Daily OT Security News: August 05, 2026

Multi-State Cyberattacks Target U.S. Water Infrastructure

Possible cyber intrusions targeting operational technology at water and wastewater utilities have been reported in at least 12 U.S. states. Sources indicate that attackers are targeting internet-facing programmable logic controllers (PLCs), potentially blinding utility operators by altering passwords or disabling alarms. While there have been no widespread disruptions to water supplies, federal authorities, including the FBI and CISA, are urging operators to disconnect exposed systems from the internet and prepare to use manual controls if automated systems are compromised.

Source: ABC News

CISA Issues Advisory for Acrisure KARR Systems

The Cybersecurity and Infrastructure Security Agency (CISA) has released an Industrial Control Systems (ICS) Advisory concerning vulnerabilities in Acrisure KARR BT and DR-100 systems. The advisory states that affected firmware versions predate July 20, 2026. Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. CISA recommends minimizing network exposure and utilizing secure remote access methods such as VPNs.

Source: CISA

Process Knowledge Separates Nuisance from Capital Loss in OT Attacks

A recent incident at an Israeli food producer highlights the critical role of engineering knowledge in operational technology attacks. Intruders breached a refrigeration system, switching gas-cooler and receiver valves to manual and pinning them open, which caused liquid CO2 to flood and destroy the compressors. Security researchers note that while sending a write command to an industrial controller is relatively straightforward, knowing precisely which valve positions will destroy the machinery requires specialized process knowledge, marking a significant escalation in attacker capability.

Source: Help Net Security

Share this