Daily OT Security News – August 08, 2026
Today’s briefing spotlights critical developments in operational technology (OT) cybersecurity, focusing on emerging threats to water systems, medical devices, and industrial controllers. From targeted attacks on U.S. water utilities to new vulnerability disclosures and strategic frameworks, these stories underscore the evolving challenges that OT environments face and the importance of proactive defense measures.
CISA Warns of Iranian-Affiliated Actors Targeting U.S. Water Systems
The Cybersecurity and Infrastructure Security Agency (CISA) has released an updated advisory (AA26-097A) revealing that Iranian-affiliated threat actors are actively targeting internet-exposed OT devices, including programmable logic controllers (PLCs), within water utilities across at least 12 U.S. states. Attackers are manipulating these controllers and altering settings using legitimate engineering tools, making traditional antivirus solutions ineffective. Operators are urged to secure exposed endpoints promptly to prevent potential disruptions.
Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
CISA Issues ICS Medical Advisory for Medixant RadiAnt DICOM
CISA has published an Industrial Control Systems (ICS) Medical Advisory (ICSMA-26-218-01) addressing vulnerabilities found in the Medixant RadiAnt DICOM Viewer software. These security flaws could allow unauthorized access or manipulation of sensitive medical imaging data, posing risks to patient confidentiality and diagnostic accuracy. Healthcare providers using this software are advised to implement recommended mitigations to safeguard critical medical systems.
Source: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01
Claroty’s Team82 to Expose Refrigeration Controller Vulnerabilities at DEFCON34
Claroty’s Team82 research group announced an upcoming presentation at DEFCON34 where Amir Zaltzman will discuss newly discovered security vulnerabilities in industrial refrigeration controllers. These controllers play a crucial role in industries like food, beverage, and pharmaceuticals, highlighting the need for stronger OT cybersecurity measures beyond traditional IT defenses to protect critical supply chains.
Source: https://claroty.com/team82
NIST Releases Final Transit Profile to Prioritize IT/OT Cybersecurity Risks
The National Institute of Standards and Technology (NIST) has published the final Transit Profile, offering a detailed framework to help transit agencies prioritize and manage cybersecurity risks spanning IT and OT environments. This guide reinforces the importance of integrating OT security within broader risk management strategies to defend vital transportation infrastructure against evolving cyber threats.
Source: https://www.nist.gov/cyberframework/profiles
Minnesota Water Systems Hit by Coordinated Cyberattack via Cellular Connections
More than 30 water systems in Minnesota have been affected by a coordinated cyberattack targeting cellular-connected OT devices. The attack exploited vulnerabilities similar to those seen in other PLC-focused campaigns, emphasizing the risks of remote OT monitoring and control. Authorities are calling for improved security practices including removal of default credentials and adoption of secure remote access protocols to mitigate future threats.
Source: https://www.secureworld.io/industry-news/cyberattack-taps-minnesota-water
As threats to operational technology continue to evolve, staying informed and resilient is essential. We encourage all stakeholders to prioritize robust cybersecurity strategies and maintain vigilance against emerging attack vectors.