Daily OT Security News: August 06, 2026

Daily OT Security News briefing: the items below summarize this week’s notable operational-technology and industrial cyber developments, including incident reporting, advisories, vendor certification, and product announcements.

Cyberattacks on U.S. water systems expand to 12 states

The Record reported on August 5 that water utilities in at least 12 U.S. states had reported cyberattacks affecting operational technology. Clayton County Water Authority in Georgia reported a temporary disruption to part of its operational systems and water service and issued a precautionary boil-water advisory that was later lifted; sources linked the campaign to Iranian actors while federal agencies had not publicly attributed it. CISA separately advised operators to remove internet-exposed PLCs and stated that attackers had changed passwords and IP addresses, leading to boil-water notices and sustained manual operations.

Source: https://therecord.media/iran-cyberattacks-water-treatment

Canadian advisory flags affected Zbtlink cellular and router firmware

The Canadian Centre for Cyber Security issued advisory AV26-779 on August 5 for a vulnerability affecting a long list of Zbtlink router and cellular-device firmware versions, including CPE2801, WE-series, WG-series, and ZBT-Z8102AX-2SIM products. The advisory links to technical material describing the ENDLESSDOORS Zbtlink Router rctl/kworker phone-home root implant and instructs users to apply vendor updates as they become available.

Source: https://www.cyber.gc.ca/en/alerts-advisories/zbtlink-security-advisory-av26-779

Fortinet announces IEC 62443-4-2 Security Level 4 certification for FortiOS 7.6

Fortinet announced on August 5 that FortiOS v7.6.x achieved IEC 62443-4-2 Security Level 4 certification. The company said the certification applies across FortiGate, FortiGate Rugged, FortiWiFi, and FortiGate VM products powered by FortiOS v7.6.x and positioned the certification as relevant to OT, critical infrastructure, and industrial automation deployments.

Source: https://www.fortinet.com/blog/operational-technology/fortinet-achieves-iec-62443-4-2-security-level-4-certification-for-fortios-76

CISA flags actively exploited TeamCity remote-code-execution vulnerability

The Hacker News reported on August 6 that CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog after active exploitation was observed. The CVSS 9.8 deserialization flaw affects on-premises JetBrains TeamCity and can let an unauthenticated attacker use the agent-polling protocol to bypass authentication and execute operating-system commands with TeamCity server-process privileges.

Source: https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html

Viakoo announces Device Configuration Manager and expanded OT/IoT ecosystem

Viakoo announced at Black Hat USA 2026 the launch of Device Configuration Manager (DXM), a planned integrated module of the Viakoo Action Platform expected in Q4 2026. The announcement describes DXM as providing continuous agentless baseline monitoring, configuration-drift detection, and policy-driven remediation across OT and IoT endpoints and cites partner integrations with OT/CPS discovery platforms and relationships with Johnson Controls, Axis Communications, and Honeywell.

Source: https://lasvegassun.com/news/2026/aug/05/viakoo-accelerates-otiot-security-momentum-with-pl/

End of briefing.

Share this