This briefing summarizes verified developments relevant to OT, IoT, ICS, and CPS security: a CISA warning following attacks on Minnesota water utilities, an update to SBOM minimum elements from CISA and partners, and an FCC Covered List change addressing foreign-produced robotics and power inverters.
Minnesota Water-Sector Attacks Prompt CISA Warning on Internet-Exposed PLCs
The report describes cybersecurity attacks on Minnesota water utilities and a CISA warning about increased threat-actor targeting of programmable logic controllers (PLCs). CISA urged critical-infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other OT assets from the internet as soon as possible, and recommended mitigations including using VPNs or gateway devices for remote operations, changing default passwords, IP allowlisting, and keeping a clean PLC-image backup. Source
CISA and Partners Refresh Minimum SBOM Elements for Software Supply-Chain Risk Management
CISA and U.S. and international partners released the 2026 Minimum Elements for a Software Bill of Materials (SBOM). The update adds minimum elements including Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context, with the guidance intended to improve software supply-chain transparency and support scalable, machine-readable risk management across software types. Source
FCC Covered List Update Elevates Cybersecurity and Supply-Chain Concerns for Connected Robotics
An FCC fact sheet dated July 28, 2026 states the Commission updated its Covered List to include foreign-produced advanced robotic devices and power inverters covered by national-security determinations. The fact sheet states that the devices could create supply-chain vulnerabilities capable of disrupting U.S. critical infrastructure and creating cybersecurity risk, and the action illustrates the widening regulatory focus on security risks from networked cyber-physical systems. Source
Across these confirmed items the operational-security themes are consistent: exposure of networked OT/CPS assets (notably PLCs and connected devices) increases cyber risk, supply-chain transparency and integrity are being emphasized by policy and guidance (SBOM updates and regulatory listings), and authorities are issuing mitigation and regulatory responses to address those risks.