Daily OT Security News: August 09, 2026

Daily OT/ICS/IoT security briefing for August 09, 2026. Below are five significant operational-technology and Internet-of-Things incidents and advisories affecting critical infrastructure, industrial environments, and widely deployed vendor products.

Oregon confirms unauthorized access to drinking-water provider OT; pressure loss and flooding reported

Oregon authorities confirmed that between July 27–30 attackers connected to internet-accessible PLCs at an unnamed drinking-water provider, changed IP addresses and passwords, and disrupted monitoring and control. The FBI reported operational impacts that included pressure loss and flooding, underscoring the risks of exposed control assets and weak remote-access protections.

Source: https://www.opb.org/article/2026/08/07/oregon-drinking-water-system-accessed-cyber-attacks/

Fifteen TP-Link Omada vulnerabilities allow credential theft, VPN access and possible root execution

Researchers disclosed 15 flaws in TP-Link Omada that can let unaffiliated attackers obtain controller credentials, a shared site password, VPN access, and in some cases achieve command execution at a high privilege level. A common TLS certificate and private key issue affects Omada and some VIGI camera, Festa, Tapo, and Kasa products, amplifying the attack surface across multiple device families.

Source: https://www.helpnetsecurity.com/2026/08/05/forescout-tp-link-omada-vulnerabilities/

Kaspersky ICS CERT Q2 2026: ~40 attacks on industrial organizations; refrigeration incident floods compressors with liquid CO2

Kaspersky ICS CERT’s Q2 2026 analysis documents roughly 40 attacks against industrial organizations, including an incident where an intruder changed a food producer’s central controller credentials and set refrigeration valves to manual/open. That manipulation flooded compressors with liquid CO2, causing equipment damage and forcing a system rebuild, illustrating the physical consequences of credential and control-plane compromises.

Source: https://www.helpnetsecurity.com/2026/08/05/ai-industrial-cyberattacks-know-how/

CISA: ABB Ability Zenon IIoT services using MongoDB 4.2 are vulnerable—update or remove services

CISA advisory ICSA-26-218-01 warns that ABB Ability Zenon deployments using built-in IIoT services with MongoDB 4.2 may be exploited to bypass security controls, crash systems, execute unauthorized actions, or compromise data. ABB recommends migrating to a supported, patched MongoDB version or uninstalling unneeded IIoT services to mitigate the risk.

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01

CISA: Johnson Controls TL280 <5.63 exposes devices to risky cryptography (CVE-2026-27871)

CISA advisory ICSA-26-218-02 reports that Johnson Controls TL280 firmware earlier than 5.63 contains CVE-2026-27871, a broken or risky cryptographic-algorithm issue that could expose sensitive device information if exploited. The agency notes no public exploitation is known and that attack complexity is high, but urges timely updates to version 5.63 or later to eliminate the vulnerability.

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-02

Closing note: Organizations should immediately inventory exposed control assets, apply vendor-recommended patches or mitigations, enforce network segmentation and strong credential management, and remove or disable unnecessary IIoT services to reduce the risk of similar operational-impact incidents.

Share this