllers, communication stacks, and certificate handling.

Michigan Water Systems Join Minnesota in Reporting Cyberattacks

The Associated Press reports that nine Michigan water systems indicated activity consistent with a federal alert after more than 30 Minnesota systems were targeted. Michigan officials said all systems continued to operate safely, while Minnesota’s Braham water plant was temporarily offline after attackers shut down operating controls; the FBI had not publicly identified a culprit. Federal agencies had warned that Iranian hackers were targeting water and wastewater systems and other critical-infrastructure operational controls.

Source: Associated Press via ABC7 New York

CISA Flags Hard-Coded Keys in Watchfire Controller Software

CISA’s advisory on Watchfire controllers (ICSA-26-211-09) says CVE-2026-5846 involves self-signed hard-coded RSA private keys and X.509 certificates embedded in firmware patch binaries for HTTPS/TLS management interfaces. CISA warns a malicious user could deliver malicious firmware and gain full control of a controller; Watchfire issued version-specific patches and remediation details were updated on July 31, 2026. Affected sectors include commercial facilities, critical manufacturing, and healthcare and public health.

Source: CISA ICS Advisory ICSA-26-211-09

CISA Reports High-Impact Vulnerabilities in the open62541 OPC UA Stack

CISA’s ICSA-26-211-08 advisory reports four vulnerabilities in the open62541 OPC UA stack across 1.3, 1.4, and 1.5 branches on Windows and Linux, including integer underflow, integer overflow, and use-after-free conditions. CISA says successful exploitation could disclose sensitive information, cause denial of service, or potentially allow arbitrary code execution, and that fixes are available. The advisory identifies critical manufacturing, energy, and transportation systems as relevant sectors.

Source: CISA ICS Advisory ICSA-26-211-08

Mitsubishi Electric CC-Link IE TSN Weakness Risks Control-Communication Tampering

CISA’s ICSA-26-211-07 advisory describes CVE-2026-13584 as an improper message-integrity-enforcement weakness affecting a broad range of Mitsubishi Electric MELSEC and related CC-Link IE TSN products. CISA says a same-network-segment attacker may be able to tamper with communication data using specially crafted packets under specific timing conditions, potentially interfering with control functions or causing denial of service. CISA identifies critical manufacturing as the relevant sector.

Source: CISA ICS Advisory ICSA-26-211-07

Rockwell Automation CIP Security Flaw Undermines Certificate Revocation Validation

CISA’s ICSA-26-211-05 advisory says CVE-2026-9636 affects CompactLogix 5380, ControlLogix 5580, GuardLogix, Compact GuardLogix, and 1756-EN4TR modules by failing to reject certificates signed by an intermediate certificate that has been revoked. CISA warns this could allow a network-based attacker to establish a connection with a certificate that should be untrusted and bypass CIP Security protections; Rockwell recommends version-specific upgrades. The advisory lists manufacturing and energy/utilities among relevant verticals.

Source: CISA ICS Advisory ICSA-26-211-05

That concludes today’s roundup. Subscribe for targeted OT security updates and vendor advisory tracking.

Share this