Today’s roundup covers five security advisories and research items affecting water systems, physical-security and transportation devices, healthcare diagnostic equipment, IoT provisioning workflows, and machine-identity governance in production environments.
Water-sector cyberattacks reportedly extend to at least 12 U.S. states
SecurityWeek reported on August 5 that at least 12 U.S. states had reportedly been affected by a campaign targeting water and wastewater facilities, with more than 30 Minnesota community water systems targeted on July 26–27 and confirmations or disruption reported in Michigan, South Dakota, and Georgia. The FBI said malicious actors targeted internet-exposed Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, changing IP addresses and enabling or setting passwords, causing loss of view and in some cases loss of function; reported operational effects include loss of pressure and flooding, and investigators are considering possible Iranian involvement though no official attribution has been announced.
Source: SecurityWeek
CISA flags hard-coded key weakness in Acrisure KARR BT and DR-100 systems
CISA released ICS Advisory ICSA-26-216-01 on August 4 for Acrisure KARR BT and DR-100 systems with firmware earlier than July 20, 2026, identifying CVE-2026-18411, a hard-coded cryptographic-key issue with a CVSS v3 score of 8.1. CISA says successful exploitation could allow unauthorized vehicle-control operations and recommends reducing network exposure, isolating control-system networks from business networks, and securing remote access; CISA reports no known public exploitation specifically targeting this vulnerability.
Source: CISA
CISA warns that Thermo Fisher genetic-analyzer software could enable DNA-data tampering
CISA released medical advisory ICSMA-26-216-01 on August 4 covering multiple Thermo Fisher Applied Biosystems genetic-analyzer data-collection and instrument-software product families and identifying CVE-2026-17583, a missing integrity-check vulnerability with a CVSS v3 score of 8.4. CISA warns that successful exploitation could allow an attacker to modify .fsa or .hid output files and produce inaccurate test results, and recommends minimizing network exposure and using secure remote access while noting healthcare and public health as the relevant critical-infrastructure sector.
Source: CISA
Forescout discloses 15 TP-Link Omada zero-touch provisioning vulnerabilities
Forescout published research on August 4 disclosing 15 vulnerabilities affecting Zero-Touch Provisioning in TP-Link’s Omada ecosystem and noted that some weaknesses extend to other TP-Link products and services, including IP cameras, smart-home IoT devices, mobile applications, and cloud accounts. The findings include a hard-coded-key trust-chain compromise, sensitive-information disclosure, and remote code execution, with grouped potential impacts including client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications; Forescout recommends strong unique device credentials, enabling MFA where available, rotating possibly exposed VPN credentials, segmenting networks, and monitoring network activity.
Source: Forescout Research
ClearVector report highlights a machine-identity governance gap in production environments
ClearVector released its Identity Intelligence Report 2026 on August 4 reporting that 91% of identities operating in the production environments it analyzed were non-human; the report is based on production activity across AWS and Google Cloud Platform and is not a study focused specifically on OT. It argues that periodic or time-based monitoring can miss much non-human activity and that attackers increasingly abuse legitimate credentials and trusted workflows, and it advocates continuous behavioral modeling of human, non-human, third-party, and AI-driven identities to identify suspicious activity.
Source: ClearVector via PR Newswire
Note: monitor vendor advisories and investigate device exposure and credential posture in affected environments.