Daily OT Security News: August 10, 2026

Briefing: four OT security developments and recommended actions for asset owners, operators and service providers.

Minnesota water systems confront coordinated attacks on internet-facing control equipment

SecureWorld reports a coordinated July 26–27 attack that affected the OT of more than 30 Minnesota community water systems, targeting PLCs and HMIs used to control pumps, wells, pressure and chemical treatment. Affected communities used quick isolation and manual operations; no Minnesota city reported contamination, changed chemical levels, a prolonged interruption or a boil-water advisory. The FBI said actors remotely accessed internet-facing OT devices and changed IP addresses and passwords, impairing monitoring and control. The incident underscores that asset owners should eliminate direct internet exposure of PLCs, use authenticated segmented remote access, and rehearse manual operations to maintain resilience.

SecureWorld: Minnesota water systems confront coordinated attacks on internet-facing control equipment

Technical review maps exposure and legacy risk in the U.S. water-controller campaign

Forescout reports 4,407 internet-facing controllers exposing EtherNet/IP port 44818 in its measurement, with MicroLogix 1400 devices the most common family. Its review of the FBI/EPA advisory says actors targeted Rockwell Automation/Allen‑Bradley MicroLogix 1100 and 1400 PLCs, with reports of remote reconfiguration and, in at least one victim, PLC-logic modification; the analysis names CVE-2017-16740 among relevant legacy exposures but notes that exploitation would require Modbus TCP to be enabled and was not confirmed. These findings point to the need to prioritize an external-exposure inventory, disable unnecessary services, employ secure access gateways, and plan end‑of‑life controller replacement.

Forescout Vedere Labs: Technical review maps exposure and legacy risk in the U.S. water-controller campaign

CERT Poland reports first observed private-APN route into an OT network

CERT Polska’s follow-up report describes a previously undisclosed December 2025 attack on a smaller combined heat‑and‑power plant in which a steam turbine and the process‑water treatment system were shut down, interrupting cogeneration; operators limited the event to a short outage without heat‑supply disruption. The investigation reconstructed a path into the OT network through a private APN and identified a misconfiguration that allowed arbitrary devices within the private APN to communicate. This highlights that private APNs should be treated as segmented security zones, with device‑to‑device reachability constrained, access monitored, and configuration assumptions tested.

CERT Polska: Incident follow-up report — energy sector

U.S. tax-policy proposal seeks to lower barriers to OT cybersecurity services

In an August 5 letter, Senator Tom Cotton asked the Treasury Department to clarify federal tax guidance in ways intended to encourage investment in OT security for critical infrastructure. The requested actions include potential section 41 research treatment for industrial‑control‑system security software, a safe harbor treating certain public‑utility cybersecurity agreements as services, and extension of a utility exception to service providers. These are proposals to Treasury rather than enacted changes; utilities and security providers should monitor the proposal while continuing to build resilience plans around current—not prospective—policy and funding conditions.

Office of U.S. Senator Tom Cotton: Cotton to Bessent — Protect critical infrastructure from cyberattacks

Share this